The goal of business continuity planners is to implement a combination of policies, procedures,
and processes such that a potentially disruptive event has as little impact on the business as
possible (Stewart et al., 2004).
3. Documented Operating Procedures
Operating procedures should be documented and made available to all users who need them.
Documented procedures should be prepared for operational
activities associated with information processing and
communication facilities, such as computer start-up and closedown procedures, backup, equipment maintenance, media
handling, computer room and mail handling management and
safety.
The operating procedures should specify the operational instructions, including:
a) the installation and configuration of systems;
b) processing and handling of information both automated and manual;
c) backup;
d) scheduling requirements, including interdependencies with other systems, earliest
job start and latest job completion times;
e) instructions for handling errors or other exceptional conditions, which might arise
during job execution, including restrictions on the use of system utilities;
f) support and escalation contacts including external support contacts in the event of
unexpected operational or technical difficulties;
g) special output and media handling instructions, such as the use of special stationery
or the management of confidential output including procedures for secure disposal
of output from failed jobs;
h) system restart and recovery procedures for use in the event of system failure;
i) the management of audit-trail and system log information;
j) monitoring procedures.
Operating procedures and the documented procedures for system activities should be treated
as formal documents and changes authorized by management. Where technically feasible,
information systems should be managed consistently, using the same procedures, tools and
utilities. (NL ISO/IEC, 2015)
4. Patch and Vulnerability Management
Information about technical vulnerabilities of information systems being used should be
obtained in a timely fashion, the organization’s exposure to such vulnerabilities evaluated and
appropriate measures taken to address the associated risk.
Lebanese National Security Policy Guidelines v1.7
Page
44 |