The goal of business continuity planners is to implement a combination of policies, procedures, and processes such that a potentially disruptive event has as little impact on the business as possible (Stewart et al., 2004). 3. Documented Operating Procedures Operating procedures should be documented and made available to all users who need them. Documented procedures should be prepared for operational activities associated with information processing and communication facilities, such as computer start-up and closedown procedures, backup, equipment maintenance, media handling, computer room and mail handling management and safety. The operating procedures should specify the operational instructions, including: a) the installation and configuration of systems; b) processing and handling of information both automated and manual; c) backup; d) scheduling requirements, including interdependencies with other systems, earliest job start and latest job completion times; e) instructions for handling errors or other exceptional conditions, which might arise during job execution, including restrictions on the use of system utilities; f) support and escalation contacts including external support contacts in the event of unexpected operational or technical difficulties; g) special output and media handling instructions, such as the use of special stationery or the management of confidential output including procedures for secure disposal of output from failed jobs; h) system restart and recovery procedures for use in the event of system failure; i) the management of audit-trail and system log information; j) monitoring procedures. Operating procedures and the documented procedures for system activities should be treated as formal documents and changes authorized by management. Where technically feasible, information systems should be managed consistently, using the same procedures, tools and utilities. (NL ISO/IEC, 2015) 4. Patch and Vulnerability Management Information about technical vulnerabilities of information systems being used should be obtained in a timely fashion, the organization’s exposure to such vulnerabilities evaluated and appropriate measures taken to address the associated risk. Lebanese National Security Policy Guidelines v1.7 Page 44 |

Select target paragraph3