|
+BCM-04.01AC |
1. ÜbersichtBCM-04.01ACIn addition to the tests, exercises are also carried out which, among other things, have resulted in scenarios from security incidents that have already occurred in the past.Tests are primarily conducted at the operational level and are aimed at operational target groups. Tests include e.g.: 1. Test of technical precautionary safeguards; 2. Functional tests; and 3. Plan review. Exercises also take place on a tactical and strategic level. These include e.g.: 1. Plan meeting; 2. Personnel exercise; 3. Command post exercise; 4. Communication and alerting exercise; 5. Simulation of scenarios; and 6. Emergency or full exercise. Relevant third parties are in particular service organisations of the cloud service provider who contribute to the development or operation of the cloud service (cf. basic criteria SSO-02 and SSO-06). A cloud service customer is affected (in the sense of this criterion) if the test or excercise leads to a service downgrade outside of the level defined in the SLA or if the effectiveness of the plans can only be tested if the cloud service customer has to take action.
1.1 Referenzen1.2 Identifizierte Anforderungen1.2 Related Regulation2. Identifizierte Anforderungen
3. Related Regulations
|