Archival Storage & Backup
ISO 8601 File Naming and the 3-2-1 Backup Rule for Archives
Turn a folder of scans into a collection your family can find, understand, and protect—with consistent names and a practical backup plan.

At a glance
- ISO 8601 big-endian date prefixes (YYYY-MM-DD) guarantee that lexicographical (alphabetical) sorting matches true chronological order across every operating system, phone gallery, and cloud drive.
- Because hard drive makers sell decimal terabytes (1 TB = 10^12 B) while operating systems report binary gibibytes (1 GiB = 2^30 B), a 1 TB drive displays only 931.32 GiB of usable space before formatting overhead.
- Implementing the CISA and Library of Congress 3-2-1 backup rule with periodic SHA-256 cryptographic checksum manifests detects silent bit rot before a corrupted sector overwrites your offsite mirror.
Scanning a shoebox of Kodachrome slides or nineteenth-century cabinet cards is only half of a family preservation project. Without a self-describing file-naming schema, an audited backup architecture, and museum-grade physical housing for the originals, digital scans quickly splinter into thousands of anonymous IMG_0042.jpg files scattered across aging laptops and expired cloud links. By combining ISO 8601 lexicographical file naming, CISA 3-2-1 storage capacity math, SHA-256 fixity checksums, and ISO 18916 Photographic Activity Test (PAT) enclosures, you can build a family archive that survives hardware failures and remains intelligible fifty years from now.
Why IMG_0042.jpg and Folder-Only Dates Fail in Real Life
Flatbed scanners, cameras, and transfer labs assign sequential counter names such as SCAN0001.tif or IMG_0042.jpg. Many family archivists leave those default filenames intact and rely on nested folders—such as Family Photos / 1954 / Lake George—or desktop organizers to store dates, names, and locations.
That strategy breaks the moment a file leaves your computer:
- Texting, emailing, and cloud sharing strip folder context: When you text or email
IMG_0042.jpgto a relative or upload it to an online tree, the folder path disappears. The recipient receives a bareIMG_0042.jpgwith no clue about who is pictured or when it was taken. - Filesystem timestamps reset on copy: Operating system
Date CreatedandDate Modifiedattributes record when the file was written to disk (2026-10-01), not when the wedding occurred (1948-06-12). Copying files onto an exFAT drive or uploading through a browser resets those timestamps. - Counter collisions overwrite scans: Every new batch restarts at
SCAN0001.tiforIMG_0001.jpg, creating overwrite conflicts orIMG_0001 (1).jpgduplicates. - Proprietary catalog lock-in: Captions typed into a proprietary organizer stay inside an external database rather than the filename, vanishing when that software is retired.
ISO 8601 Lexicographical Date Sorting Explained
Writing dates in US middle-endian order (MM-DD-YYYY, such as 06-14-1952) or European little-endian order (DD-MM-YYYY) scrambles alphabetical file sorting. In an ASCII or UTF-8 directory listing, a computer compares characters from left to right:
Alphabetical sort of MM-DD-YYYY filenames (chronologically broken):
04-12-1985_easter-sunday.tif
06-14-1922_grandparents-wedding.tif
11-03-1944_army-furlough.tif
Because '0' precedes '1', April 1985 sorts ahead of June 1922 and November 1944.
The international standard ISO 8601 solves this by placing time units in big-endian (most-significant to least-significant) order with mandatory zero-padding: YYYY-MM-DD. Because the four-digit year occupies positions 1–4, the two-digit month occupies positions 6–7, and the two-digit day occupies positions 9–10, lexicographical character order is mathematically identical to chronological order:
Lexicographical sort of ISO 8601 YYYY-MM-DD filenames (exact chronological order):
1922-06-14_miller-arthur-benson-clara_chicago-il_wedding_001.tif
1944-11-03_miller-arthur_fort-benning-ga_furlough_001.tif
1985-04-12_miller-family_columbus-oh_easter-dinner_001.tif
Formally, for any two valid dates (Y1, M1, D1) and (Y2, M2, D2) formatted with zero-padded fields Y ∈ [0000, 9999], M ∈ [01, 12], and D ∈ [01, 31], string comparison matches integer comparison:
String("Y1-M1-D1") ≤ String("Y2-M2-D2") ⟺ (Y1 × 10000 + M1 × 100 + D1) ≤ (Y2 × 10000 + M2 × 100 + D2)
When cataloging eighteenth-century family Bibles or colonial deeds recorded before September 1752, normalize Old Style Julian dates first using The 1752 Julian-to-Gregorian Calendar Shift and Colonial Double-Dating.
The 5-Part Archival Filename Template
Following NARA digital file-naming guidance and FADGI technical guidelines, a durable filename uses five underscore-delimited fields restricted to lowercase ASCII letters (a–z), digits (0–9), hyphens (-), and underscores (_):
YYYY-MM-DD_surname-given_location_event_seq.tif
- Field 1 (
YYYY-MM-DD): Exact or approximate ISO 8601 capture date. - Field 2 (
surname-given): Primary subject’s birth/maiden surname first, followed by given name (miller-clara, ormiller-family). - Field 3 (
location): Municipality and state or country code (chicago-il,cork-ie, orunknown-loc). - Field 4 (
event): Concise event or subject slug (graduation,homestead-porch,marriage-certificate). - Field 5 (
seq): Zero-padded three-digit sequence (001,002) plus an optional side suffix (001afront/recto,001bback/verso).
Restricting characters to [a-z0-9_-] avoids URL encoding (%20), illegal path characters (:, /, \), and Unicode normalization mismatches across macOS, Windows, and Linux NAS servers. You can generate compliant filenames interactively in the Photo, Slide & Home-Movie Digitization Planner.
Handling Approximate, Month-Only, and Decade-Only Dates
When the exact calendar day or month is unknown, preserve chronological sorting without inventing false precision by using zero-placeholder digits (1942-00-00) or trailing circa tokens (1942-00-00-ca rather than a leading ca1942 prefix):
| Historical Date Certainty | Recommended Prefix | Sorting Behavior in Directory | Example Filename |
|---|---|---|---|
| Exact day known | YYYY-MM-DD |
Sorts on exact day within month | 1954-07-04_clark-robert_boston-ma_parade_001.tif |
| Year and month known | YYYY-MM-00 |
Sorts at top of month (00 precedes 01) |
1954-07-00_clark-robert_cape-cod-ma_beach_001.tif |
| Year only known | YYYY-00-00 |
Sorts at the start of that year | 1942-00-00_clark-family_boston-ma_portrait_001.tif |
| Circa year (±2–3 yr) | YYYY-00-00-ca |
Sorts with year YYYY while flagging ca1942 |
1942-00-00-ca_clark-thomas_camp-polk-la_uniform_001.tif |
| Decade only known | YYY0-00-00-decade |
Groups undated decade items at decade start | 1920-00-00-decade_clark-homestead_ames-ia_barn_001.tif |
Putting -ca after 1942-00-00 (1942-00-00-ca_...) rather than at the start (ca1942_...) prevents the computer from sorting the file alphabetically under C instead of chronologically between 1941 and 1943.
The CISA and Library of Congress 3-2-1 Backup Rule
Both the Library of Congress Personal Archiving guidance and CISA data backup guidance recommend the 3-2-1 backup rule:
3total copies: Your primary working copy (Copy 1) plus two independent backups (Copy 2andCopy 3).2storage media types: Combine distinct hardware technologies, such as an internal NVMe SSD (Copy 1) plus an external CMR hard disk drive or NAS (Copy 2).1offsite copy: KeepCopy 3in a separate location—an encrypted cloud bucket or a drive stored at a relative’s home in another city—to survive fire, flood, or theft.
Storage Math: Why a 1 TB Hard Drive Holds Only 931.3 GiB
When sizing drives for a 3-2-1 archive, account for the 7.37% difference between decimal SI units (MB, GB, TB) and binary IEC units (MiB, GiB, TiB):
Decimal (Drive packaging): 1 GB = 10^9 B | 1 TB = 10^12 B = 1,000,000,000,000 B ≈ 931.3 GiB
Binary (OS file manager): 1 GiB = 2^30 B | 1 TiB = 2^40 B = 1,099,511,627,776 B
Conversion Ratio: 1 TB / 1 GiB = 10^12 / 2^30 = 931.3226 GiB (0.9095 TiB)
Drive makers label capacity in powers of 10 (1 TB = 10^12 B ≈ 931.3 GiB), whereas operating systems divide bytes by powers of 2 (2^30 B). A "1 TB" drive displays 931.32 GiB, and a "4 TB" drive displays 3,725.29 GiB (3.638 TiB) before formatting overhead.
Worked 3-2-1 Capacity Example for a Family Estate Collection
Suppose you digitize a collection using the resolutions in Best PPI Resolution for Scanning Old Family Photos and Slides, the byte math in TIFF vs. PNG vs. JPEG: Archival File Formats and Bit-Depth Math, and the bitrates in Digitizing VHS, Hi8, MiniDV, and 8mm Home Movies:
600mounted 35mm slides (24 × 36 mm) at4,000 PPIin 48-bit RGB TIFF (6 B/px):3,780 × 5,669 = 21,428,820 px→128.57 MB×600=77.14 GB(71.85 GiB).1,200prints (4×6 in) at600 PPI(2,400 × 3,600 = 8,640,000 px) in 24-bit RGB TIFF (25.92 MB) plus JPEG access copies (2.58 MB):28.50 MB × 1,200=34.20 GB(31.85 GiB).15two-hour VHS/Hi8 tapes (30 hours) in FFV1 lossless MKV (51.75 GB/hr) plus H.264 MP4 (4.50 GB/hr):30 hr × 56.25 GB/hr=1,687.50 GB(1,571.61 GiB).
Single Copy (1×): 77.14 GB + 34.20 GB + 1,687.50 GB = 1,798.84 GB (1.799 TB = 1,675.30 GiB)
3-2-1 Total (3×): 1,798.84 GB × 3 copies = 5,396.52 GB (5.397 TB = 5,025.91 GiB)
Because a "2 TB" drive offers 1,862.65 GiB raw, storing 1,675.30 GiB leaves under 9% headroom. Selecting two 4 TB CMR drives (3,725 GiB each) for Copy 1 and Copy 2, plus 1.8 TB of cloud storage for Copy 3, gives ample room.
SHA-256 Checksum Fixity Verification Against Bit Rot
Storage media can suffer silent data corruption (“bit rot”)—magnetic relaxation or charge leakage that flips a bit without raising a disk error. Without integrity checks, an automated backup script can overwrite a clean backup with a corrupted file.
Prevent silent corruption with SHA-256 fixity manifests. After scanning a batch of TIFFs, compute a 256-bit SHA-256 hash (a 64-character hex fingerprint) for each file and save it in manifest-sha256.txt:
shasum -a 256 *.tif | tee manifest-sha256.txt
shasum -a 256 -c manifest-sha256.txt
Flipping one bit inside a 128.57 MB TIFF alters roughly half of the 64 hex characters in its SHA-256 digest. Run shasum -a 256 -c semiannually before syncing Copy 1 to Copy 2 and Copy 3, and use conventional magnetic recording (CMR) hard drives for cold storage rather than unpowered flash drives.
Physical Housing Standards: PAT, Enclosures, and Climate
According to Library of Congress photograph preservation guidelines, three physical standards govern how long original prints and negatives survive:
- ISO 18916 (Photographic Activity Test / PAT): Avoid 1970s “magnetic” sticky-line albums and
PVCvinyl sleeves. Every paper envelope, box, and uncoated polyester (Mylar D/Melinex 516), polypropylene, or polyethylene sleeve must pass ISO 18916 (PAT). - Buffered (
pH 8.5) vs. unbuffered (pH 7.0) enclosures: Use buffered (pH 8.5) paper for black-and-white silver-gelatin prints, newsprint, letters, and isolated acetate negatives, and unbuffered neutral (pH 7.0) enclosures for chromogenic color prints and slides, cyanotypes, albumen prints, and dye-transfer prints. - Cool, dry climate (
≤ 70°Fand30–50% RH): Dye decay doubles with every10°F (5.6°C)temperature rise. Keep archival boxes out of attics and damp basements, storing them in an interior closet at≤ 70°F (21°C)and30–50% RH.
Put it into practice
Try it with your own collection
Photo & slide planner
Plan scan quality, estimate storage, and inspect a photograph’s colors.
Sources & further reading
- Library of Congress: Care, Handling, and Storage of Photographs
- Cybersecurity and Infrastructure Security Agency (CISA): Data Backup Options
- FADGI: Technical Guidelines for Digitizing Cultural Heritage Materials
- National Archives (NARA): Digital File Naming and Transfer Guidance
- Wikipedia: ISO 8601 Date and Time Standard
Information on this page is for educational archival preservation and historical genealogy research. Always test conservation handling on non-unique materials first, verify AI handwriting transcriptions against original county or NARA microfilm, and never use autosomal DNA statistics for clinical or legal parentage determinations. Nothing on this site is legal, probate, medical, or financial advice. Spotted an error? Tell us and we will review it under our corrections policy.
Back to the beginning ↑