How to control data tape movement during COVID19
We are ISO certified organization and due to COVID 19, we are not able to comply controls i.e. backup tapes movement from one location to off-site location
How do we address this? Is there any advisory published by ISO / any template /format where we can mention this and take approval from management & it will be helpful during the audit as well.
Assign topic to the user
For ISO certified organizations, this situation can be addressed through a management review (during the normal scheduled meeting, or by means of an extraordinary meeting), where the situation is presented to Top management, and they can decide for the proper course of action (e.g., accept the risk of not keeping backup tapes on off-site location during the isolation period, apply another type of control, or change the current procedure/technology to overcome this physical movement of backup tapes).
In this case, you can use the management review minutes template you already have to document this decision.
To see an example of a management review minutes template, see: https://advisera.com/27001academy/documentation/management-review-minutes/
This article will provide you further explanation about management review:
- Why is management review important for ISO 27001 and ISO 22301? https://advisera.com/27001academy/blog/2014/03/03/why-is-management-review-important-for-iso-27001-and-iso-22301/
Is this necessary to document this as an exception in BCP , backup and restoration policies
Also Please suggest what should be accurate statement we should write in above mentioned policies.
Once the decision is made by Top management, if it impacts BCP procedures or policies guidelines, then you have to document the exception, according to your procedure for documents and records control.
As a suggestion for the text, you should consider include this exception as a sub-clause in the main topic of your document, defining it the details about how to handle this situation. For example:
Clause x - Backup
Clause x.x - Backup procedure during a pandemic
In case of a pandemic, the backup procedure must be made as follows: <from this point you must include the procedure specific for this case>
Comment as guest or Sign in
Apr 28, 2020