c) the backups should be stored in a remote location, at a sufficient distance to escape any damage from a disaster at the main site; d) backup information should be given an appropriate level of physical and environmental protection consistent with the standards applied at the main site; e) backup media should be regularly tested to ensure that they can be relied upon for emergency use when necessary; this should be combined with a test of the restoration procedures and checked against the restoration time required. Testing the ability to restore backed-up data should be performed onto dedicated test media, not by overwriting the original media in case the backup or restoration process fails and causes irreparable data damage or loss; f) in situations where confidentiality is of importance, backups should be protected by means of encryption. Operational procedures should monitor the execution of backups and address failures of scheduled backups to ensure completeness of backups according to the backup policy. Backup arrangements for individual systems and services should be regularly tested to ensure that they meet the requirements of business continuity plans. In the case of critical systems and services, backup arrangements should cover all systems information, applications and data necessary to recover the complete system in the event of a disaster. The retention period for essential business information should be determined, taking into account any requirement for archive copies to be permanently retained. (NL ISO/IEC, 2015) 8. Logging and Monitoring Event logs recording user activities, exceptions, faults and information security events should be produced, kept and regularly reviewed. Event logs should include, when relevant: a) user IDs; b) system activities; c) dates, times and details of key events, e.g. log-on and log-off; d) device identity or location if possible and system identifier; e) records of successful and rejected system access attempts; f) records of successful and rejected data and other resource access attempts; g) changes to system configuration; h) use of privileges; i) use of system utilities and applications; j) files accessed and the kind of access; k) network addresses and protocols; l) alarms raised by the access control system; m) activation and de-activation of protection systems, such as anti-virus systems and intrusion detection systems; Lebanese National Security Policy Guidelines v1.7 Page 48 |

Select target paragraph3