|
An Introduction To |
|
Operational procedures and responsibilitiesObjective: To ensure the correct and secure operation of information processing facilities Responsibilities and procedures for the management of all computers, networks and information processing facilities should be established. Documented operating proceduresThe operating procedures identified by the Information Security Policy relating to all information processing should be documented and maintained under formal change control. Change managementAll changes to operational information processing facilities and systems should be controlled. Segregation of dutiesSegregation of duties should be considered to minimise the risk of negligent or deliberate system misuse. Separation of development, test and operational facilitiesDevelopment and testing facilities should be isolated from operational systems. Rules for the promotion of software to operational status should be defined and documented. |
The Security Practitioner An Introduction to Information Security |