【正文】
plementation Guidance Information Security Management Systems (ISMS) 27002 Code of Practice ISMS Family Risk manage。 Prevent occurrence。 eliminate or reduce impact SC27 WG4 Roadmap Framework Investigate to establish facts about breaches。 WD for new Part 1, 2 3。 Includes outsourcing and offshoring security Gaps between Readiness Response IT Security, BCP, and DRP Planning Execution Protect Detect React/ Response IT Security Planning Activate BCP Activate DCRP Plan Prepare Test Plan Prepare Test Business Continuity Planning Disaster Contingency Recovery Planning Disaster Events IT Systems Failures ICT Readiness for Business Continuity ? What is ICT Readiness? ? Prepare anization ICT technology (infrastructure, operation, applications), process, and people against unforeseeable focusing events that could change the risk environment ? Leverage and streamline resources among traditional business continuity, disaster recovery, emergency response, and IT security incident response and management ? Why ICT Readiness focus on Business Continuity? ? ICT systems are prevalent in anizations ? ICT systems are necessary to support incident, business continuity, disaster, and emergency response and management needs ? Business continuity is inplete without considering ICT systems readiness ? Responding to security incident, disasters, and emergency situations are about business continuity Implications of ICT Readiness Operational Status Time Incident Current IHM, BCM and DRP focus on shortening period of disruption and reducing the impact of an incident by risk mitigation and recovery planning. T=0 T=i T=k T=l T=j 100% x% y% z% Early detection and response capabilities to prevent sudden and drastic failure, enable gradual deterioration of operational status and further shorten recovery time. Before implementation of IHM, BCM, and/or DRP After implementation of IHM, BCM, and/or DRP After implementation of ICT Readiness for BC ICT Readiness for Business Continuity ? Reproposed as singlepart standard (Nov ?07) ? Structure (DRAFT, Document SC27N6274) ? Introduction ? Scope ? Normative References ? Terms and D