Jump to Navigation

 

3.3.7 Operate & Monitor System Control Objectives

This set of control objectives corresponds to the operation of the system, the reporting of metrics and the collection of evidence, as defined in the Analyse and Design phase of the lifecycle, in accordance with what is defined in the service agreement (or contract), and in compliance to the accountability expectations (e.g. ethical behaviour, social norms, ...)

 

Identifier

Control Objective

Lifecycle Phase

4.01

Operate the system as intended.

4 - Operate

4.02

Gather and report on accountability and risk treatment metrics, keep the dashboards updated.

4 - Operate

4.03

Ensure collection and protection of evidence.

4 - Operate

4.05

Continuously monitor the system, the operating environment, and the ecosystem for signs of incident, breach or significant change. Trigger the exception handling processes as required, in case of a detected breach.

4 - Operate

 

Table 10: Operate and monitor system control objectives.