UNCLASSIFIED
GV5 – All organisations must implement appropriate business continuity (BC)
and disaster recovery (DR) programmes to minimise the impact of and
ensure the timely recovery from interruptions that may result from natural
disasters, accidents, equipment failures and deliberate actions. As a
minimum requirement, organisations must have in place: (a) a BC
management strategy that takes a long-term view of organisational continuity
needs; (b) a policy outlining management direction and support for business
continuity; (c) BC and DR plans for all locations; and, (d) systematic BC/DR
testing, reporting and maintenance procedures for all critical infrastructure.
To achieve the security outcomes mandated above, organisations must:
4.7
Address information security needs of organisational business continuity;
Establish the criticality of different facilities, systems, sites and networks by
performing a business impact analysis of the unavailability of each asset;
Identify and assess the probability and the information security impacts of
events that could cause interruptions to business operations e.g. fire, theft;
Adopt a common business continuity planning framework to ensure that all
plans address information security requirements consistently;
Ensure that continuity plans support correct information security levels;
Test, audit and update business continuity plans regularly to ensure their
effectiveness in an event of an emergency;
Have put in place up-to-date and effective disaster recovery plans for critical
infrastructure systems to minimise the impact of security incidents; and
Report on BC/DR activities at least once a year.
Incident Management
Incident management aims to demonstrate that the organisation is reducing the
likelihood and impact of security incidents and ensuring the quick resumption of
business activities in line with the mandatory minimum-security outcomes below.
GV6 – All organisations with critical infrastructure must have a formal security
incident management process to enable the accurate and timely
identification, communication, investigation and response to security events
and weaknesses. As a minimum requirement, the process must: (a) formally
establish management’s accountability for incident management; (b) define
roles and responsibilities; (c) include tested policies, plans and procedures;
(d) ensure staff obtain specialist incident response training; (e) promote an
incident reporting culture; and, (f) quantify, monitor and learn from incidents.
To achieve the security outcomes mandated above, organisations must:
18