necessary, improve the availability and efficiency of systems. Detective controls should be put
in place to indicate problems in due time. Projections of future capacity requirements should
take account of new business and system requirements and current and projected trends in the
organization’s information processing capabilities.
Particular attention needs to be paid to any resources with long procurement lead times or high
costs; therefore managers should monitor the utilization of key system resources. They should
identify trends in usage, particularly in relation to business applications or information systems
management tools.
Managers should use this information to identify and avoid potential bottlenecks and
dependence on key personnel that might present a threat to system security or services, and
plan appropriate action.
Providing sufficient capacity can be achieved by increasing capacity or by reducing demand.
Examples of managing capacity demand include:
a) deletion of obsolete data (disk space);
b) decommissioning of applications, systems, databases or environments;
c) optimising batch processes and schedules;
d) optimising application logic or database queries;
e) denying or restricting bandwidth for resource-hungry services if these are not
business critical (e.g. video streaming).
A documented capacity management plan should be considered for mission critical systems.
This control also addresses the capacity of the human resources, as well as offices and facilities.
(NL ISO/IEC, 2015)
6. Separation of Development, Testing and Operational Environments
Development, testing, and operational environments should be separated to reduce the risks of
unauthorized access or changes to the operational environment.
The level of separation between operational, testing, and development environments that is
necessary to prevent operational problems should be identified and implemented.
The following items should be considered:
a) rules for the transfer of software from development to operational status should be
defined and documented;
b) development and operational software should run on different systems or computer
processors and in different domains or directories;
c) changes to operational systems and applications should be tested in a testing or
staging environment prior to being applied to operational systems;
Lebanese National Security Policy Guidelines v1.7
Page
46 |