Printable sheet: Cybersecurity and continuity
To print or save as a PDF (portable document format), use your browser's print function (Ctrl+P or Cmd+P).
Cybersecurity and continuity
Separated environments, controlled access and recovery capability demonstrated in testing.
The need
Critical systems need more than generic protection. They need separated environments, control over who can access what and a proven ability to restore service after an incident.
Intended outcome
Isolated critical environments, role-based and traceable access, and recovery tested against agreed objectives.
Scope
- Risk assessment and threat modelling for each environment.
- Logical segregation: networks, accounts, data and administration separated by environment.
- Physical segregation where required: a dedicated technical area, equipment, installation conditions and physical access control.
- Identity and access: role-based accounts, strong authentication, privilege management and activity logs.
- System and network protection: secure configuration, updates, filtering and incident detection.
- Backups, recovery and continuity plans with regular testing.
Deliverables
- Risk register and threat model.
- Physical and logical segregation architecture, with separation of duties.
- Role-based access matrix.
- Backup and recovery plan and test reports.
- Continuity plan and reports of tests held at the agreed frequency.
Deployment options
It applies to on-premises, cloud or hybrid environments. The physical component involves building work, equipment and installation conditions of its own, planned with the client and, where needed, carried out with specialist partners.
Limits and dependencies
- Physical segregation of premises requires its own building design and equipment; delivery may involve specialist partners named in the proposal.
- Where an independent audit is required, it is carried out by an organisation independent of IP World and its delivery partners, engaged by the client or by whoever the client designates.
- There is no such thing as zero risk. Recovery objectives and controls are defined in the contract and verified by testing.
Continuity and exit
- Data and export formats
- Export of activity logs and asset inventories in open formats.
- Documentation
- Security architecture, incident response and recovery procedures.
- Configurations
- Security policies and configurations exported, under version control.
- Responsibilities
- Documented separation between those who build, those who operate and those who audit.
- Licences and contracts
- Transfer and regularisation of security licences and vendor support contracts, with the holder of each.
- Knowledge transfer
- Handover of keys and credentials through a controlled procedure and training for the incoming team.
Next step
Describe your critical systems and what must not stop; we will propose a risk assessment.
Rua Centro de Convenções S8, Masuika Office Plaza, Bloco A, 7.º andar, porta 7C, Luanda, Angola