Organizational, technical, procedural and process changes, whether in an operational or
continuity context, can lead to changes in information security continuity requirements. In such
cases, the continuity of processes, procedures and controls for information security should be
reviewed against these changed requirements.
Organizations should verify their information security management continuity by:
a) exercising and testing the functionality of information security continuity processes,
procedures and controls to ensure that they are consistent with the information
security continuity objectives;
b) exercising and testing the knowledge and routine to operate information security
continuity processes, procedures and controls to ensure that their performance is
consistent with the information security continuity objectives;
c) reviewing the validity and effectiveness of information security continuity measures
when information systems, information security processes, procedures and controls
or business continuity management/disaster recovery management processes and
solutions change.
The verification of information security continuity controls is different from general information
security testing and verification and should be performed outside the testing of changes. If
possible, it is preferable to integrate verification of information security continuity controls with
the organization’s business continuity or disaster recovery tests. (NL ISO/IEC, 2015)
14. Redundancies and Availability of Information Processing Facilities
The objective is to ensure availability of information processing facilities.
Information processing facilities should be implemented with redundancy sufficient to meet
availability requirements.
Organizations should identify business requirements for the availability of information systems.
Where the availability cannot be guaranteed using the existing systems architecture, redundant
components or architectures should be considered.
Where applicable, redundant information systems should be tested to ensure the failover from
one component to another component works as intended.
The implementation of redundancies can introduce risks to the integrity or confidentiality of
information and information systems, which need to be considered when designing information
systems. (NL ISO/IEC, 2015)
Lebanese National Security Policy Guidelines v1.7
Page
52 |