necessary, improve the availability and efficiency of systems. Detective controls should be put in place to indicate problems in due time. Projections of future capacity requirements should take account of new business and system requirements and current and projected trends in the organization’s information processing capabilities. Particular attention needs to be paid to any resources with long procurement lead times or high costs; therefore managers should monitor the utilization of key system resources. They should identify trends in usage, particularly in relation to business applications or information systems management tools. Managers should use this information to identify and avoid potential bottlenecks and dependence on key personnel that might present a threat to system security or services, and plan appropriate action. Providing sufficient capacity can be achieved by increasing capacity or by reducing demand. Examples of managing capacity demand include: a) deletion of obsolete data (disk space); b) decommissioning of applications, systems, databases or environments; c) optimising batch processes and schedules; d) optimising application logic or database queries; e) denying or restricting bandwidth for resource-hungry services if these are not business critical (e.g. video streaming). A documented capacity management plan should be considered for mission critical systems. This control also addresses the capacity of the human resources, as well as offices and facilities. (NL ISO/IEC, 2015) 6. Separation of Development, Testing and Operational Environments Development, testing, and operational environments should be separated to reduce the risks of unauthorized access or changes to the operational environment. The level of separation between operational, testing, and development environments that is necessary to prevent operational problems should be identified and implemented. The following items should be considered: a) rules for the transfer of software from development to operational status should be defined and documented; b) development and operational software should run on different systems or computer processors and in different domains or directories; c) changes to operational systems and applications should be tested in a testing or staging environment prior to being applied to operational systems; Lebanese National Security Policy Guidelines v1.7 Page 46 |

Select target paragraph3