10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

9. Contingency Planning<br />

These Contingency Planning Mandatory Procedures support the Enterprise Security <strong>Policy</strong><br />

(ITEC 7230 Rev 1), the Business Contingency Planning <strong>Policy</strong> (ITEC 5300) and the Business<br />

Contingency Implementation <strong>Policy</strong> (ITEC 5310).<br />

Mandatory<br />

Non-Mandatory<br />

Procedures Baselines Procedures Baselines<br />

9. Contingency Planning <br />

9.1. Contingency Plans<br />

9.1.1. Build a Plan (5 sets) (3 sets)<br />

9.1.2. Test the Plan (3 sets) (2 sets)<br />

9.2. Contingency Infrastructure<br />

9.2.1. Required Contingency Infrastructure (1 set)<br />

9.3. Contingency Operations<br />

9.3.1. Build a Team and Provide Training (4 sets) (3 sets)<br />

9.3.2. Backup Scheduling and Frequency (1 sets) (1 sets)<br />

9.1. Contingency Plans<br />

The following are the Mandatory Procedures that support the Contingency Plans<br />

section <strong>of</strong> the Default Security Requirements:<br />

9.1.1. Build a Plan<br />

Contingency planning requires the identification <strong>of</strong> assets to be protected by<br />

the plan, determination <strong>of</strong> the strategies applicable to the execution <strong>of</strong> the<br />

plan and the documentation <strong>of</strong> the plan itself:<br />

9.1.1.1 Establish the Nature and Scope <strong>of</strong> the Plan<br />

Contingency planning can incorporate a number <strong>of</strong> different types <strong>of</strong><br />

plans. The organization must first decide exactly what type <strong>of</strong><br />

planning is in-scope before commencing plan construction:<br />

• Determine the specific sub-plan components to be developed.<br />

9.1.1.2 Conduct a Business Impact Analysis<br />

Since it is impossible to effectively restore all systems and system<br />

functions simultaneously, the organization must determine which<br />

capabilities are the most critical in order to build a proper restoration<br />

prioritization:<br />

• Identify critical IT resources.<br />

• Identify disruption impacts and determine allowed outage<br />

times.<br />

• Develop recovery prioritization schedules.<br />

9.1.1.3 Identify In-Place and Required Preventative Measures<br />

The use <strong>of</strong> appropriate preventative measures can <strong>of</strong>fset the need to<br />

initiate contingency actions and so establishing these measures is an<br />

essential component <strong>of</strong> overall contingency planning.<br />

9.1.1.4 Develop a Recovery Strategy<br />

21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!