UNCLASSIFIED GV5 – All organisations must implement appropriate business continuity (BC) and disaster recovery (DR) programmes to minimise the impact of and ensure the timely recovery from interruptions that may result from natural disasters, accidents, equipment failures and deliberate actions. As a minimum requirement, organisations must have in place: (a) a BC management strategy that takes a long-term view of organisational continuity needs; (b) a policy outlining management direction and support for business continuity; (c) BC and DR plans for all locations; and, (d) systematic BC/DR testing, reporting and maintenance procedures for all critical infrastructure. To achieve the security outcomes mandated above, organisations must: 4.7  Address information security needs of organisational business continuity;  Establish the criticality of different facilities, systems, sites and networks by performing a business impact analysis of the unavailability of each asset;  Identify and assess the probability and the information security impacts of events that could cause interruptions to business operations e.g. fire, theft;  Adopt a common business continuity planning framework to ensure that all plans address information security requirements consistently;  Ensure that continuity plans support correct information security levels;  Test, audit and update business continuity plans regularly to ensure their effectiveness in an event of an emergency;  Have put in place up-to-date and effective disaster recovery plans for critical infrastructure systems to minimise the impact of security incidents; and  Report on BC/DR activities at least once a year. Incident Management Incident management aims to demonstrate that the organisation is reducing the likelihood and impact of security incidents and ensuring the quick resumption of business activities in line with the mandatory minimum-security outcomes below. GV6 – All organisations with critical infrastructure must have a formal security incident management process to enable the accurate and timely identification, communication, investigation and response to security events and weaknesses. As a minimum requirement, the process must: (a) formally establish management’s accountability for incident management; (b) define roles and responsibilities; (c) include tested policies, plans and procedures; (d) ensure staff obtain specialist incident response training; (e) promote an incident reporting culture; and, (f) quantify, monitor and learn from incidents. To achieve the security outcomes mandated above, organisations must: 18

Select target paragraph3