S 2.135 Safe transfer of data to a database

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator

In many database systems, it is necessary for applications to accept the data from other systems. Basically, two different categories can be differentiated in principle:

Transfer of initial or old data

When transferring data from old systems, for example when a new database system has been purchased for use in the production environment, it must be ensured in particular that

A concept for the transfer of data must be drawn up specifying how the data to be transferred needs to be prepared and how the data transfer is to be performed in detail. Furthermore, a complete backup of the old data must be made. If the data is transferred in several steps, an independent data backup should be performed before each step.

Regular data transfers

If the destination database already contains data that must not be changed during the transfer or if data is transferred to a database at regular intervals,

Before updating a database, the users affected must be informed of the pending data transfer in due time, especially if it is expected that there will be limited database availability or longer database response times because of the update.

Before performing a data transfer, the actions to take in case of errors must be specified. For example, this includes whether or not the transfer should continue with the next record after a faulty record is detected or whether or not the entire data transfer must be cancelled. Furthermore, it is also necessary to specify how the data transfer will be resumed after it has been cancelled.

Review questions: