Zusammenfassung der Ressource
Security Mgt U8,
Information
Assurance
- information assurance concerned with
- confidentiality
- integrity
- availability
- legality
- business continuity planning (BCP)
- Tested plans and procedures built into the
normal operations processes which allow
a business to protect itself against threats
- includes
- damage limitation
- recovery
- emergency response
- crisis management
- monitoring
- mitigation
- acceptance of residual risk
- stakeholders
- employees
- bankers
- suppliers
- regulators
- finance
- competitors
- shareholders
- goal
- recovery reducing
the impact from
untoward events
- things to identify during
planning (see attached
chart)
Anlagen:
- what is "normal" output
- minimum acceptable output
level for business
- how long it will take to get
back to full production
- steps for
replacement
and repair
- resumption time
- this is the time from the
incident to the
achieving minimal
acceptable output level
- NOT a technical issue
- board level accountability
- ownership by
business and
operations
- stress test based
- NOT disaster recovery planning
- DRP focuses on
technology (limited
scope) whereas BCP
focuses on business
processes
- legislation, standards
and organizations that
provide guidance
- Nimda
- Code Red
- SANS
- Turnbull compliance
- Basel 2
- ISO 17799
- why?
- minimize incident impact on org &
recover from loss of information
assets to an acceptable level
through a combo of preventative
and recovery controls