ISO IEC 17799 2000*TRANSLATED INTO PLAIN ENGLISHSection 8: Communications and Operations ManagementFREE DETAILED STANDARD |
||
| MAIN MENU | TO SECTION 9 | |
|
* ISO
17799 2000 is now OBSOLETE. |
||
![]()
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
8.1 ESTABLISH OPERATIONAL PROCEDURES |
|
|
|
Establish procedures to manage your |
|
|
Assign responsibilities that govern the
management |
|
|
Establish procedures to operate your |
|
|
Assign responsibilities that govern the
operation of |
|
8.1.1 DOCUMENT YOUR OPERATING PROCEDURES |
|
|
|
Develop operating procedures that |
|
|
Document your operating procedures. |
|
|
Control your operating procedure documents. |
|
|
Make sure that all changes to your operating
procedure |
|
|
Make sure that operating procedures explain
|
|
|
Make sure that your operating procedures |
|
|
Make sure that your operating procedures |
|
|
Make sure that operating procedures explain
|
|
|
Make sure that your operating procedures
expect |
|
|
Make sure that operating procedures describe the systemic interdependencies that influence how jobs are done. |
|
|
Make sure that your operating procedures
explain |
|
|
Make sure that your operating procedures
explain how |
|
|
Make sure that your operating procedures
identify |
|
|
Make sure that your operating procedures |
|
|
Make sure that your operating procedures
explain |
|
|
Make sure that your operating procedures
explain |
|
|
Make sure that operating procedures explain
|
|
|
Make sure that operating procedures |
|
|
Make sure that operating procedures |
|
|
Develop operational housekeeping procedures
|
|
|
Develop operational housekeeping |
|
|
Develop computer startup and shutdown procedures. |
|
|
Develop computer backup procedures. |
|
|
Develop equipment maintenance procedures. |
|
|
Develop computer room procedures. |
|
|
Develop mail handling management procedures. |
|
|
Develop mail handling safety procedures. |
|
8.1.2 CONTROL CHANGES TO FACILITIES AND SYSTEMS |
|
|
|
Control changes to information processing facilities. |
|
|
Control changes to your information systems. |
|
|
Assign management responsibility |
|
|
Assign management responsibility |
|
|
Assign management responsibility |
|
|
Develop procedures to control changes to equipment. |
|
|
Develop procedures to control changes to software. |
|
|
Develop procedures to control changes to procedures. |
|
|
Control all changes to operational programs. |
|
|
Use audit logs to track changes to programs. |
|
|
Identify all significant changes to your
organization’s |
|
|
Record all significant changes to your
organization’s |
|
|
Assess the potential impact before you make
changes |
|
|
Use a formal procedure to authorize proposed
|
|
|
Ensure that the details of all changes to
facilities and |
|
|
Use a procedure to control how unsuccessful
|
|
8.1.3 ESTABLISH INCIDENT MANAGEMENT PROCEDURES |
|
|
|
Establish procedures that must be used to |
|
|
Assign incident management responsibilities. |
|
|
Develop procedures to handle all types of security incidents. |
|
|
Develop procedures to handle information system failures. |
|
|
Develop procedures to handle the loss of service. |
|
|
Develop procedures to handle the denial of service. |
|
|
Develop procedures to handle incomplete data. |
|
|
Develop procedures to handle inaccurate data. |
|
|
Develop procedures to handle confidentiality breakdowns. |
|
|
Make sure that your procedures expect people
to identify |
|
|
Make sure that your procedures expect people
to figure |
|
|
Make sure that procedures expect people to
communicate |
|
|
Make sure that your procedures expect people
to report the |
|
|
Make sure that your procedures expect people
to study |
|
|
Use evidence to analyze your security incidents. |
|
|
Collect evidence for breach of contract purposes. |
|
|
Collect evidence to address regulatory violations. |
|
|
Collect evidence to support legal proceedings. |
|
|
Collect evidence to support your requests for
|
|
|
Develop procedures to control how you |
|
|
Make sure that your recovery procedures ensure
|
|
|
Make sure that your
recovery procedures |
|
|
Make sure that your recovery procedures expect
|
|
|
Make sure that your recovery procedures expect
management |
|
|
Make sure that your
recovery procedures ensure that the |
|
|
Make sure that
your recovery procedures ensure |
|
8.1.4 SEGREGATE CONTROL OVER KEY RESPONSIBILITIES |
|
|
|
Make it difficult to modify information or
services without |
|
|
Make it difficult to misuse information or
services by |
|
|
Reduce the chances that people will accidentally or intentionally modify or misuse information or services by separating duties and responsibilities. |
|
|
Ensure that responsibility for initiating and
authorizing |
|
|
Reduce the chances that fraud will be
perpetrated |
|
|
Reduce the opportunity for collusion by
ensuring that |
|
|
Take steps to ensure that fraud can be
detected |
|
|
Supervise work activities more closely
whenever the security |
|
|
Use audit trails whenever the security of your
information |
|
8.1.5 SEPARATE SYSTEMS DEVELOPMENT AND OPERATIONS |
|
|
|
Separate the responsibility for software |
|
|
Separate development and testing activities. |
|
|
Develop and document rules to control the
transfer of software |
|
|
Run developmental software and operational |
|
|
Run developmental software and operational |
|
|
Prevent unauthorized access to editors,
compilers, and |
|
|
Make sure that test systems and operational
|
|
|
Expect users to use different passwords |
|
|
Make sure that it is easy for users to
distinguish between |
|
|
Control how operational system passwords are
|
|
8.1.6 CONTROL THE MANAGEMENT OF EXTERNAL FACILITIES |
|
|
|
Make sure that external contractors have |
|
|
Make sure that your contracts specify the |
|
|
Make sure that your contracts specify |
|
|
Make sure that your contracts specify the
security |
|
|
Make sure that your contracts specify how
compliance |
|
|
Make sure that your contracts allocate
specific |
|
|
Make sure that your contracts identify the |
|
|
Make sure that your contracts allocate the
responsibility |
|
|
Make sure that your contracts define the
procedures that |
|
|
Keep your most sensitive applications in‑house. |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
8.2 DEVELOP PLANS TO PROVIDE FUTURE CAPACITY |
|
|
|
Develop plans to ensure
that adequate information processing |
|
|
Project what your
information processing
capacity |
|
|
Establish the operational requirements of new
|
|
|
Document the operational requirements of new
|
|
|
Test the operational requirements of new |
|
8.2.1 MONITOR USAGE AND MEET FUTURE REQUIREMENTS |
|
|
|
Monitor the demands that are being placed on
your |
|
|
Figure out what your
future information storage |
|
|
Develop plans to ensure that future storage
|
|
|
Make sure that your plans consider the burden
|
|
|
Make sure that your plans respect |
|
|
Figure out what your mainframe computing
capacity |
|
|
Monitor mainframe computer processor usage. |
|
|
Monitor mainframe computer storage usage. |
|
|
Monitor mainframe computer output device usage. |
|
|
Monitor mainframe communication system usage. |
|
|
Identify trends in mainframe computer usage. |
|
|
Make sure that
managers use trend information to identify |
|
|
Make sure that managers use trend |
|
|
Make sure that
managers use trend |
|
8.2.2 USE ACCEPTANCE CRITERIA TO TEST SYSTEMS |
|
|
|
Use acceptance criteria to test new
information |
|
|
Use acceptance criteria to test information
system |
|
|
Use acceptance criteria to test new versions
of |
|
|
Make sure that managers ensure that new
information |
|
|
Make sure that managers ensure that new
information |
|
|
Make sure that managers ensure that new
information |
|
|
Make sure that your acceptance criteria consider |
|
|
Make sure that your acceptance criteria
consider |
|
|
Make sure that your acceptance criteria
consider |
|
|
Make sure that acceptance criteria consider
the need to |
|
|
Make sure that acceptance criteria consider
the need to |
|
|
Make sure that your acceptance criteria
consider the |
|
|
Make sure that your acceptance criteria
consider the need |
|
|
Make sure that acceptance criteria
consider the need to |
|
|
Make sure that your acceptance criteria
consider the need |
|
|
Make sure that your acceptance criteria
consider the need |