d) other than in exceptional circumstances, testing should not be done on operational systems; e) compilers, editors and other development tools or system utilities should not be accessible from operational systems when not required; f) users should use different user profiles for operational and testing systems, and menus should display appropriate identification messages to reduce the risk of error; g) sensitive data should not be copied into the testing system environment unless equivalent controls are provided for the testing system. Development and testing activities can cause serious problems, e.g. unwanted modification of files or system environment or system failure. There is a need to maintain a known and stable environment in which to perform meaningful testing and to prevent inappropriate developer access to the operational environment. Development and testing personnel also pose a threat to the confidentiality of operational information. Development and testing activities may cause unintended changes to software or information if they share the same computing environment. Separating development, testing and operational environments is therefore desirable to reduce the risk of accidental change or unauthorized access to operational software and business data. (NL ISO/IEC, 2015) 7. Information Backup Backup copies of information, software and system images should be taken and tested regularly in accordance with an agreed backup policy. “Being too busy to worry about A backup policy should be established to define the backup is like being too busy driving a organization’s requirements for backup of car to put on a seatbelt.” information, software and systems. – T.E. Ronneberg– Writer, and web developer from Sydney, Australia The backup policy should define the retention and protection requirements. Adequate backup facilities should be provided to ensure that all essential information and software can be recovered following a disaster or media failure. When designing a backup plan, the following items should be taken into consideration: a) accurate and complete records of the backup copies and documented restoration procedures should be produced; b) the extent (e.g. full or differential backup) and frequency of backups should reflect the business requirements of the organization, the security requirements of the information involved and the criticality of the information to the continued operation of the organization; Lebanese National Security Policy Guidelines v1.7 Page 47 |

Select target paragraph3