<?xml version="1.0" encoding="UTF-8" standalone="no"?><!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook V4.1//EN" "http://www.oasis-open.org/docbook/xml/4.1/docbookx.dtd">
<book>
<bookinfo>
<title>Application Service Provider Security Standard</title>
<titleabbrev>LCZ-ASP</titleabbrev>
<edition>1.1</edition>
<pubdate>16 May 2009</pubdate>
<abstract>
<para>This document specifies technical and non-technical security policy for ASP implementations and applies to any ASP service regardless of technology to be used.
</para>
<para>This standard contains 22 baseline controls, and 3 above baseline controls, for a total of 25 controls.</para></abstract>
<revhistory>
<revision>
<revnumber>1.1</revnumber>
<date>16 May 2009</date>
<authorinitials>FOD</authorinitials>
<revremark>Revised for re-release</revremark>
</revision>
<revision>
<revnumber>1.0</revnumber>
<date>13 June 2003</date>
<authorinitials>LCZ</authorinitials>
<revremark>Initial Draft for public release</revremark>
</revision>
</revhistory>
<copyright>
<year>2001</year><year>2002</year><year>2003</year><year>2009</year>
<holder>Frank O'Dwyer</holder>
</copyright>
<legalnotice><important><para>All of these Security Standards and Security Policies are copyrighted. THEY ARE NOT IN THE
PUBLIC DOMAIN. They are however distributed under a liberal open-source license, 
see <link linkend="publishing">Publishing these Security Standards and Policies</link>.</para></important></legalnotice><publisher><publishername>Frank O'Dwyer</publishername></publisher></bookinfo>
<chapter><title>Introduction</title>
<section><title>Objectives</title><para>The objectives of this document are:</para><itemizedlist>
<listitem><para>To specify a security policy and standards for ASP delivered solutions.
</para></listitem>
<listitem><para>To provide guidance to administators, developers and security personnel in securely implementing ASP solutions.  
</para></listitem>
</itemizedlist></section>
<section><title>Scope</title>
<para>
</para>
<para>
</para>
</section>
<section><title>Not In Scope</title>
<para>Compliance with this standard will not provide <quote>in depth</quote> security architecture or intelligent security design guidance
to projects. As a consequence, for high impact or safety-critical business applications, additional guidance will still need to be 
sought from the Information Security team consultancy function.  
</para>
<para>This is an ASP security policy. Controls specific to technologies used in the service are not 
defined here but will be the subject of additional standards. This document should also be read in conjunction with the generic security standards and the technology 
specific standards, which specifies controls applicable for particular technologies.
</para>
<para>Compliance with this standard does not negate the need for an overall security review 
of a proposed application or service. Contact the Information Security team if you are in doubt.
</para>
</section>
<section><title>Giving Feedback</title><para>Your feedback to improve this document is welcome. Please let me know of your experiences in applying the controls and 
	guidance in this standard. Are the controls effective, easy to implement, too onerous, clear, unclear, something missing? Does an exceptional case 
need to be covered? Let me know. Please 
send your comments to frankodwyer AT netscape.net. Your comments will be 
used to produce better free security standards for the IT community.</para><para>I also request that you give feedback where you think the controls and guidance is 
correct. This will let us gauge whether or not specific controls are controversial or 
broadly acceptable to the community, and will help us to resolve cases where we have 
conflicting feedback on particular content.</para></section><section id="publishing"><title>Publishing these Security Standards and Policies</title><para>This document may be reproduced and distributed in whole or in part, free of charge, subject to the following conditions:</para><itemizedlist><listitem><para>All copyright and trademark notices, and this permission notice must be preserved complete on all complete or partial copies.</para></listitem><listitem><para>Any translation or derivative work of this document must be approved by Frank O'Dwyer in writing before distribution.</para></listitem><listitem><para>If you distribute this guide in part, instructions for obtaining the complete version of this manual must be included, and a means for obtaining a complete version provided.</para></listitem><listitem><para>Small portions may be reproduced as illustrations for reviews or quotes in other works without this permission notice if proper citation is given.</para></listitem><listitem><para>Neither Frank O'Dwyer's name nor the names of any contributors may be used to endorse or promote products derived from this document without specific prior written permission.</para></listitem></itemizedlist><para>THIS DOCUMENT IS PROVIDED BY FRANK O'DWYER AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY 
AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL FRANK O'DWYER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF 
LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.</para><para>I would like to be informed of any plans to publish or distribute these documents, just so I know how they're being used and where they are becoming available. 
	If you are publishing or distributing or planning to publish or distribute any of these documents, please send mail to frankodwyer AT netscape.net</para></section>
<section><title>Related Documents</title><para>This document should be read and applied in conjunction with the technology specific security standards that are available from the frankodwyer.com  
web site. Please note that some of the documents below are currently under development and as such may not as yet be available. Check back frequently for updates
to this document and those documents listed below.</para><section><title>Generic Security Standards</title><para><emphasis>Generic Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para><para><emphasis>Data Protection European Union Security Standard</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para><para><emphasis>Application Service Provider Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para></section><section><title>Operating System Security Standards</title><para><emphasis>Generic Unix Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Generic Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Workstation Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Server Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Domain Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para></section><section><title>Database Security Standards</title><para><emphasis>Oracle Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#db">http://www.frankodwyer.com/standards/index.html#db</ulink></para></section></section>
<section><title>Definitions</title>

<para>An <quote>Information Asset</quote> equates to any computerised information system 
or component thereof and thus includes an application, an item of off the shelf software, hardware, media, 
a data item, a data item repository and associated communications networks.</para>
<para>The specification of 
the Information Asset in question will usually be given so that this document is unambiguous, except
where a control relates to any <quote>Information Asset</quote>. </para>


<para>The use of <quote>must</quote> or <quote>will</quote> indicates what the author considers to be a mandatory control.</para>
<para>However, whether the controls listed here are mandatory for your organisation is entirely at your organisation's discretion and
thus they should be interpreted as representing the strongest recommendation of the author.</para>


<para>The use of <quote>should</quote> or <quote>recommended</quote> or <quote>ought</quote> indicates
that the author believes that the controls in question are worthwhile and should be implemented unless such
an implementation is impossible, onerous or impractical. Again, the implementation of controls so recommended
in this document is entirely at your organisation's discretion.</para>

</section>
</chapter>





<chapter><title>Security Compliance</title>

<section><title>Security Management</title>
<section><title>Obtain a copy of the suppliers information security service descriptions</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>ASP-SECMAN-3</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The suppliers information security service descriptions should be obtained and analysed for consistency against the supplier security organisation and against your organisation's security service requirements.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain the suppliers information security service descriptions</para></listitem>
<listitem><para>Analyse the services in view of their stated organisational structure, their service capability claims and against your organisation's security service requirements.</para></listitem>
<listitem><para>Identify areas where the suppliers services appear to be unsupported by their structure and resourcing</para></listitem>
<listitem><para>In the context of the service to be provided analyse the impact of the disparities</para></listitem>
<listitem><para>Feed the results into your analysis of the proposed service</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Required security services may not be delivered</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that ASP contracts include a schedule detailing the security services provided and references a service level agreement for the provision of those services.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-11</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that ASP contracts include a schedule detailing the security services provided and references a service level agreement for the provision of those services.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify the security services required</para></listitem>
<listitem><para>Identify the service level required for each security service</para></listitem>
<listitem><para>Ensure that the contract for the application service provision references these services and the service level required</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The effectiveness of the service provision claims may be unsupportable</para></listitem>
<listitem><para>The effectiveness of the service provision claims may be unremediable through legal means</para></listitem>
<listitem><para>Incident management may be ineffective</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Procedural security may be wholly inappropriate</para></listitem>
<listitem><para>Personnel security may be wholly inappropriate</para></listitem>
<listitem><para>Technical security may be wholly inappropriate</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Obtain a copy of the suppliers information security organisational structure</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>ASP-SECMAN-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The suppliers information security organisational structure must be obtained and analysed for consistency with the stated policies and claimed security services.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain the suppliers information security organisational structure</para></listitem>
<listitem><para>Analyse the structure in view of the stated policies and security services</para></listitem>
<listitem><para>Identify areas where the suppliers defined structure appears unable to support the claimed policy objectives and the claimed security services.</para></listitem>
<listitem><para>In the context of the service to be provided analyse the impact of the disparities</para></listitem>
<listitem><para>Feed the results into your analysis of the proposed service</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>A wholly inappropriate technical security solution may be implemented</para></listitem>
<listitem><para>A wholly inappropriate security management solution may be implemented</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Obtain a description of the suppliers arrangements for auditing the services that they provide.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>ASP-SECMAN-4</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Auditing provides independent management checks on the functioning of controls, therefore obtain a description of the suppliers arrangements for auditing the services that they provide and compare this to the regime that would be implemented were it in your own organisation.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain the description of the auditing provided by the supplier</para></listitem>
<listitem><para>Ensure that the auditing to be provided equates at least to that which would be provided were the application hosted in-house</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The service may be operated in such a was as to be out of control</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that the supplier is bound by confidentiality agreements to prevent leakage of your data to other parties who may also use the ASP service.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-12</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that the supplier is bound by confidentiality agreements to prevent leakage of your data to other parties who may also use the ASP service.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that the ASP contract includes supplier confidentiality clauses</para></listitem>
<listitem><para>Determine whether further more stringent confidentiality measures are required from the risk analysis</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
</itemizedlist></section></section>
<section><title>Obtain a copy of the suppliers information security policy</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>ASP-SECMAN-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The suppliers information security policy should be obtained and analysed for consistency with that of your own organisation.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain the suppliers information security policy</para></listitem>
<listitem><para>Perform a comparative analysis between the suppliers policy and your own</para></listitem>
<listitem><para>Identify areas where the suppliers policy requirements do not meet yours</para></listitem>
<listitem><para>In the context of the service provided analyse the impact of the disparities</para></listitem>
<listitem><para>Feed the results into your analysis of the proposed service</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>A wholly inappropriate technical security solution may be implemented</para></listitem>
<listitem><para>A wholly inappropriate security management solution may be implemented</para></listitem>
<listitem><para>An inappropriate security cultural solution may be implemented</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Avoid ASPs who are unwilling to disclose their security capabilities even under non-disclosure agreements</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-10</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Avoid using ASPs who are unwilling to disclose their security capabilities even under non-disclosure agreements</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Determine whether the supplier is willing to disclose their security capabilities</para></listitem>
<listitem><para>Avoid those, who even under NDA will not disclose their security service capabilities</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The effectiveness of the service provision claims may be unsupportable</para></listitem>
<listitem><para>Incident management may be ineffective</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that ASP personnel are subject to equivalent background checks as staff within your own organisation</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-13</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that ASP personnel who will be working on the ASP solution are subject to equivalent background checks as staff within your own organisation</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Determine what background checks are performed by the ASP</para></listitem>
<listitem><para>Compare these checks to those performed by your own organisation</para></listitem>
<listitem><para>Determine whether there are any major mismatches and thus, exposures.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Procedural security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that hardening of the components of the solution takes place in line with the policies and standards that are applicable within your organisation.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-16</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that hardening of the components of the solution takes place in line with the policies and standards that are applicable within your organisation.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain details of the component hardening that the ASP performs</para></listitem>
<listitem><para>Compare the hardening process used against the steps that your organisation would take.</para></listitem>
<listitem><para>Identify any substantive differences that would reduce the security of the solution when compared to hosting it by your own organisation</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that a regime of measuring the security services provided are in place and the ASP provides these at an agreed frequency</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-9</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that a regime of measuring the security services provided are in place and the ASP provides these at an agreed frequency</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>For each of the security services provided as part of the ASP define measures of effectiveness</para></listitem>
<listitem><para>For each of the measures of effectiveness determine the frequency of report to be provided by the ASP.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The effectiveness of the service provision claims may be unmeasured</para></listitem>
<listitem><para>Incident management may be ineffective</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that ASP contracts of employment place equivalent or greater emphasis on information security as that in your organisation's own contracts of employment</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-14</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that ASP contracts of employment place equivalent or greater emphasis on information security as that in your organisation's own contracts of employment</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Determine the information security clauses within your organisation's contract of employment</para></listitem>
<listitem><para>Determine the information security clauses within the ASP contracts of employment</para></listitem>
<listitem><para>Determine whether any mismatches are significant</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Procedural security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that the ASP management practices in relation to the components that make up the solution do not introduce vulnerabilities</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-15</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that the ASP management practices in relation to the components that make up the solution, do not introduce vulnerabilities</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain the management procedures for the solution components from the ASP</para></listitem>
<listitem><para>Compare these management procedures to those that would be applied were the solution hosted by your own organisation</para></listitem>
<listitem><para>Identify substantive differences that may give rise to security vulnerabilities</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Procedural security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that the ASP has a well defined audit capability</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-8</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that the ASP undertakes periodic audits</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain a description of the audit cycle for the service</para></listitem>
<listitem><para>If one does not exist or if the cycle is too long this should be considered a deficiency</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The effectiveness of the service provision claims may be unmeasured</para></listitem>
<listitem><para>Incident management may be ineffective</para></listitem>
<listitem><para>Security responsibilities may be confused</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that the supplier provides contact names and details for each element of their security organisation that will deliver security services to your organisation.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>ASP-SECMAN-5</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>It must be ensured that the supplier provides contact names and details for each element of their security organisation that will deliver security services.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Using the supplier organisation chart and the security services that are to be supplied ensure that all contact details have been supplied.</para></listitem>
<listitem><para>Ensure that the number of services to be provided by each individual named are reasonable</para></listitem>
<listitem><para>Ensure that the contact info is maintained in an appropriate form such that incidents and responses can be appropriately dealt with.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The service provision claims may unsupportable</para></listitem>
<listitem><para>Incident management may be unfeasible</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure the ASP has a well defined information security organisation with clearly defined responsibilities</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMAN-7</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure the ASP has a well defined information security organisation with clearly defined responsibilities</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Obtain the information security organisation from the ASP</para></listitem>
<listitem><para>Correlate the security services provided with the security organisation</para></listitem>
<listitem><para>Identify any significant mismatches</para></listitem>
<listitem><para>Correlate the security services provided against the security services required</para></listitem>
<listitem><para>Identify any significant mismatches</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The service provision claims may be unsupportable</para></listitem>
<listitem><para>Incident management may be unfeasible</para></listitem>
<listitem><para>Security responsibilities may be confused</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
</chapter>

<chapter><title>Network Security Configuration</title>

<section><title>Internet Considerations</title>
<section><title>Vulnerability scanning/penetration testing should be performed prior to any new service going live</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NETSEC-1</para></entry><entry><para>1.0</para></entry><entry><para>above baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Where the new service is to be host by an ASP vulnerability scanning/penetration testing should be performed prior to the new service going live</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify whether the ASP provides any monitoring of the platform builds</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Security vulnerabilities may go undetected and lead to site compromise</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The new service should be protected by a firewall</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NETSEC-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The new ASP hosted service should be protected by a firewall</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify whether the ASP can supply the service with firewall protection in place</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Security vulnerabilities associated with non-essential services may lead to compromise of the system</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
</chapter>







<chapter><title>Auditing and Monitoring</title>
<section><title>Events to be alerted in real-time</title>
<section><title>Intrusion detection should be deployed</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMON-1</para></entry><entry><para>1.0</para></entry><entry><para>above baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Intrusion detection systems should be deployed in order to identify attacks against the service</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Determine from the risk analysis of the system it's importance</para></listitem>
<listitem><para>For important systems deploy an intrusion detection solution to monitor for attempted breaches</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Attempts to breach the system may go undetected.</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>

<section><title>Events to be audited</title>
<section><title>Monitoring of the platforms of the ASP components should take place to flag when any components move out of alignment with the hardened build specification.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMON-`2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Monitoring of the platforms of the ASP components should take place to flag when any components move out of alignment with the hardened build specification.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify whether the ASP provides any monitoring of the platform builds</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Security breaches of the platforms may go undetected</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The ASP should provide monitoring of the firewall rule base</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>SECMON-3</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The ASP should provide monitoring of the firewall rule base</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify whether the ASP can monitor firewall rule changes and reconcile the changes to valid, authorised changes.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Unregulated rule changes may introduce security vulnerabilities that may lead to compromise of the system</para></listitem>
<listitem><para>Legal and regulatory responsibilities may not be met</para></listitem>
<listitem><para>Technical security controls may be undermined</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
</chapter>
<chapter><title>Other</title>
<section><title>Ensure that the Application Service Provider and your organisation develop and agree incident handling processes and procedures</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>OTHER-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that the Application Service Provider and your organisation develop and agree incident handling processes and procedures</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Define security incidents that require a response</para></listitem>
<listitem><para>Determine the responses to be taken in the event of a security incident</para></listitem>
<listitem><para>Determine the party responsible for taking the response</para></listitem>
<listitem><para>Capture the above in a process document</para></listitem>
<listitem><para>Define procedures to be followed to execute the process</para></listitem>
<listitem><para>Implement the process and procedures between your organisation and the ASP.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Remedial action may fail to be taken in the event of an incident</para></listitem>
<listitem><para>Inappropriate and potentially more damaging action may be taken in the event of an incident</para></listitem>
<listitem><para>Legal, regulatory or contractual obligations may be breached</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that for a high availability requirement service that a fault tolerant implementation is deployed</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>OTHER-1</para></entry><entry><para>1.0</para></entry><entry><para>above baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that for a high availability requirement service that a fault tolerant implementation is deployed</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that the service is deployed with RAID, fault tolerant power supplies, online backups, mirroring, diverse network connections</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure a risk analysis is performed on the service to be provided</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>ASP-OTHER-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>A risk analysis must be performed on the service to be hosted to ensure that appropriate controls are built into the solution</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Perform a risk analysis on the application to determine the control requirements</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>A wholly inappropriate security solution may be implemented</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The security provided by the service provider must equate to the same or greater level of security that would be put in place were you to host it using your own organisation's capabilities.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>ASP-OTHER-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The security provided by the service provider should equate to a same or greater level of security that would be put in place were you to host it by your own organisation.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Determine the appropriate level of security control required using risk analysis</para></listitem>
<listitem><para>Determine the security capability of the provider</para></listitem>
<listitem><para>Determine whether this delivers the control required against the risk analysis</para></listitem>
<listitem><para>Determine whether this delivers the same control as that were you to host the service yourselves.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The security solution delivered may be wholly inappropriate for the service</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Incident handling processes and procedures should be tested</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>OTHER-3</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Incident handling processes and procedures should be tested</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Define and agree scenarios to be tested with the ASP</para></listitem>
<listitem><para>Simulate the scenario and execute the incident handling procedure</para></listitem>
<listitem><para>Measure deficiencies with the plan and its execution and re-develop the process and procedure accordingly</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Remedial action may fail to be effective in the event of an incident</para></listitem>
<listitem><para>Inappropriate and potentially more damaging action may be taken in the event of an incident</para></listitem>
<listitem><para>Legal, regulatory or contractual obligations may be breached</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</chapter>
<chapter><title>Checklist</title><informaltable><tgroup cols="3" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="5*" colname="c2"/><colspec colwidth="1*" colname="c3"/><spanspec align="left" nameend="c3" namest="c1" spanname="hspan"/><tbody><row><entry align="center" spanname="hspan"><para><emphasis>Security Compliance</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Security Management</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>ASP-SECMAN-3</entry><entry>Has the suppliers information security service claims been analysed for consistency with their organisational structure, resourcing level and your organisation's security service requirements.</entry><entry><para/></entry></row><row><entry>SECMAN-11</entry><entry>Does the ASP contract define the security services to be provided and the service levels?</entry><entry><para/></entry></row><row><entry>ASP-SECMAN-2</entry><entry>Has the suppliers information security organisational structure been analysed for consistency with the stated policies and the claimed security services.</entry><entry><para/></entry></row><row><entry>ASP-SECMAN-4</entry><entry>Does the description of the suppliers arrangements for auditing the services that they provide equate to or exceed the level of auditing that would be provided were it performed in-house?</entry><entry><para/></entry></row><row><entry>SECMAN-12</entry><entry>Is the supplier bound by confidentiality agreements to prevent leakage of your data to other parties who might also use the ASP service.</entry><entry><para/></entry></row><row><entry>ASP-SECMAN-1</entry><entry>Has the suppliers information security policy been obtained and analysed for consistency with that of your own organisation?</entry><entry><para/></entry></row><row><entry>SECMAN-10</entry><entry>Is the ASP willing to provide details of their security capabilities?</entry><entry><para/></entry></row><row><entry>SECMAN-13</entry><entry>Are ASP personnel working on the ASP solution subject to equivalent background checks as staff within your own organisation?</entry><entry><para/></entry></row><row><entry>SECMAN-16</entry><entry>Is it ensured that hardening of the components of the solution takes place in line with the policies and standards that are applicable within your organisation?</entry><entry><para/></entry></row><row><entry>SECMAN-9</entry><entry>Is there a regime for measuring the security services provided at an appropriate frequency?</entry><entry><para/></entry></row><row><entry>SECMAN-14</entry><entry>Do the ASP contracts of employment place equivalent or greater emphasis on information security as that in your organisation's own contracts of employment?</entry><entry><para/></entry></row><row><entry>SECMAN-15</entry><entry>Has it been ensured that the ASP management practices in relation to the components that make up the solution do not introduce vulnerabilities?</entry><entry><para/></entry></row><row><entry>SECMAN-8</entry><entry>Is the ASP subject to periodic audits?</entry><entry><para/></entry></row><row><entry>ASP-SECMAN-5</entry><entry>Has the supplier provided contact names and details for each element of the security organisation that is to deliver security services to your organisation?</entry><entry><para/></entry></row><row><entry>SECMAN-7</entry><entry>Does the ASP have a well defined information security organisation with clearly defined responsibilities?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Network Security Configuration</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Internet Considerations</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NETSEC-1</entry><entry>Will vulnerability scanning/penetration testing be performed prior to the new service going live?</entry><entry><para/></entry></row><row><entry>NETSEC-2</entry><entry>Is the new ASP hosted service protected by a firewall?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Auditing and Monitoring</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Events to be alerted in real-time</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>SECMON-1</entry><entry>Has an intrusion detection system been deployed in order to identify attacks?</entry><entry><para/></entry></row><row><entry spanname="hspan"><para><emphasis>Events to be audited</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>SECMON-`2</entry><entry>Will the solution provide perform monitoring of the platforms of the ASP components to flag when any components move out of alignment with the hardened build specification?</entry><entry><para/></entry></row><row><entry>SECMON-3</entry><entry>Does the ASP provide monitoring of the firewall rule base?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Other</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>OTHER-2</entry><entry>Have incident handling processes and procedures been developed and agreed with the Application Service Provider?</entry><entry><para/></entry></row><row><entry>OTHER-1</entry><entry>Has a fault tolerant implementation been deployed?</entry><entry><para/></entry></row><row><entry>ASP-OTHER-1</entry><entry>Has a risk analysis been performed on the service to be hosted?</entry><entry><para/></entry></row><row><entry>ASP-OTHER-2</entry><entry>Is the security provided by the service provider equivalent or greater than the level of security that would be put in place were it hosted by your own organisation?</entry><entry><para/></entry></row><row><entry>OTHER-3</entry><entry>Have incident handling processes and procedures been tested?</entry><entry><para/></entry></row></tbody></tgroup></informaltable></chapter></book>
