| Qualità applicata | Articoli, documenti e leggi utili | |
| Sei in Home > Dossier Qualità applicata | ![]() |
|
| Managing crises with new ISO/IEC standard for IT disaster recovery - 10 marzo 2008 | Links utili | |
| fonte:
ww.iso.org
From fires to earthquakes to pandemics, businesses and other organizations may become the victims of disaster at any time. In order to deal with the unexpected and safeguard the interests of their stakeholders, as well as their reputation, brand and value-creating activities, a new ISO/IEC International Standard will help them mitigate risks and be prepared to respond to crises. ISO/IEC 24762:2008, Information technology – Security techniques – Guidelines for information and communications technology disaster recovery services aims to offer guidance on the information and communications technologies and services necessary for disaster recovery (ICT DR) as part of business continuity management. With this guidance, the standard supports the operation of an information security management system (ISMS) by addressing the information security and availability aspects of business continuity management in time of crisis. A business continuity plan comprises an organization’s strategies to prepare for future national, regional or local crises that could jeopardize its capacity to continue with its core mission, as well as its long term stability. According to ISO/IEC 24762:2008, business continuity management is an integral part of any holistic risk management process and involves:
With this new standard, organizations will be able to build resilience into their information and communications technology (ICT) infrastructure critical to their key business activities. This will complement their business continuity management initiative (to better manage relevant risks possibly interrupting their business activities) and their information security management initiative (to effectively protect the confidentiality, integrity and availability of information). Mr Philip Sy, project editor of ISO/IEC 24762:2008, commented: “This next generation standard takes into account today’s technological developments to minimize damage in a crisis situation from an information security and communication standpoint. “The fallback arrangements included in the standard," he emphasized, "will help out both during periods of minor outages and, more importantly, will play an essential role in ensuring information and service availability during a disaster or failure, and for a long-term complete recovery of activities. “This is particularly important today as organizations around the world are increasingly vulnerable to threats of terrorism, natural disasters, piracy and other crises”, concluded Mr Sy. The standard includes guidelines on the implementation, testing and execution aspects of disaster recovery, and can be applicable to both “in-house” and “outsourced” ICT DR service providers of physical facilities and services. It provides guidance on:
ISO/IEC 24762:2008 is an initiative of ISO and the International Electrotechnical Commission (IEC) developed within the joint technical committee ISO/IEC JTC1, Information technology, subcommittee SC 27, IT Security techniques. This international standard can be complemented by two other joint ISO/IEC standards providing control objectives for information security aspects of business continuity management to further reduce risk:
|
www.fita.it/quaform1.html |
|
| Ultimi articoli | ||

Copyright © 1999-2008
Tutti i diritti riservati.