ISO IEC 17799 2000TRANSLATED INTO PLAIN ENGLISHSection 11: Business Continuity ManagementDETAILED STANDARD |
||
ISO 17799 2000 is now OBSOLETE. See ISO 27002 2013. |
11.1 DESIGN A CONTINUITY MANAGEMENT PROCESS |
|
|
Develop a business continuity management
process to protect |
|
Make sure that your business continuity
management process is used |
|
Make sure that your business continuity
management process is used |
|
Make sure that your business continuity
management |
|
Make sure that your business continuity
management process is used |
|
Make sure that your business continuity
|
|
Analyze the impact that disasters could
|
|
Analyze the impact that security failures
|
|
Analyze the impact that a loss of service
|
|
Developed contingency plans in order to
|
|
Practice implementing your contingency plans. |
11.1.1 ESTABLISH YOUR CONTINUITY MANAGEMENT PROCESS |
|
|
Establish a process to manage and maintain
|
|
Identify and prioritize your organization’s |
|
Identify the risks that threaten the
|
|
Estimate the likelihood that your organization
will be |
|
Analyze the impact that serious threats could
have |
|
Analyze the impact that interruptions could
|
|
Find solutions to the security problems that
|
|
Find solutions for the security threats and |
|
Increase your security through the
|
|
Formulate business objectives and priorities
|
|
Formulate a business continuity strategy
|
|
Document your business continuity strategy. |
|
Make sure that your business continuity
strategy is consistent |
|
Formulate business continuity plans
|
|
Document your business continuity plans. |
|
Make sure that
your business continuity plans are |
|
Make sure that
responsibility for coordinating your continuity |
|
Institutionalize continuity management. |
11.1.2 PERFORM THREAT ANALYSIS AND IMPACT ANALYSIS |
|
|
Carry out a threat analysis in order to
identify the |
|
Carry out your threat analysis with the full
|
|
Make sure that your threat analysis
|
|
Carried out a risk assessment in order to
identify the |
|
Make sure that your impact analysis identifies
how much |
|
Make sure that your impact analysis identifies
how long it |
|
Carry out your impact analysis with the full
|
|
Make sure that your impact analysis includes all business processes. |
|
Use the results of your analyses and
assessments to develop a strategy |
|
Make sure that your senior management endorses
|
11.1.3 DEVELOP YOUR BUSINESS CONTINUITY PLANS |
|
|
Develop plans to restore and continue business
operations |
|
Make sure that your business continuity plans
|
|
Make sure that business continuity plans help
you to restore |
|
Make sure that your business
continuity plans identify the |
|
Make sure that your business continuity plans
identify the |
|
Make sure that your business continuity plans
identify the |
|
Make sure that your business continuity plans
identify |
|
Make sure that your business continuity plans
define |
|
Make sure that your emergency response
procedures |
|
Make sure that your emergency response
|
|
Make sure that your emergency response
procedures |
|
Document all emergency response procedures. |
|
Document all critical business processes. |
|
Make sure that your business continuity plans
identify |
|
Teach your staff members how to use
|
|
Teach your staff members how critical business
|
|
Teach your staff members about your crisis
|
|
Test your business continuity plans on a regular basis. |
|
Update your business continuity plans on a regular basis. |
11.1.4 MAINTAIN A CONTINUITY PLANNING FRAMEWORK |
|
|
Establish a single framework of business
continuity plans |
|
Use your business continuity planning
|
|
Use your business continuity planning
framework |
|
Make sure that each business continuity plan
includes |
|
Amend your business continuity plans whenever
|
|
Make sure that each business continuity plan
clearly |
|
Make sure that each business continuity plan
|
|
Make sure that each business continuity plan
|
|
Make sure that each business continuity plan
|
|
Make sure that each business continuity plan
specifies |
|
Make sure that each business continuity plan
|
|
Make sure that each business continuity plan
describes |
|
Make sure that each business continuity plan
|
|
Make sure that each business continuity plan
explains |
|
Make sure that each business continuity plan
explains |
|
Make sure that each business continuity plan
|
|
Make sure that each business continuity plan
describes |
|
Make sure that each business continuity plan
describes |
|
Make sure that each business continuity plan
describes the education and |
|
Make sure that each business continuity plan
specifies who |
|
Make sure that owners of business processes
and resources |
|
Make sure that owners of business processes
and resources are |
|
Make sure that technical service providers are
responsible |
|
Make sure that information service providers
are responsible |
|
Make sure that communications service
providers are responsible
|
11.1.5 TEST AND UPDATE CONTINUITY MANAGEMENT PLANS |
|
11.1.5.1 TEST BUSINESS CONTINUITY MANAGEMENT PLANS |
|
|
Test your business continuity management plans
regularly |
|
Evaluate your planning assumptions when you
|
|
Check to see that you haven’t missed anything
important |
|
Make sure that changes in equipment haven’t
compromised |
|
Make sure that changes in personnel haven’t
compromised |
|
Make sure that the personnel who must
implement |
|
Make sure that all recovery team members are
aware |
|
Develop a test schedule that explains how and
when each |
|
Identify examples of business interruptions
and then discuss |
|
Carry out simulations of business
interruptions in |
|
Carry out technical recovery tests in order to
ensure |
|
Carry out recovery tests at alternative backup sites. |
|
Test the ability of suppliers to provide
contracted |
|
Carry out complete rehearsals in order to
ensure that |
11.1.5.2 UPDATE BUSINESS CONTINUITY MANAGEMENT PLANS |
|
|
Use regular reviews and updates to maintain
the |
|
Make sure that your change management program
|
|
Make sure that the responsibility for the
regular review |
|
Make sure that your business continuity
management |
|
Make sure that updated business continuity
management |
|
Make sure that you consider updating |
|
Consider updating business continuity
management |
|
Consider updating business continuity
management |
|
Consider updating business continuity
management plans |
|
Consider updating your business continuity
management |
|
Consider updating your business continuity
management |
|
Consider updating your business continuity
|
|
Consider updating your business continuity
management |
|
Consider updating your business continuity
management |
|
Consider updating your business continuity
management |
|
Consider updating your business continuity
management |
|
Consider updating your continuity management
plans |
|
Consider updating your business continuity
management |
Also see our extensive INFORMATION SECURITY LIBRARY |
Praxiom Research Group Limited help@praxiom.com 780-461-4514 |
|||
Updated on March 27, 2014. First published on October 28, 2004. |
|||
Legal
Restrictions on the Use of this Page
Copyright © 2004 - 2014 by Praxiom Research Group Limited. All Rights Reserved. |