including information technology services.
9.2. Policy & Baseline Controls
In order to comply with this policy, Agencies MUST ensure:
BC 1.
*A person is appointed to own and manage the Business Continuity Programme.
BC 2.
*A Business Continuity (BC) Plan is prepared to ensure continuance of critical processes
and the delivery of essential services to an acceptable level. This plan SHALL include,
and be based on Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
for each Agency process.
BC 3.
The BC Plan covers disaster scenarios possible and adequate and includes disaster recovery
provisions.
BC 4.
*The BC Plan is maintained and updated to reflect the current status and requirements
and relevant information is made available for all team members, employees and service
providers.
BC 5.
A copy of the up to date BC Plan along with the necessary backup data tapes media and information
is stored in a fire/tamper proof safe, along with an additional copy stored in an off-site location.
Best practices state that offsite location must be in a geographically different zone than the primary
data centre.
BC 6.
They identify alternate disaster recovery sites, whose readiness is determined by the RTO
requirements. These sites may be Hot/Warm/Cold Sites depending upon the Agency’s requirements.
BC 7.
They specify strong controls in contracts that involve outsourcing a portion of their business or
information technology functions or business continuity services.
BC 8.
The BC Plan is periodically tested at least on an annual basis or when significant changes take
place in the business or legal/regulatory requirements.
BC 9.
*Awareness about the BC plan is created amongst its employeess.
10. Logging & Security Monitoring [SM]
10.1. Policy Objective
The aim of this policy is to provide requirements for logging and monitoring to identify unauthorized data, application
and resource access and to detect unauthorized changes or access privileges abuse.
10.2. Policy & Baseline Controls
To meet the requirements of this Policy, Agencies SHALL ensure that:
SM 1.
*Adequate set of technical control implementations, or processes exist for logging,
identification and continuous monitoring of access, changes, command execution to, any/
all information assets for protection of business sensitive information.
SM 2.
*Monitoring practices are established in accordance with criticality of the infrastructure
, data, and applications. It is RECOMMENDED to provide a 24/7 monitoring for C3, I3 and A3
classified infrastructures and ensure that monitoring responsibilities are allocated as specified in
clause PS9, section B- 6, Personnel Security [PS].
SM 3.
Monitoring activity is in line with regulatory and legal frameworks such as the proposed Information
Privacy & Protection Law and SHALL cover use or access to systems.
SM 4.
*They enable logging on all infrastructure and data processing equipment, and applications
that are associated with the access, transmission, processing, security, storage, and/or
handing of information classified with a confidentiality rating of C2 and above.
SM 5.
They classify all security logs with a confidentiality rating of C3, while application and system logs
SHALL be classified in accordance with the confidentiality rating of the system.
SM 6.
Logs containing Personal Information have appropriate privacy protection measures in place, in
NATIONAL INFORMATION ASSURANCE MANUAL
24