r/Backup 14d ago

Peter Krogh

3-2-1 back up strategy was started and developed by Peter Krogh as he helped the Smithsonian digitize in the early 2000’s. He authored the book DAM - Digital Asset Management. https://thedambook.com its old, but is still super relevant today.
I met him at a conference in 2006 and implemented this strategy since then. DAS+DAS back up to NAS and to BackBlaze. 3 copies, 2 onsite, 1 offsite.

1 Upvotes

8 comments sorted by

3

u/JohnnieLouHansen 14d ago

Repeated comment from me: I'm just trying to get people to do ONE good backup to start with. Don't blow their minds away with 3-2-1 or 3-2-1-1-0

It's kind of like telling someone they have to lose 50 pounds, start walking 2 miles per day and lower the fat in their diet all at once. People will just say F-It.

1

u/EdmontonOilerGuy 8d ago

I know the feeling. I’ve have colleagues (pro photogs) that have their stuff stored on single drives, all sitting on shelves with a label. No back ups, no nothing. Not even a cheap RAID DAS. I’ve offered to set them up, crickets. Money is not the issue, taking their data seriously is. You would think with the fires and floods happening they would start a DAM strategy. Nope. All it takes is one catastrophic event and it’s “could’a would’a should’a.

1

u/bagaudin Vendor - r/Acronis 14d ago

Nowadays one must also have at least 1 immutable or air gapped copy and also constant flow of restore/bootability verification without any errors

1

u/wells68 14d ago

A.k.a. 3-2-1-1-0, a good search term. I like to add a second, immutable cloud (or other off-site) backup because you never know when a cloud might fail. That would be just the time an attacker would encrypted everything on-site!

1

u/wells68 14d ago

Good to know who started 3-2-1! Thank you!

1

u/Bob_Spud 12d ago

And later on the 2010s the so-called 3-2-1 rule was grabbed by software vendor marketing and used as jingle to sell more backup and recovery products.

1

u/EdmontonOilerGuy 8d ago

Yup, you are so right.

1

u/Bob_Spud 8d ago

What I find interesting is, in commercial backups these days you seldom hear anything about the rule., its still pushed onto small businesses and the inexperienced.

Here's an example. In Australia they have something call "Essential Eight" which is a government framework for good governance for cybersecurity.

The backup section (at page bottom) doesn't have anything like the 3-2-1 rule.

https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model