the business continuity management process or within the disaster recovery management
process.
Information security requirements should be determined when planning for business continuity
and disaster recovery.
In the absence of formal business continuity and disaster recovery planning, information
security management should assume that information security requirements remain the same
in adverse situations, compared to normal operational conditions. Alternatively, an
organization could perform a business impact analysis for information security aspects to
determine the information security requirements applicable to adverse situations. (NL ISO/IEC,
2015)
12. Implementing Information Security Continuity
The organization should establish, document, implement and maintain processes, procedures
and controls to ensure the required level of continuity for information security during an
adverse situation.
An organization should ensure that:
a) an adequate management structure is in place to prepare for, mitigate and respond
to a disruptive event using personnel with the necessary authority, experience and
competence;
b) incident response personnel with the necessary responsibility, authority and
competence to manage an incident and maintain information security are
nominated;
c) documented plans, response and recovery procedures are developed and approved,
detailing how the organization will manage a disruptive event and will maintain its
information security to a predetermined level, based on management-approved
information security continuity objectives.
Within the context of business continuity or disaster recovery, specific processes and
procedures may have been defined. Information that is handled within these processes and
procedures or within dedicated information systems to support them should be protected.
Therefore an organization should involve information security specialists when establishing,
implementing and maintaining business continuity or disaster recovery processes and
procedures. (NL ISO/IEC, 2015)
13. Verify, Review and Evaluate Information Security Continuity
The organization should verify the established and implemented information
security continuity controls at regular intervals in order to ensure that they are
valid and effective during adverse situations.
Lebanese National Security Policy Guidelines v1.7
Page
51 |