Chapter 4 Business Continuity Plan |
Article 12 | (System Backup)
- An organization shall prescribe the duration of the information and communication system’s tolerance of data loss.
- An organization shall make a backup of the source codes and data of programs of the information and communication system.
- An organization shall test the backup information of the information and communication system on a regular basis to verify the reliability of the backup media and exhaustiveness of the information.
- A core system of a type 1 organization shall restore backups as part of the test of the business continuity plan.
- A core system of a type 1 organization shall store backups of important information and communication system software and other security related information in independent facilities or fireproof cabinets at a location different from that of the operating system.
|
|
Article 13 | (Redundancy)
- An organization shall prescribe the tolerable time from interruption to recovery of the information and communication system.
- When a service of the information and communication system is interrupted, an organization shall render the service using backup equipment or other means within the tolerable time.
- An organization shall develop contingency procedures to respond to material information system incidents or acts of God and shall confirm the corresponding resources to ensure reasonable impact of a material disaster on major operations and businesses.
|
|