Standard | Category | Controls Satisfied | 800-53r4 Controls | ISO/SEC 27001 | A-lign Controls |
---|---|---|---|---|---|
NIST 800-171 | Systems & Information Integrity | 3.14.1 - 3.14.3 | SI-2, SI-3, SI-5 | A.12.6.1, A.14.2.2, A.14.2.3, A.16.1.3, A.12.2.1, A.6.1.4 | 5.0, 7.0 |
Date | Comment | Who |
---|---|---|
7/26/2019 | Initial Doc, Anti-Virus Policy | Tharp |
8/09/2019 | Updated 7.4 | Tharp |
8/12/2019 | Formatting Updates | Tharp |
8/29/2019 | Copied Content For IS-1 SOC submission | Tharp |
10/6/2021 | Policy's Reviewed for Audit | Tharp |
The purpose of this policy is to establish the organizational requirements for Systems Integration and Integrity monitoring and logging to ensure we operate within a secure infrastructure, using methods that meet or exceed industry best practice as well any governing compliance frameworks necessary to support our customers.
Provide guidance to operation methods and processes that must be maintained to conform with these policies.
Identify, report, and correct system flaws in a timely manner.
Provide protection from malicious code at designated locations within organizational systems.
Monitor system security alerts and advisories and take action in response.
Update malicious code protection mechanisms when new releases are available.
Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
Identify unauthorized use of organizational systems.
This Plan defines the backup Plan for computers within DLZP Group which have their data backed up. These systems are typically servers but are not necessarily limited to servers. Servers backed up include file, mail, database, application, and web.
This Plan is designed to protect data within DLZP Group to be sure it is not lost and can be recovered in the event of an equipment failure, intentional destruction of data, or disaster.
This Plan applies to all equipment and data owned and operated by DLZP Group, Inc.
Term | Definition |
---|---|
Backup | The saving of files onto mass storage media for the purpose of preventing loss of data in the event of equipment failure or destruction. |
Archive | The saving of old or unused files on offline low-cost mass storage media for the purpose of reducing storage costs. |
Restore | The process of bringing backup data back from mass storage media and putting it on an online storage system such for systems or data recovery. |
Backups are performed per the clients Contract or Statement of Work.
Full data replication of scanned files and reports, and scanned billing documentation and invoices is done real time using AWS data replication technology. DLZP Group also utilizes other AWS services to replicate production data to alternate site and/or disaster recovery standby databases. As data is changed on the production systems, that data is replicated to standby databases. This is done realtime. In case of primary database failure, the standby database can configured as the primary database with minimal configuration changes.