10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

9.1.2.3 Review Test Results and Take Corrective Action<br />

Once the test has been completed, the results should be reviewed to<br />

see if the contingency plan accurately reflects the needs <strong>of</strong> the<br />

organization or if an adjustment is required.<br />

9.2. Contingency Infrastructure<br />

No applicable Mandatory Procedures.<br />

9.3. Contingency Operations<br />

The following are the Mandatory Procedures that support the Contingency Operations<br />

section <strong>of</strong> the Default Security Requirements:<br />

9.3.1. Build a Team and Provide Training<br />

Contingency planning is a security control that requires specialized capabilities.<br />

Building a team ensures they are always appropriately provided for:<br />

9.3.1.1 Identify Roles with Contingency Responsibilities<br />

To be able to efficiently and effectively respond to disruptions as they<br />

occur, a variety <strong>of</strong> skills are required. Defining roles that <strong>of</strong>fer those<br />

skills ensures that appropriate personnel can be identified.<br />

9.3.1.2 Associate Personnel with Contingency Roles<br />

Once roles have been determined, individual employees must be<br />

associated with those roles according to the skill sets required <strong>of</strong> the<br />

role and available within the employee pool.<br />

9.3.1.3 Identify Contingency Responsibilities <strong>of</strong> those Roles<br />

Once individual employees have been associated with particular<br />

roles, it is important to define and assign specific responsibilities so<br />

that in the event <strong>of</strong> a disruption all members <strong>of</strong> the team know who<br />

will be handling what.<br />

9.3.1.4 Build and Deliver a Contingency Training Program<br />

To ensure that all members <strong>of</strong> the contingency team are able to<br />

execute their responsibilities in the most efficient manner possible a<br />

training program must be devised and delivered:<br />

• Determine needs and design a program accordingly.<br />

• Create the materials to support the delivery <strong>of</strong> the program.<br />

• Provide instructive training as per the program.<br />

• Provide training support materials as per the program.<br />

9.3.2. Backup Scheduling and Frequency<br />

Systems and data backups are an important component <strong>of</strong> any contingency<br />

plan or contingency operations and so backups must be taken according to<br />

appropriate schedule:<br />

23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!