standards evolution government policy or Cabinet directives threat or vulnerability notification other incidents or continuous improvement activities A proposed change to a system could involve: an upgrade to, or introduction of, IT equipment an upgrade to, or introduction of, software environment or infrastructure change major changes to access controls The accreditation of a system accepts residual security risk relating to the operation of that system. Changes may impact the overall security risk for the system. It is essential that the Accreditation Authority is consulted and accepts the changes and any changes to risk. 9.4. Business Continuity and Disaster Recovery Objective: Mandatory Control 1: Recommended Control 1: Recommended Control 2: Recommended Control 3: To ensure business continuity and disaster recovery processes are established to assist in meeting the agency’s business requirements, minimize any disruption to the availability of information and systems, and assist recoverability Agencies must determine availability and recovery requirements for their systems and implement appropriate measures to support them Agencies should: identify vital records backup all vital records store backups of critical information, with associated documented recovery procedures, at a remote location secured in accordance with the requirements test backup and restoration processes regularly to confirm their effectiveness Agencies should develop and document a business continuity plan Agencies should develop and document a disaster recovery plan Availability and recovery requirements will vary based on each agency’s business needs and are likely to be widely variable across government. Agencies will determine their own availability and recovery requirements and implement appropriate measures to achieve them as part of their risk management and governance processes. 40

Select target paragraph3