Alikriteeri tarkentaa pääkriteerin vaatimusta.
In the processing of classification level I information, it is recommended on a risk basis that log data be retained for longer periods than for classification level II information (for example, at least 10 years).
Information processing environments for classification level I are typically limited in scope, consisting for example of terminal devices permanently disconnected from all networks. However, the reliable retention of a 10-year log accumulation is difficult to achieve using only terminal devices. Therefore, the collection of logs from such devices and the backup of collected log data usually require a planned and regular process. A practical implementation may be the regular collection of log data onto removable media, which is handled and stored for as long as classification level I information itself.
It must also be noted that if system access control or, for example, traceability relies on physical security measures, the records created by such measures may also need to be retained and managed in accordance with classification level I procedures.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.