Expert Advice Community

Guest

How to control data tape movement during COVID19

  Quote
Guest
Guest user Created:   Apr 24, 2020 Last commented:   Apr 28, 2020

How to control data tape movement during COVID19

We are ISO certified organization and due to COVID 19, we are not able to comply controls i.e. backup tapes movement from one location to off-site location

How do we address this? Is there any advisory published by ISO / any template /format where we can mention this and take approval from management & it will be helpful during the audit as well.

0 0

Assign topic to the user

EU GDPR & ISO 27001 INTEGRATED DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR & ISO 27001 INTEGRATED DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 24, 2020

For ISO certified organizations, this situation can be addressed through a management review (during the normal scheduled meeting, or by means of an extraordinary meeting), where the situation is presented to Top management, and they can decide for the proper course of action (e.g., accept the risk of not keeping backup tapes on off-site location during the isolation period, apply another type of control, or change the current procedure/technology to overcome this physical movement of backup tapes).

In this case, you can use the management review minutes template you already have to document this decision.

To see an example of a management review minutes template, see: https://advisera.com/27001academy/documentation/management-review-minutes/

This article will provide you further explanation about management review:
- Why is management review important for ISO 27001 and ISO 22301? https://advisera.com/27001academy/blog/2014/03/03/why-is-management-review-important-for-iso-27001-and-iso-22301/

Quote
0 0
Guest
Chetan Dhamija Apr 24, 2020

Is this necessary to document this as an exception in BCP , backup and restoration policies

Also Please suggest what should be accurate statement we should write in above mentioned policies.

Quote
0 0
Expert
Rhand Leal Apr 28, 2020

Once the decision is made by Top management, if it impacts BCP procedures or policies guidelines, then you have to document the exception, according to your procedure for documents and records control.

As a suggestion for the text, you should consider include this exception as a sub-clause in the main topic of your document, defining it the details about how to handle this situation. For example:

Clause x - Backup
Clause x.x - Backup procedure during a pandemic
In case of a pandemic, the backup procedure must be made as follows: <from this point you must include the procedure specific for this case>

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 24, 2020

Apr 28, 2020

Suggested Topics