C. Integrity
Question 17
Is there any digital certificate system in the Network
infrastructure?
1 : No 2 : Not sure 3 : distribution only 4 : Not applicable 5 :
Yes
Question 18
Is access to data files and programs restricted or controlled in
any way?
1 : No 2 : Not sure 3 : No opinion 4 : Not applicable 5 : Yes
Question 19
Is there a facility to detect and report unauthorized attempts to
access ALL sensitive data?
1 : No 2 : Not sure 3 : No opinion 4 : Not applicable 5 : Yes
Question 20
In addition to logical access controls, are there any physical
access controls for computers holding very sensitive data (e.g. PC key/lock,
stored in locked cabinet, etc.)?
1 : No 2 : Not sure 3 : No opinion 4 : Not applicable 5 : Yes
Question 21
Are laptops computers carrying sensitive data used offsite (home,
public network,...)?
1 : No 2 : Not sure 3 : No opinion 4 : Not applicable 5 : Yes
Question 22
Is there a mechanism in place to detect and prevent virus
infection?
1: No 2: Not sure 3: Planned 4: Not applicable 5: Yes
Question 23
Are all virus incidents managed in a secure manner, in that they
are cleaned up, investigated, reported to management, and properly
documented?
1: No 2: Not sure 3: Only reported 4: investigated 5: reported
and documented 6: investigated, reported and documented
Page | 62
D. Availability
Question 25
Do critical network and e-payment system hardware components
operate from an uninterruptable power supply system?
1 : No 2 : Not sure 3 : No opinion 4 : Some of them 5 : Yes
Question 26
Is the recovery of the e-payment system included in a formal
contingency/business resumption plan? (Business continuity plan)?
1 : No 2 : Not sure 3 : No opinion 4 : plan in development 5 :
Yes
Question 27
Are any back-up facilities, features or practices in place for
the DATA and SOFTWARE held on the system being reviewed?
1 : No 2 : Not sure 3 : No opinion 4 : Not applicable 5 : Yes
Question 28
What type of backup is performed?
1: Incremental 2 : Not sure 3 : No opinion 4 : periodic full and
incremental 5: always full backup
Question 29
How many copies of backup are taken?
1: one copy 2 : not sure 3 : not applicable 4 : two copies 5 :
more than two copies
|