including information technology services. 9.2. Policy & Baseline Controls In order to comply with this policy, Agencies MUST ensure: BC 1. *A person is appointed to own and manage the Business Continuity Programme. BC 2. *A Business Continuity (BC) Plan is prepared to ensure continuance of critical processes and the delivery of essential services to an acceptable level. This plan SHALL include, and be based on Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each Agency process. BC 3. The BC Plan covers disaster scenarios possible and adequate and includes disaster recovery provisions. BC 4. *The BC Plan is maintained and updated to reflect the current status and requirements and relevant information is made available for all team members, employees and service providers. BC 5. A copy of the up to date BC Plan along with the necessary backup data tapes media and information is stored in a fire/tamper proof safe, along with an additional copy stored in an off-site location. Best practices state that offsite location must be in a geographically different zone than the primary data centre. BC 6. They identify alternate disaster recovery sites, whose readiness is determined by the RTO requirements. These sites may be Hot/Warm/Cold Sites depending upon the Agency’s requirements. BC 7. They specify strong controls in contracts that involve outsourcing a portion of their business or information technology functions or business continuity services. BC 8. The BC Plan is periodically tested at least on an annual basis or when significant changes take place in the business or legal/regulatory requirements. BC 9. *Awareness about the BC plan is created amongst its employeess. 10. Logging & Security Monitoring [SM] 10.1. Policy Objective The aim of this policy is to provide requirements for logging and monitoring to identify unauthorized data, application and resource access and to detect unauthorized changes or access privileges abuse. 10.2. Policy & Baseline Controls To meet the requirements of this Policy, Agencies SHALL ensure that: SM 1. *Adequate set of technical control implementations, or processes exist for logging, identification and continuous monitoring of access, changes, command execution to, any/ all information assets for protection of business sensitive information. SM 2. *Monitoring practices are established in accordance with criticality of the infrastructure , data, and applications. It is RECOMMENDED to provide a 24/7 monitoring for C3, I3 and A3 classified infrastructures and ensure that monitoring responsibilities are allocated as specified in clause PS9, section B- 6, Personnel Security [PS]. SM 3. Monitoring activity is in line with regulatory and legal frameworks such as the proposed Information Privacy & Protection Law and SHALL cover use or access to systems. SM 4. *They enable logging on all infrastructure and data processing equipment, and applications that are associated with the access, transmission, processing, security, storage, and/or handing of information classified with a confidentiality rating of C2 and above. SM 5. They classify all security logs with a confidentiality rating of C3, while application and system logs SHALL be classified in accordance with the confidentiality rating of the system. SM 6. Logs containing Personal Information have appropriate privacy protection measures in place, in NATIONAL INFORMATION ASSURANCE MANUAL 24

Select target paragraph3