ISO IEC 17799 2000 (BS
7799)
|
|
OTHER SAFETY AND SECURITY RESOURCES ISO 28000 Supply Chain Security Audit Program NFPA 1600 Business Continuity Audit Program ISO 22000 Food Safety Management Audit Program |
|
The following material will
introduce our ISO 17799 (BS 7799) We begin with a table of
contents. It shows how we've organized The audit questionnaires
are used to identify the gaps that exist |
|
(THE FOLLOWING MATERIAL IS OBSOLETE) See our NEW ISO 27002 (17799 2005) Audit Tool |
||
ISO IEC 17799 2000 (BS
7799)
|
||
|
TABLE OF CONTENTS |
||
|
PART |
PAGE |
|
|
1 |
Audit Profile |
3 |
|
2 |
Audit Overview |
4 |
|
3 |
Security Policy Audit |
5 |
|
4 |
Organizational Security Audit |
8 |
|
5 |
Asset Classification and Control Audit |
21 |
|
6 |
Personnel Security Management Audit |
25 |
|
7 |
Physical and Environmental Security Audit |
33 |
|
8 |
Communications and Operations Management Audit |
43 |
|
9 |
Information Access Management Control Audit |
69 |
|
10 |
Systems Development and Maintenance Audit |
95 |
|
11 |
<< SAMPLE |
|
|
12 |
Compliance Management Audit |
122 |
|
13 |
Security Performance Scores |
135 |
|
14 |
Legal and Contact Information |
136 |
|
OCT 2004 |
COPYRIGHT © 2004 BY PRAXIOM RESEARCH GROUP LIMITED |
VER 1.0 |
| The following material is now OBSOLETE. |
ISO IEC 17799 2000
|
||||||
|
11.1 DESIGN A CONTINUITY MANAGEMENT PROCESS |
||||||
|
1 |
Have you developed a business continuity |
YES |
NO |
N/A |
||
|
2 |
Is your business continuity management process |
YES |
NO |
N/A |
||
|
3 |
Is your business continuity management process |
YES |
NO |
N/A |
||
|
4 |
Is your business continuity management |
YES |
NO |
N/A |
||
|
5 |
Is your business continuity management process |
YES |
NO |
N/A |
||
|
6 |
Is your business continuity management process used |
YES |
NO |
N/A |
||
|
7 |
Have you analyzed the impact that disasters |
YES |
NO |
N/A |
||
|
8 |
Have you analyzed the impact that security failures |
YES |
NO |
N/A |
||
|
9 |
Have you analyzed the impact that a loss of service |
YES |
NO |
N/A |
||
|
10 |
Have you developed contingency plans in order to |
YES |
NO |
N/A |
||
|
11 |
Do you practice implementing your contingency plans? |
YES |
NO |
N/A |
||
|
11.1.1 ESTABLISH YOUR CONTINUITY MANAGEMENT PROCESS |
||||||
|
12 |
Have you established a process to manage and maintain |
YES |
NO |
N/A |
||
|
13 |
Have you identified and prioritized your |
YES |
NO |
N/A |
||
|
14 |
Have you identified the risks that threaten |
YES |
NO |
N/A |
||
|
15 |
Have you estimated the likelihood that your organization
|
YES |
NO |
N/A |
||
|
16 |
Have you analyzed the impact that serious threats could |
YES |
NO |
N/A |
||
|
17 |
Have you analyzed the impact that interruptions |
YES |
NO |
N/A |
||
|
18 |
Have you found solutions to the security problems |
YES |
NO |
N/A |
||
|
19 |
Have you found solutions for the security threats |
YES |
NO |
N/A |
||
|
20 |
Have you increased your security through |
YES |
NO |
N/A |
||
|
21 |
Have you formulated business objectives and |
YES |
NO |
N/A |
||
|
22 |
Have you formulated a business continuity strategy |
YES |
NO |
N/A |
||
|
23 |
Have you documented your continuity strategy? |
YES |
NO |
N/A |
||
|
24 |
Is your business continuity strategy consistent |
YES |
NO |
N/A |
||
|
25 |
Have you formulated business continuity plans |
YES |
NO |
N/A |
||
|
26 |
Have you documented your business continuity plans? |
YES |
NO |
N/A |
||
|
27 |
Are your business continuity plans consistent |
YES |
NO |
N/A |
||
|
28 |
Has responsibility for coordinating your continuity |
YES |
NO |
N/A |
||
|
29 |
Have you institutionalized continuity management? |
YES |
NO |
N/A |
||
|
11.1.2 PERFORM THREAT ANALYSIS AND IMPACT ANALYSIS |
||||||
|
30 |
Have you carried out a threat analysis in order to identify
|
YES |
NO |
N/A |
||
|
31 |
Did you carry out your threat analysis with the full |
YES |
NO |
N/A |
||
|
32 |
Did your threat analysis include all business processes? |
YES |
NO |
N/A |
||
|
33 |
Have you carried out a risk assessment in order to identify |
YES |
NO |
N/A |
||
|
34 |
Has your impact analysis identified how much damage |
YES |
NO |
N/A |
||
|
35 |
Has your impact analysis identified how long it would |
YES |
NO |
N/A |
||
|
36 |
Did you carry out your impact analysis with the |
YES |
NO |
N/A |
||
|
37 |
Did your impact analysis include all business processes? |
YES |
NO |
N/A |
||
|
38 |
Did you use the results of your analyses and assessments |
YES |
NO |
N/A |
||
|
39 |
Did your senior management endorse your |
YES |
NO |
N/A |
||
|
11.1.3 DEVELOP YOUR BUSINESS CONTINUITY PLANS |
||||||
|
40 |
Have you developed plans to restore and continue |
YES |
NO |
N/A |
||
|
41 |
Do your business continuity plans help you |
YES |
NO |
N/A |
||
|
42 |
Do your business continuity plans help you to restore |
YES |
NO |
N/A |
||
|
43 |
Do your business continuity plans identify the resources
|
YES |
NO |
N/A |
||
|
44 |
Do your business continuity plans identify the services |
YES |
NO |
N/A |
||
|
45 |
Do your business continuity plans identify the staffing |
YES |
NO |
N/A |
||
|
46 |
Do your business continuity plans identify and assign |
YES |
NO |
N/A |
||
|
47 |
Do your business continuity plans define all |
YES |
NO |
N/A |
||
|
48 |
Do your emergency response procedures ensure |
YES |
NO |
N/A |
||
|
49 |
Do your emergency response procedures accommodate |
YES |
NO |
N/A |
||
|
50 |
Do your emergency response procedures respect |
YES |
NO |
N/A |
||
|
51 |
Have you documented emergency response procedures? |
YES |
NO |
N/A |
||
|
52 |
Have you documented critical business processes? |
YES |
NO |
N/A |
||
|
53 |
Do your business continuity plans identify fallback |
YES |
NO |
N/A |
||
|
54 |
Have you taught your staff members how to |
YES |
NO |
N/A |
||
|
55 |
Have you taught your staff members how your critical |
YES |
NO |
N/A |
||
|
56 |
Have you taught your staff members about your |
YES |
NO |
N/A |
||
|
57 |
Do you regularly test your business continuity plans? |
YES |
NO |
N/A |
||
|
58 |
Do you regularly update your business continuity plans? |
YES |
NO |
N/A |
||
|
11.1.4 MAINTAIN A CONTINUITY PLANNING FRAMEWORK |
||||||
|
59 |
Have you established a
single framework of business |
YES |
NO |
N/A |
||
|
60 |
Do you use your business continuity planning |
YES |
NO |
N/A |
||
|
61 |
Do you use your business continuity planning |
YES |
NO |
N/A |
||
|
62 |
Does each business continuity plan include a |
YES |
NO |
N/A |
||
|
63 |
Do you amend your business continuity plans whenever |
YES |
NO |
N/A |
||
|
64 |
Does each business continuity plan clearly specify |
YES |
NO |
N/A |
||
|
65 |
Does each business continuity plan specify the process |
YES |
NO |
N/A |
||
|
66 |
Does each business continuity plan explain how a crisis |
YES |
NO |
N/A |
||
|
67 |
Does each business continuity plan specify who should |
YES |
NO |
N/A |
||
|
68 |
Does each business continuity plan clearly specify who |
YES |
NO |
N/A |
||
|
69 |
Does each business continuity plan nominate |
YES |
NO |
N/A |
||
|
70 |
Does each business
continuity plan describe the |
YES |
NO |
N/A |
||
|
71 |
Does each
business
continuity plan explain how relations |
YES |
NO |
N/A |
||
|
72 |
Does each business
continuity plan explain how relations |
YES |
NO |
N/A |
||
|
73 |
Does each business
continuity plan explain how |
YES |
NO |
N/A |
||
|
74 |
Does each business
continuity plan describe fallback |
YES |
NO |
N/A |
||
|
75 |
Does each business continuity plan describe fallback |
YES |
NO |
N/A |
||
|
76 |
Does each business continuity plan describe resumption |
YES |
NO |
N/A |
||
|
77 |
Does each business continuity plan describe the education |
YES |
NO |
N/A |
||
|
78 |
Does each business continuity plan specify who owns
|
YES |
NO |
N/A |
||
|
79 |
Have owners of business processes and resources been |
YES |
NO |
N/A |
||
|
80 |
Are owners of business processes and resources |
YES |
NO |
N/A |
||
|
81 |
Are technical service providers responsible for managing
|
YES |
NO |
N/A |
||
|
82 |
Are information service providers responsible for managing |
YES |
NO |
N/A |
||
|
83 |
Are communications service providers responsible |
YES |
NO |
N/A |
||
|
Etcetera ... |
YES |
NO |
N/A |
|||
|
PRAXIOM RESEARCH GROUP
LIMITED |
|||
|
First published on October 11, 2004. Updated on December 26, 2011. |
|||
Disclaimer
and Limitation of Liability
The
publisher and authors have used their best efforts in designing and
developing this electronic publication. We make no representation or
warranties
with respect to accuracy or completeness of the contents of
this publication and
specifically disclaim any implied warranties or
merchantability or fitness for any
particular purpose and shall in no
event be liable for any loss of profit or any
other commercial damage,
including but not limited to special, incidental,
consequential, or
other damages.
Legal
Restrictions on the Use of this Page
Thank
you for visiting this page. You are, of course, welcome to view our
material as often as you wish, free of charge. And as long as you
keep intact
all copyright notices, you are also welcome to print or make one
copy of this
page for your own personal, noncommercial, home use. But, you are not
legally authorized to print or produce additional copies or to
copy and paste
any of our material onto another web site or to republish it in
any way.
Copyright © 2004 - 2011 by Praxiom Research Group Limited. All Rights Reserved.
![]()