10.08.2015 Views

Risico’s van een gevirtualiseerde IT-omgeving

Risico's van een gevirtualiseerde IT-omgeving - Vurore

Risico's van een gevirtualiseerde IT-omgeving - Vurore

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Risico’s</strong> <strong>van</strong> <strong>een</strong> <strong>gevirtualiseerde</strong> <strong>IT</strong>-<strong>omgeving</strong> Possen & Ulrich----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ProcessnumberProcessControlobjectivenumberControl objectiveDS11 Manage data DS11.6 Security Requirements forData ManagementDS12DS12DS12DS12DS12Manage the physicalenvironmentManage the physicalenvironmentManage the physicalenvironmentManage the physicalenvironmentManage the physicalenvironmentControl objective descriptionDefine and implement policies and procedures to identify and apply securityrequirements applicable to the receipt, processing, storage and output of datato meet business objectives, the organisation’s security policy and regulatoryrequirements.DS12.1 Site Selection and Layout Define and select the physical sites for <strong>IT</strong> equipment to support thetechnology strategy linked to the business strategy. The selection and designof the layout of a site should take into account the risk associated with naturaland man-made disasters, whilst considering rele<strong>van</strong>t laws and regulations,such as occupational health and safety regulations.DS12.2 Physical Security Measures Define and implement physical security measures in line with businessrequirements to secure the location and the physical assets. Physical securitymeasures must be capable of effectively preventing, detecting and mitigatingrisks relating to theft, temperature, fire, smoke, water, vibration, terror,<strong>van</strong>dalism, power outages, chemicals or explosives.DS12.3 Physical Access Define and implement procedures to grant, limit and revoke access topremises, buildings and areas according to business needs, includingemergencies. Access to premises, buildings and areas should be justified,authorised, logged and monitored. This should apply to all persons enteringthe premises, including staff, temporary staff, clients, vendors, visitors or anyother third party.DS12.4DS12.5Protection AgainstEnvironmental FactorsPhysical FacilitiesManagementDesign and implement measures for protection against environmental factors.Install specialised equipment and devices to monitor and control th<strong>een</strong>vironment.Manage facilities, including power and communications equipment, in linewith laws and regulations, technical and business requirements, vendorspecifications, and health and safety guidelines.----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Pagina 121

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!