A&T Sysyems Inc.
Protecting, Retaining & Returning Customer Data Banner

Protecting, Retaining & Returning Customer Data

Protecting, Retaining & Returning Customer Data

Protecting customer data in a cloud environment requires more than selecting a cloud provider. Organizations should define how data is classified, accessed, encrypted, backed up, retained, recovered, exported, transferred, and securely deleted throughout the entire service lifecycle.

A&T Systems helps customers incorporate data protection, resilience, portability, and transition requirements into cloud architecture and managed operations from the beginning rather than addressing them only when a contract or service is ending.

Establish Data Ownership & Responsibility

Customers should clearly understand who owns the data, who is responsible for protecting it, which parties may access it, and how responsibilities are divided among the customer, cloud service provider, managed-services provider, and other authorized parties.

  • Identify the authoritative owner of customer data
  • Define data-controller, processor, custodian, and administrator responsibilities where applicable
  • Establish authorized-access requirements
  • Document provider and customer responsibilities
  • Address subcontractor and third-party access where applicable

Classify Data Before Selecting Controls

Data-protection requirements should be based on the sensitivity, business value, contractual requirements, regulatory obligations, and mission impact associated with the information being stored or processed.

Government customers may also need to address requirements associated with Controlled Unclassified Information, federal security categorizations, privacy information, records-management obligations, agency-specific requirements, or other contractual controls.

Protect Data at Rest & in Transit

Organizations should establish encryption, access-control, key-management, network-security, and monitoring requirements appropriate to their environment.

Data Protection Controls

  • Encryption at rest
  • Encryption in transit
  • Centralized key management
  • Least-privilege access controls
  • Multi-factor authentication
  • Data-loss-prevention controls where appropriate

Monitoring & Accountability

  • Access logging
  • Security-event monitoring
  • Configuration monitoring
  • Privileged-access review
  • Alerting and incident response
  • Retention of appropriate audit evidence

Backup & Recovery

Cloud infrastructure does not eliminate the need for a deliberate backup and recovery strategy. Customers remain responsible for establishing appropriate backup, versioning, replication, retention, and recovery processes according to their workload and business requirements.

A backup strategy should be designed around defined Recovery Point Objectives (RPOs) and Recovery Time Objectives (RTOs), data criticality, retention requirements, geographic-resilience needs, and business-continuity objectives.

  • Define which systems and data require backup
  • Establish backup frequency and retention periods
  • Protect backup data from unauthorized modification or deletion
  • Consider geographic and account-level separation where appropriate
  • Monitor backup completion and failures
  • Regularly test restoration and recovery procedures

AWS documentation specifically notes that customers remain responsible for managing the resilience of their data, including backup, versioning, and replication strategies. Recovery procedures should therefore be tested rather than assumed to work simply because cloud services are being used.

Retention & Records Management

Organizations should define how long information must be retained and when it may or must be deleted. Retention requirements may originate from business needs, contracts, records-management policies, litigation holds, privacy obligations, regulatory requirements, or agency-specific rules.

  • Document data-retention schedules
  • Apply lifecycle policies where appropriate
  • Address legal and preservation holds
  • Prevent premature deletion of required records
  • Dispose of data when retention requirements have been satisfied

Plan for Data Portability

Data portability should be considered during architecture and procurement rather than only when a customer decides to leave a provider. The ease of moving data depends on the services being used, data formats, application architecture, encryption, network capacity, volume of information, contractual requirements, and destination environment.

Organizations should identify how data and associated metadata can be exported, what tools are available, how long an export may take, and what costs or technical dependencies may apply.

  • Identify supported export formats
  • Document required metadata and configuration information
  • Consider application and database portability
  • Evaluate data-transfer volumes and network requirements
  • Account for cloud data-egress costs where applicable
  • Test export and restoration procedures before they are needed

Include an Exit & Transition Plan

An effective cloud strategy should include a documented transition approach for contract expiration, provider change, organizational restructuring, migration to another cloud, or return to an on-premises environment.

The exit plan should define responsibilities, timing, data-transfer methods, validation procedures, security requirements, continuity expectations, and the disposition of data remaining within the outgoing environment.

  • Identify what data must be returned or transferred
  • Define the required format and transfer method
  • Preserve system availability during transition where required
  • Validate completeness and integrity of transferred data
  • Transfer required documentation and configuration information
  • Document responsibilities of the outgoing and incoming providers

Secure Data Deletion

After required data has been successfully transferred, retained, or archived, organizations should establish procedures for securely deleting information that is no longer authorized to remain in the environment.

Deletion requirements should address production data, backups, snapshots, replicas, temporary copies, logs, and other locations where customer information may exist. Appropriate evidence of deletion should be retained when required by contract, policy, regulation, or security requirements.

Federal Cloud Considerations

Federal organizations should confirm that the specific cloud service offering being used meets applicable FedRAMP, agency authorization, data-handling, geographic, personnel-access, and contractual requirements.

FedRAMP certification applies to specific cloud service offerings and provides security-assessment information that agencies can use in their own risk-based authorization decisions. Agencies remain responsible for determining whether a service is appropriate for their mission and issuing any required agency authorization.

A&T’s Approach to Data Protection

A&T Systems incorporates data protection into cloud architecture, cybersecurity, service management, resilience, governance, and operational processes. Our approach includes access control, encryption, monitoring, backup and recovery, retention, portability, incident response, and transition planning based on customer and contractual requirements.

The objective is to ensure that customer data remains protected, available, recoverable, manageable, and transferable throughout the service lifecycle.

For related information, see Implementing a Public Cloud Model, Security Features from a Public Cloud Provider, and Cloud Computing & Datacenter Services.