ISO IEC 17799 2000*TRANSLATED INTO PLAIN ENGLISHSection 11: Business Continuity ManagementFREE DETAILED STANDARD |
||
| MAIN MENU | TO SECTION 12 | |
|
* ISO
17799 2000 is now OBSOLETE. |
||
![]()
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
11.1 DESIGN A CONTINUITY MANAGEMENT PROCESS |
|
|
|
Develop a business continuity management
process to protect |
|
|
Make sure that your business continuity
management process is used |
|
|
Make sure that your business continuity
management process is used |
|
|
Make sure that your business continuity
management |
|
|
Make sure that your business continuity
management process is used |
|
|
Make sure that your business continuity |
|
|
Analyze the impact that disasters could |
|
|
Analyze the impact that security failures |
|
|
Analyze the impact that a loss of service |
|
|
Developed contingency plans in order to |
|
|
Practice implementing your contingency plans. |
|
11.1.1 ESTABLISH YOUR CONTINUITY MANAGEMENT PROCESS |
|
|
|
Establish a process to manage and maintain |
|
|
Identify and prioritize your organization’s |
|
|
Identify the risks that threaten the |
|
|
Estimate the likelihood that your organization
will be |
|
|
Analyze the impact that serious threats could
have |
|
|
Analyze the impact that interruptions could
|
|
|
Find solutions to the security problems that
|
|
|
Find solutions for the security threats and |
|
|
Increase your security through the |
|
|
Formulate business objectives and priorities
|
|
|
Formulate a business continuity strategy |
|
|
Document your business continuity strategy. |
|
|
Make sure that your business continuity
strategy is consistent |
|
|
Formulate business continuity plans |
|
|
Document your business continuity plans. |
|
|
Make sure that
your business continuity plans are |
|
|
Make sure that
responsibility for coordinating your continuity management process has
been assigned to someone at the |
|
|
Institutionalize continuity management. |
|
11.1.2 PERFORM THREAT ANALYSIS AND IMPACT ANALYSIS |
|
|
|
Carry out a threat analysis in order to
identify the |
|
|
Carry out your threat analysis with the full
|
|
|
Make sure that your threat analysis |
|
|
Carried out a risk assessment in order to
identify the |
|
|
Make sure that your impact analysis identifies
how much |
|
|
Make sure that your impact analysis identifies
how long it |
|
|
Carry out your impact analysis with the full
|
|
|
Make sure that your impact analysis includes all business processes. |
|
|
Use the results of your analyses and assessments to develop a strategy that defines your organization’s general approach to business continuity. |
|
|
Make sure that your senior management endorses
|
|
11.1.3 DEVELOP YOUR BUSINESS CONTINUITY PLANS |
|
|
|
Develop plans to restore and continue business
operations |
|
|
Make sure that your business continuity plans
|
|
|
Make sure that business continuity plans help
you to restore |
|
|
Make sure that your business
continuity plans identify the |
|
|
Make sure that your business continuity plans
identify the |
|
|
Make sure that your business continuity plans
identify the |
|
|
Make sure that your business continuity plans
identify |
|
|
Make sure that your business continuity plans
define |
|
|
Make sure that your emergency response
procedures |
|
|
Make sure that your emergency response |
|
|
Make sure that your emergency response
procedures |
|
|
Document all emergency response procedures. |
|
|
Document all critical business processes. |
|
|
Make sure that your business continuity plans
identify |
|
|
Teach your staff members how to use |
|
|
Teach your staff members how critical business
|
|
|
Teach your staff members about your crisis |
|
|
Test your business continuity plans on a regular basis. |
|
|
Update your business continuity plans on a regular basis. |
|
11.1.4 MAINTAIN A CONTINUITY PLANNING FRAMEWORK |
|
|
|
Establish a single framework of business
continuity plans |
|
|
Use your business continuity planning |
|
|
Use your business continuity planning
framework |
|
|
Make sure that each business continuity plan
includes |
|
|
Amend your business continuity plans whenever
|
|
|
Make sure that each business continuity plan
clearly |
|
|
Make sure that each business continuity plan
|
|
|
Make sure that each business continuity plan
|
|
|
Make sure that each business continuity plan
|
|
|
Make sure that each business continuity plan
specifies |
|
|
Make sure that each business continuity plan
|
|
|
Make sure that each business continuity plan
describes |
|
|
Make sure that each business continuity plan
|
|
|
Make sure that each business continuity plan
explains |
|
|
Make sure that each business continuity plan
explains |
|
|
Make sure that each business continuity plan
|
|
|
Make sure that each business continuity plan
describes |
|
|
Make sure that each business continuity plan
describes |
|
|
Make sure that each business continuity plan describes the education and awareness activities that should be carried out to help ensure that staff members understand your business continuity methods and procedures. |
|
|
Make sure that each business continuity plan
specifies who |
|
|
Make sure that owners of business processes
and resources |
|
|
Make sure that owners of business processes
and resources are responsible for managing the implementation of the
emergency |
|
|
Make sure that technical service providers are
responsible |
|
|
Make sure that information service providers
are responsible |
|
|
Make sure that communications service
providers are responsible |
|
11.1.5 TEST AND UPDATE CONTINUITY MANAGEMENT PLANS |
|
|
11.1.5.1 TEST BUSINESS CONTINUITY MANAGEMENT PLANS |
|
|
|
Test your business continuity management plans
regularly |
|
|
Evaluate your planning assumptions when you
|
|
|
Check to see that you haven’t missed anything
important |
|
|
Make sure that changes in equipment haven’t
compromised |
|
|
Make sure that changes in personnel haven’t
compromised |
|
|
Make sure that the personnel who must
implement |
|
|
Make sure that all recovery team members are
aware |
|
|
Develop a test schedule that explains how and
when each |
|
|
Identify examples of business interruptions
and then discuss |
|
|
Carry out simulations of business
interruptions in |
|
|
Carry out technical recovery tests in order to
ensure |
|
|
Carry out recovery tests at alternative backup sites. |
|
|
Test the ability of suppliers to provide
contracted |
|
|
Carry out complete rehearsals in order to
ensure that |
|
11.1.5.2 UPDATE BUSINESS CONTINUITY MANAGEMENT PLANS |
|
|
|
Use regular reviews and updates to maintain
the |
|
|
Make sure that your change management program
|
|
|
Make sure that the responsibility for the
regular review |
|
|
Make sure that your business continuity
management |
|
|
Make sure that updated business continuity
management |
|
|
Make sure that you consider updating |
|
|
Consider updating business continuity
management |
|
|
Consider updating business continuity
management |
|
|
Consider updating business continuity
management plans |
|
|
Consider updating your business continuity
management |
|
|
Consider updating your business continuity
management |
|
|
Consider updating your business continuity |
|
|
Consider updating your business continuity
management |
|
|
Consider updating your business continuity
management |
|
|
Consider updating your business continuity
management |
|
|
Consider updating your business continuity
management |
|
|
Consider updating your continuity management
plans |
|
|
Consider updating your business continuity
management |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
![]()

| Home Page | Table of Contents | Alphabetical Index | Site Map |
| How to Order | Our Products | Our Prices | Our Guarantee |
![]()
| CONTACT INFORMATION |
| Praxiom Research Group Limited 9619 - 100A Street, Edmonton, Alberta, T5K 0V7, Canada Phone: (780)461-4514 Fax: (780)463-6034 info@praxiom.com |
Legal
Restrictions on the Use of this Page
Thank you
for visiting this page. You are, of course, welcome to view our
material as often as you wish, free of charge. And as long as you keep
intact
all copyright notices, you are also welcome to print or make one copy of
this
page for your own personal, noncommercial, home use. But, you
are not
legally authorized to print or produce additional copies, or to copy and
paste
any of our material onto another web site. If you would like to
purchase our
material, please contact our Sales Desk. Our staff would be very pleased to
take your order or to answer any questions you might have.
Copyright © 2005 - 2007 by Praxiom Research Group Limited. All Rights Reserved.
Disclaimer
and Limitation of Liability
The
publisher and authors have used their best efforts in designing and
developing this electronic publication. We make no representation or
warranties
with respect to accuracy or completeness of the contents of
this publication and
specifically disclaim any implied warranties or
merchantability or fitness for any
particular purpose and shall in no
event be liable for any loss of profit or any
other commercial damage,
including but not limited to special, incidental,
consequential, or
other damages.
![]()
This web page was updated on October 2, 2007
On the Web since May 25, 1997