d) other than in exceptional circumstances, testing should not be done on operational
systems;
e) compilers, editors and other development tools or system utilities should not be
accessible from operational systems when not required;
f) users should use different user profiles for operational and testing systems, and
menus should display appropriate identification messages to reduce the risk of
error;
g) sensitive data should not be copied into the testing system environment unless
equivalent controls are provided for the testing system.
Development and testing activities can cause serious problems, e.g. unwanted modification of
files or system environment or system failure. There is a need to maintain a known and stable
environment in which to perform meaningful testing and to prevent inappropriate developer
access to the operational environment.
Development and testing personnel also pose a threat to the confidentiality of operational
information. Development and testing activities may cause unintended changes to software or
information if they share the same computing environment. Separating development, testing
and operational environments is therefore desirable to reduce the risk of accidental change or
unauthorized access to operational software and business data. (NL ISO/IEC, 2015)
7. Information Backup
Backup copies of information, software and system images should be taken and tested regularly
in accordance with an agreed backup policy.
“Being too busy to worry about
A backup policy should be established to define the
backup is like being too busy driving a
organization’s requirements for backup of
car to put on a seatbelt.”
information, software and systems.
– T.E. Ronneberg– Writer, and web
developer from Sydney, Australia
The backup policy should define the retention and
protection requirements.
Adequate backup facilities should be provided to ensure that all essential information and
software can be recovered following a disaster or media failure.
When designing a backup plan, the following items should be taken into consideration:
a) accurate and complete records of the backup copies and documented restoration
procedures should be produced;
b) the extent (e.g. full or differential backup) and frequency of backups should reflect
the business requirements of the organization, the security requirements of the
information involved and the criticality of the information to the continued
operation of the organization;
Lebanese National Security Policy Guidelines v1.7
Page
47 |