Enveloc Helps with Sarbanes-Oxley Backup Compliance

The Sarbanes-Oxley (SOX) Act of 2002 legislates the manner and duration in which certain financial institutions’ data are secured and stored . The act places rigorous requirements on the security, accuracy and reliability of certain records. As a result, data security and storage becomes vitally important because the records of transactions must be secure. The Corporate and Criminal Fraud Accountability aspects of SOX require a broad range of corporate documents be retained for five years and failure to produce certain documents during an audit is subject to severe penalties.

SOX mandates that subject matter data be continuously available 24/7 for a period of five years. However, hoping your server does not crash for five years is obviously not a choice. Making matters more complex, conventional solutions like storage tapes are prohibitively expensive, unreliable and require the implementation and maintenance of complex hardware systems. Tapes also lack effective data encryption to prevent unauthorized access to the media and there are also concerns about the cost and sufficiency for the actual the physical storage of the tapes themselves.

Enveloc provides a cost effective alternative: secure, automated offsite backup services that helps with SOX compliance without elaborate storage procedures or outrageous IT budgets.

Enveloc’s online data backup solutions offer the following safeguards to ensure quality control:

  • Backup data is encrypted using 256-bit AES encryption before transmission and remains encrypted in lossless compression at Enveloc’s redundant data centers until restored to client servers.
  • Stored information can only be retrieved by authorized using a user-defined encryption passphrase. (Not even Enveloc has a copy).
  • Fully automated backups are scheduled by the user, maintained in a discernable sequence, verified daily and notifications are provided to ensure every backup has completed successfully.
  • Data can be stored on Enveloc’s secure servers indefinitely. Retention periods are configured by users during initial set up; after that, backups are automatically stored for that period and can be deleted automatically after the period stated in the Act (generally, five years).
  • Data is stored offsite on redundant, high security class-A data Network Operation Centers, is available 24/7 and can be restored instantly to any location.
  • Enveloc’s live, US-based customer service is available around the clock and daily backup audits and confirmation e-mails with summary transfer logs can be provided to ensure the integrity of every single data backup set to provide a clear audit trail, if necessary.
  • Enveloc logs data access each time a user restores any stored backup data.