Implementation Guidance

When making judgments about the nature and extent of disclosures to include the key security policies and processes, consider the following:

  • The existence of a formal security policy established to implement the entity's cybersecurity strategy
  • Key topics addressed by the security policy

When making judgments about the nature and extent of disclosures to include the prevention of intentional and unintentional security events, consider the following:

  • Protection of data whether at rest, during processing, or in-transit
  • Data loss prevention
  • User identification, authentication, authorization, and credentials management
  • Physical and logical access provisioning and de-provisioning, including remote access
  • Privileged account management
  • IT asset management, including hardware and software commissioning, configuration, maintenance, and decommissioning, as well as physical and logical servers and other devices
  • Operating location and data center physical security and environmental safeguards
  • Monitoring and managing changes to systems made internally or by external parties, including software acquisition, development, and maintenance, and patch management

When making judgments about the nature and extent of disclosures to include about the detection of security events; identification of security incidents; development of a response to those incidents; and implementation activities to mitigate and recover from identified security incidents; consider the following:

  • The deployment of tools and programs, the implementation of monitoring processes and procedures, or operation of other measures to identify anomalies, analyzing anomalies to identify security events, and communicating identified security events to appropriate parties
  • The deployment of procedures to measure the effectiveness of activities planned in the event of a disruption to operations that requires the recovery of processing at alternate locations and the updating of plans based on the result of those procedures
  • The process by which management identifies security incidents from detected security events
  • The process by which management identifies security incidents based on notification of security events received from third parties
  • The process by which management evaluates security incidents and assesses the corrective actions needed to respond to and mitigate the harm from incidents
  • The process by which management assesses the impact of security incidents to data, software, and infrastructure
  • The process by which management restores operations after identified security incidents, including the oversight and review of the recovery activities by executive management
  • The process by which the incident response plan is updated based on the analysis of lessons learned
  • The process used to communicate information about the security incident, including the nature of the incident, restoration actions taken, and activities required for future prevention of the event to management and executive management
  • The process used to make communications to affected third parties about the security incident
  • The process for periodically testing the incident response plan

When making judgments about the nature and extent of disclosures to include about the management of processing capacity to provide for continued operations during security, operational, and environmental events, consider the following:

  • The deployment of tools and programs, the implementation of monitoring processes and procedures, or operation of other measures to monitoring capacity usage
  • The process for forecasting capacity needs and the process for requesting system changes to address those needs
  • The procedures for assessing the accuracy of the capacity forecasting process and revising the process to improve accuracy

When making judgments about the nature and extent of disclosures to include about the detection, mitigation, and recovery from environmental events and the use of backup procedures to support system availability, consider the following:

  • The deployment of tools and programs, the implementation of monitoring processes and procedures, or operation of other measures to identify developing environmental threat events and the mitigation of those threats
  • The processes identifying data for backup and for backing up and restoring data to support continued availability in the event of the destruction of data within systems
  • The process for developing and maintaining a business continuity plan, including procedures for the recovery of operations in the event of a disaster at key processing locations
  • Key topics addressed by the business continuity plan, including identification and prioritization of systems and data for recovery and provision for alternate processing infrastructure in the event normal processing infrastructure becomes unavailable
  • Procedures for periodically testing the procedures set forth in the business continuity plan

When making judgments about the nature and extent of disclosures to include about the identification of confidential information when received or created; determination of the retention period for that information; retention of the information for the specified period; and destruction of the information at the end of the retention period, consider the following:

  • The process for establishing retention periods for types of confidential information and identifying the information when received or created and associating the information to a specific retention period
  • The process for identifying information classified as confidential
  • The process for preventing the destruction of identified information during its specified retention period
  • The process for identifying information that has reached the end of its retention period and information that is an exception to the retention policies
  • The process for destroying information identified for destruction
Main Menu