The repository shall have documented preservation strategies relevant to its holdings.

This is necessary in order that it is clear how the repository plans to ensure the information will remain available and usable for future generations and to provide a means to check and validate the preservation work of the repository.

Documentation identifying each preservation risk identified and the strategy for dealing with that risk.

These documented preservation strategies will describe how the repository will act upon identified risks, as part of the Preservation Strategic Plan. These preservation strategies and the Preservation Strategic Plan will typically address the degradation of storage media, the obsolescence of media drives, and the obsolescence or inadequacy of Representation Information (including formats) as the knowledge base of the Designated Community changes, and safeguards against accidental or intentional digital corruption. For example, if migration is the chosen approach to some of these issues, there also needs to be Preservation Policies on what triggers a migration and what types of migration are expected to solve the preservation risk identified. The preservation strategy will describe the range of activities that need to be done in case of a migration.

APTrust maintains documented preservation strategies relevant to its holdings through its Preservation Policy, its Risk Management, Threats, and Mitigations internal documentation, and its OAIS documentation defining SIPs, AIPs, and DIPs. These documents collectively describe how APTrust ensures long-term integrity, authenticity, and retrievability of preserved digital content.

Risk-Based Preservation Framework

APTrust’s preservation strategy is grounded in a documented threat model informed by the LOCKSS team’s bottom-up approach to digital preservation system requirements (Rosenthal et al., 2005). The Risk Management, Threats, and Mitigations documentation  identifies and evaluates risks including:

  • Media failure
  • Hardware failure
  • Software failure
  • Network disruption
  • Operator error
  • Natural disaster
  • External and internal attack
  • Economic and organizational failure

Each risk is assessed for likelihood and impact and mapped to specific mitigation strategies. Where applicable, responsibilities are explicitly assigned to APTrust, AWS, or shared between them.

This structured documentation demonstrates that APTrust’s preservation strategy directly addresses identified risks relevant to its holdings.

Shared Responsibility Model

APTrust’s preservation strategy explicitly incorporates a shared responsibility model among:

  • Depositing institutions (content stewardship and representation information)
  • APTrust (bit-level preservation, integrity verification, infrastructure management)
  • Amazon Web Services (management of underlying hardware and global infrastructure)

The division of responsibilities is described in Risk Management documentation (internal use only) and further articulated in APTrust’s public explanation of the shared responsibility model (February 2025). That explanation clarifies that:

  • APTrust ensures long-term integrity, redundancy, and retrievability of deposited digital objects.
  • Depositors retain responsibility for managing representation information, format sustainability decisions, metadata completeness, and ensuring independent understandability consistent with the Knowledge Base of the Designated Community.
  • AWS assumes responsibility for hardware durability, physical security, and global infrastructure resilience.

This model ensures that preservation strategies are aligned with APTrust’s defined service scope and the professional Knowledge Base of its Designated Community.