c) the backups should be stored in a remote location, at a sufficient distance to escape
any damage from a disaster at the main site;
d) backup information should be given an appropriate level of physical and
environmental protection consistent with the standards applied at the main site;
e) backup media should be regularly tested to ensure that they can be relied upon for
emergency use when necessary; this should be combined with a test of the
restoration procedures and checked against the restoration time required. Testing
the ability to restore backed-up data should be performed onto dedicated test
media, not by overwriting the original media in case the backup or restoration
process fails and causes irreparable data damage or loss;
f) in situations where confidentiality is of importance, backups should be protected by
means of encryption.
Operational procedures should monitor the execution of backups and address failures of
scheduled backups to ensure completeness of backups according to the backup policy.
Backup arrangements for individual systems and services should be regularly tested to ensure
that they meet the requirements of business continuity plans. In the case of critical systems and
services, backup arrangements should cover all systems information, applications and data
necessary to recover the complete system in the event of a disaster.
The retention period for essential business information should be determined, taking into
account any requirement for archive copies to be permanently retained. (NL ISO/IEC, 2015)
8. Logging and Monitoring
Event logs recording user activities, exceptions, faults and information security events should
be produced, kept and regularly reviewed.
Event logs should include, when relevant:
a) user IDs;
b) system activities;
c) dates, times and details of key events, e.g. log-on and log-off;
d) device identity or location if possible and system identifier;
e) records of successful and rejected system access attempts;
f) records of successful and rejected data and other resource access attempts;
g) changes to system configuration;
h) use of privileges;
i) use of system utilities and applications;
j) files accessed and the kind of access;
k) network addresses and protocols;
l) alarms raised by the access control system;
m) activation and de-activation of protection systems, such as anti-virus systems and
intrusion detection systems;
Lebanese National Security Policy Guidelines v1.7
Page
48 |