standards evolution
government policy or Cabinet directives
threat or vulnerability notification
other incidents or continuous improvement activities
A proposed change to a system could involve:
an upgrade to, or introduction of, IT equipment
an upgrade to, or introduction of, software
environment or infrastructure change
major changes to access controls
The accreditation of a system accepts residual security risk relating to the operation of that system.
Changes may impact the overall security risk for the system. It is essential that the Accreditation
Authority is consulted and accepts the changes and any changes to risk.
9.4.
Business Continuity and Disaster Recovery
Objective:
Mandatory Control 1:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
To ensure business continuity and disaster recovery processes are
established to assist in meeting the agency’s business
requirements, minimize any disruption to the availability of
information and systems, and assist recoverability
Agencies must determine availability and recovery requirements
for their systems and implement appropriate measures to support
them
Agencies should:
identify vital records
backup all vital records
store backups of critical information, with associated
documented recovery procedures, at a remote location
secured in accordance with the requirements
test backup and restoration processes regularly to confirm
their effectiveness
Agencies should develop and document a business continuity plan
Agencies should develop and document a disaster recovery plan
Availability and recovery requirements will vary based on each agency’s business needs and are
likely to be widely variable across government. Agencies will determine their own availability and
recovery requirements and implement appropriate measures to achieve them as part of their risk
management and governance processes.
40