lagen.nu
Example Assessment Templates

Example Assessment Templates

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2010-03-24
Språk
engelska
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

IT Business Continuity Management

January 10 An approach for Small Medium Sized Organizations – Annexes G - H - Templates About ENISA The European Network and Information Security Agency (ENISA) is an EU agency created to advance the functioning of the internal market. ENISA is a centre of excellence for the European Member States and European institutions in network and information security, giving advice and recommendations and acting as a switchboard of information for good practices. Moreover, the agency facilitates contacts between the European institutions, the Member States and private business and industry actors. Contact details:

For contacting ENISA or for general enquiries on BCP for SMEs, please use the following details:

e-mail: Dr. L. Marinos, Senior Expert — louis.marinos@enisa.europa.eu Charalambos Koutsouris, Seconded National Expert, charalampos.koutsouris@enisa.europa.eu Internet: http://www.enisa.europa.eu/

Legal notice Notice must be taken that this publication represents the views and interpretations of the authors and editors, unless stated otherwise. This publication should not be construed to be an action of ENISA or the ENISA bodies unless adopted pursuant to the ENISA Regulation (EC) No 460/2004. This publication does not necessarily represent state-of the-art and it might be updated from time to time. Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication. © European Network and Information Security Agency (ENISA), 2010 Document Revision: 1.0 This publication is intended for educational and information purposes only. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. Reproduction is authorised provided the source is acknowledged.

BCM: An approach for SMEs BCM: An approach for SMEs – Templates Annex G - H

Annex G – Useful Templates

This section of the report presents the necessary templates which the Assessment Teams should use in order to execute the proposed Business Continuity Management approach. For each template the Name and description of the template is provided as well the phase(s) and step(s) where the template is used / reused.

Risk Profile Evaluation Table – Phase 1, Step 1

Risk Areas High Medium Low

Legal and The organization handles The organization handles personal The organization does not Regulatory sensitive/personal customer customer information as defined handle personal data of information as defined by the EU by the EU Data Protection Law. individuals other than those Data Protection Law. Loss and / or destruction of the employed by the organization. Retention of the aforementioned aforementioned data will lead to Retention of the data is mandatory by Government legal fines from Regulatory Bodies. aforementioned data is not Regulations. Loss and / or Failure to meet agreed SLAs with mandatory by Government destruction of this data will lead to corporate customers regarding Regulations. Loss and / or significant legal fines from availability of product and / or destruction of the data will not Regulatory Bodies. service offerings may result in non- lead to legal fines from Failure to meet agreed SLAs with frivolous lawsuits. Regulatory Bodies. corporate customers regarding Failure to meet agreed SLAs availability of product and / or with corporate customers service offerings will result in non- regarding availability of product frivolous lawsuits. and / or service offerings may result in frivolous lawsuits.

Productivity Services and operational processes Services and operational processes Services and operational are highly dependent on are highly dependent on processes are not directly information systems, applications information systems, applications dependent on information and third party services. and third party services. systems, applications and third Interruptions to the provisioning of Interruptions to the provisioning of party services. these services or to operational these services or to operational Interruptions to the provisioning processes will generate intolerable processes have severe impact. of these services or to direct or indirect impact to However the organization can operational processes is productivity. Significant expenses continue operations by switching tolerable since the organization and effort are required to resume to backup (e.g. manual) is performing most critical business and recover from market procedures for a limited period of operations with other means loss. time without significantly affecting (e.g. manually) or can continue Provision of these services with its productivity. operations by switching to manual procedures at the agreed manual procedures for a period quality is not possible. of time without affecting its productivity.

Financial Unavailability of products and Unavailability of products and Unavailability of products and Stability services of less than one day lead services of less than one day lead services of less than one day to a major one time financial loss to a significant one time financial lead to no or marginal one time and cannot be tolerated. loss. financial loss. Yearly revenues are directly Yearly revenues are indirectly Yearly revenues are not directly related to the continuous and related to the continuous and or indirectly related to the uninterrupted provision of on-line uninterrupted provision of online continuous and uninterrupted services (i.e. sales are performed services (i.e. products and Services provision of on-line services. online). are supported with on-line Unavailability of online presence

BCM: An approach for SMEs

Unavailability of online presence services). will not lead to direct or indirect will lead to direct financial loss as Unavailability of online presence financial loss as services major services are provided by will not lead to direct financial loss provided online can be provided using e-business applications. as services provided on-line can be by using alternative means (e.g. Fines that may incur due to non- provided by using alternative semi-automated, manually, compliance with legal and means (e.g. semi-automated, etc.). regulatory requirements may lead manually, etc.). No or marginal fines will incur to intolerable financial loss. Fines that may incur due to non- due to non-compliance with compliance with legal and legal and regulatory regulatory requirements are requirements. If any, they possible but will not affect financial cannot affect financial stability. stability.

Reputation and Unavailability of service has direct Unavailability of service has direct Unavailability of service cannot Loss of impact on reputation, resulting impact on reputation, resulting have impact on reputation, Customer thus in significant loss of thus in considerable loss of remaining thus unnoticed or Confidence customers using products and customers using products and marginally noticed by services though automated services though automated customers. interfaces. interfaces.

Table 1: Risk Profile Evaluation Table Risk Profile Selection Table – Phase 1, Step 2 – Phase 3, Step 1

The risk profile selection table is the output the organizational risk determined by the Assessment Team during step 1 illustrating the identified risk levels in the predefined risk areas; the highest risk identified in a risk class defines the overall business risk profile.

Risk Profile Selection Table

Risk Areas Risk Level Risk Profile

Legal and Regulatory

Productivity

Financial Stability

Reputation and Loss of Customer Confidence

Table 2: Risk Profile Selection BCM: An approach for SMEs – Templates Annex G - H Critical Business Function Profile Card – Phase 2, Step 1

Critical Business Function Profile Card Critical Business Function Recovery Priority Who controls the function Who is responsible for delivering the function? Who is the user? (Who benefits / needs this function? / why is it critical?) How is it used?

Table 3: Detailsof the critical Business Function “Finance” Critical Business Function Table – Business Continuity Scope – Phase 2, Step 1

The Assessment Team compiles a table listing the corporate critical business functions along with the rationale for selection and the recovery priority of each business function. Critical Business Function – Business Continuity Scope Critical Business Function Rationale for Selection Recovery Priority (High, Medium, Low) Production Customer Relationship Human Resource Finance New Product Acquisition / Development.

Table 4: Critical Business Functions of example organisation BCM: An approach for SMEs Business Function Supporting IT Assets – Phase 2, Step 2

The Assessment Team selects the asset types, which are used to provide the selected critical business function(s) to the organization’s employees identified during phase 2, step 1. The Assessment Team ends up with a matrix -for each identified critical business function- identifying the supporting assets used to provide the organization’s business function(s).

Critical Business Function Supporting IT Assets Critical Business Function Name Supporting Assets Hardware Network Back Office Application Client Facing Applications People Data Facilities

Table 5: Critical Business Function Supporting IT Assets BCM: An approach for SMEs – Templates Annex G - H Hardware/Network/Application Asset Identification Card – Phase 2, Step 3

The Assessment Teams produce asset identification cards in order to gather information produced during phase 2, steps 1 and 2. These cards will be used to select the appropriate asset based controls –Phase 3, Step 2- for the protection of the organization’s critical assets. Asset Identification Card Card Creation/Update Date Asset Category Asset Name Asset Description Asset Owner Asset Location Asset Maintainer Aggregated Recovery Priority Supported Business Func#1 Assets role /usage in function Recovery Priority Requirement Asset users Supported Business Func#2 Assets role /usage in function Recovery Priority Requirement Asset users

Table 6: Hardware/Network/Application Asset Identification Card BCM: An approach for SMEs Data Asset Identification Card – Phase 2, Step 3 – Phase 3, Step 2

Data Asset Identification Card Card Creation/Update Date Asset Category Asset Name Asset Description Asset Owner Asset Storage Location Asset Maintainer Aggregated Recovery Priority Supported Business Func#1 Assets role /usage in function Recovery Priority Requirement Asset users

Table 7: Data Asset Identification Card BCM: An approach for SMEs – Templates Annex G - H People Asset Identification Card – Phase 2, Step 3 – Phase 3, Step 2

People / Suppliers Identification Card Card Creation/Update Date Name Organization and address (if not a company employee) Department Title (Role) Key BCM Responsibilities (If contractual obligations exist, put a reference to the contract) Office Telephone FAX Mobile Home Telephone E-mail

Table 8: People Identification Card BCM: An approach for SMEs Facilities Asset Identification Card – Phase 2, Step 3 – Phase 3, Step 2

Facilities Identification Card Card Creation/Update Date Asset Category Asset Name Asset Description Asset Owner Asset Location Asset Maintainer Aggregated Recovery Priority Supported Business Func#1 Supported Business Func#2 Supported Business Func#3 Supported Business Func#4 Supported Business Func#5

Table 9: Facilities Asset Identification Card BCM: An approach for SMEs – Templates Annex G - H Asset Requirements Analysis Summary – Phase 2, Step 3

IT Asset Function#1 Function#2 Function#3 Aggregated Expedited Finance Customer Recovery Service Relationship Priority Contract Management Fulfilment Hardware

Client Facing Application

People / Suppliers

Data

Facilities

Table 10: Asset Requirements Analysis Summary BCM: An approach for SMEs Organisational Continuity Controls – Phase 3, Step 1

Organizational Continuity Controls Card

Risk Areas High Medium Low

Legal and Regulatory

(SP1) SP1.1 SP1.1 (SP2) (SP2) SP3.4 SP3.4 (SP4) (SP4) SP2.3 SP5.1

Productivity

(SP1) (SP2) SP2.1 (SP2) SP3.4 (SP3) SP2.2 (SP4) (SP4) SP5.2 (SP5)

Financial Stability

(SP1) (SP2) SP2.1 (SP2) (SP4) SP5.2 (SP4)

Reputation and Loss of Customer

(SP1) SP2.2 SP2.7

Confidence

(SP2) SP2.3 (SP4) (SP4) SP3.4

Table 11: Organizational Continuity Controls Asset Continuity Control Casrds – Phase 3, Step 2

Asset Continuity Control Cards

Asset Category High Risk Cards Medium Risk Cards Low Risk Cards

Hardware & Network CCC-1HN CCC-2HN CCC-3HN Application CCC-1A CCC-2A CCC-3A

(Back Office – Client Facing)

People CCC-1P CCC-2P CCC-3P Data CCC-1D CCC-2D CCC-3D Facilities CCC-1F CCC-2F CCC-3F

Table 12: Asset Continuity Control Cards BCM: An approach for SMEs – Templates Annex G - H List of Asset Selected Controls– Phase 3, Step 3

Asset Based Continuity Controls

Control Asset & Priority Rationale for Selection

Table 13: List of Asset Selected Controls BCM: An approach for SMEs Organizational Controls Gap Analysis Table – Phase 4, Step 1

The gap analysis table is the output of the gap analysis exercise performed by the Assessment Teams during phase 4, step 1. The table summarizes the results from the evaluation of the organization's current business continuity practices compared to the selected controls described on control cards.

Organizational Continuity Controls

Control Asset Control Description Do we currently follow the controls included in the control cards?

Table 14: Organizational Controls Gap Analysis List Asset Controls Gap Analysis Table – Phase 4, Step 1

Asset Based Continuity Controls

Control Asset & Priority Do we currently follow the controls included in the control cards?

Table 15: Asset Gap Analysis List BCM: An approach for SMEs – Templates Annex G - H Organizational Controls Actions List – Phase 4, Step 2

Following the gap analysis, the Assessment Team reads the controls (Annex A, B) and decides whether the organization will implement or not the continuity controls. This activity is documented into the Actions List table along with the necessary actions that the organization should execute for the implementation of the selected controls.

Organizational Continuity Controls

Control Asset Control Description Activity needed, Outcome expected, Deliverable Documentation

Table 16: Organizational Controls Actions List – Example Asset Based Controls Actions List – Phase 4, Step 2

Asset Based Continuity Controls

Control Asset & Priority Activity needed, Outcome expected, Deliverable Documentation

Table 17: Asset Actions List – Example BCM: An approach for SMEs Controls Prioritization Matrix – Phase 4, Step 2

Controls Prioritization Matrix

Asset Hardware & Applications Data People Facilities Categories Network

ty Low Low Low Medium Medium High ri o ri P Medium Medium Medium Medium Medium High ry ve o ec High High High High High High R

Table 18: Controls Prioritization Matrix BC Controls Implementation Plan – Phase 4, Step 2

The Assessment Team produces the controls implementation plan, prioritizing the necessary actions (phase 4, step 1) towards the controls implementation. The plan also includes the responsible party for the controls implementation and the expected date of their integration within the organization.

BC Controls Implementation Plan

Control Responsible External support Milestones Implementation required Mm/Dd Priority

Table 19: BC Controls Implementation plan BCM: An approach for SMEs – Templates Annex G - H Business Continuity Plan – Phase 4, Step 3

The Business Continuity Plan Template is produced by the execution of the proposed BCM approach. The Plan is created gradually as the Assessment Team executes the various steps. The BCP template exists as a separate document build from the example assessment of a fictitious company. The assessment steps taken to build this BCP are described in chapter 5 of this BCM approach’s main document.

BCM: An approach for SMEs

Annex H – Asset Types List

Asset Category Description Asset (types)

Hardware Information systems that process and store information. Server Systems are a combination of information, software, and Laptop hardware assets. Any host, client, server, or network can be Workstation considered a system. Critical systems are those identified as essential for the continuous provision of the business service Storage and product offerings, those that store critical business Security Devices (firewall, IDS / IPS, antiinformation (customer or business proprietary) or these that spam etc) are exposed to the outside world for business functions or Network services. Devices important to the organization’s networks. Routers, Routers switches, and modems are all examples of this class of Gateways component. Wireless components/devices, such as cell phones and wireless access points that staff members use to access Switches information (for example, email). Typically, critical networks Wireless Access Points are those that are used to support essential critical applications or systems or those that are shared with third party and usually Network Segment (e.g. cabling and un-trusted networks. equipment between two computers) Other (SAT, Laser)

People People in the organization, including business, administration, Chief Technology / Information Director HR and IT. Critical people are those that play a key role the delivery of product and operational processes. Importance Information Technology Manager should be given to critical roles that are considered irreplaceable or constitute a single point of failure. Database Development & Administration (manager, analyst, architect, administrator etc.)

Programming / Software Engineering (manager, engineer, programmer, tester etc.) Technical Support (Help Desk Operator, technician etc.) Systems Analysis & Integration (manager, analyst, integrator, specialist etc.)

Technical Writing (manager, writer, publication specialist etc.)

Network Design & Administration (manager, analyst, architect, administrator, technician etc.)

WEB Development & Administration (manager, developer, designer, administrator etc.)

Back office Applications that are key to or part of daily business Financial Control Applications operations. Disruption of such applications typically results in Customer Care severe hindering or even unavailability of all dependent Logistics business processes. ERP CRM

BCM: An approach for SMEs – Templates Annex G - H

Email Internet Custom Application Intranet Industry Application Instant messaging Security Software (antivirus, proxy, IDS) Document Management System Client Facing Applications that are key to or part of the product and service E-commerce Applications offerings. Disruption of such applications typically results in Internet Service Provisioning – Static, severe hindering or even unavailability of all dependent customer facing (i.e. front office) business services. Public IP addresses, DNS service registration and management. Email Service Provisioning Web Portal Web Site

Application / Data Hosting FAX (including incoming call numbers) Incoming telephone numbers and DDIs Telecommunication Services (i.e. Phone over IP, Mobile telephony, SMS / MMS) Data Data used by the organization in order to perform its business Customer Personal Data operations, generated within the organization or imported by Customer Financial Data third parties and/or customers. Corporate Employee Personal Data Corporate Employee Financial Data Corporate Financial Data Corporate Marketing Data Corporate Sales Data System Technical / Transaction Data System manuals Facilities All physical venues/locations including buildings, offices and Headquarters rooms that the organization uses in order to provide its service/product offerings. Secondary Premises Branch Offices Offices Data Canter

Table 20: Asset List