Wednesday, 20 April 2016

Safety in Construction Site Part 1

asp.net software companies in india
























Most accidents can be prevented by taking simple measures or adopting proper working procedures for asp.net software companies in india . This article is intended to outline important issues on safety and health that should be paid attention to on construction sites for easy reference by the workers. If we work carefully and take appropriate safety measures, there will definitely be fewer work injury cases, and our sites will become a safe and secure place to work in.

The Occupational Safetyand Health Ordinance, which came into operation on 23 May 1997, covers most workplaces in order to protect the safety and health of employees at work. Other legislation applicable to construction sites includes the Factories and Industrial Undertakings Ordinance and its subsidiary legislation, particularly the Construction Sites (Safety) Regulations.

Employee’s Responsibilities

Employees should cooperate in asp.net software companies india with their employers and other persons in complying with the safety legislation and guidelines, and should not do anything to endanger themselves and other persons.

Basic Rules for Safety

Tidy up construction sites
  • Keep passages clear all the time.
  • Sort out materials and pile them up safely. The stacks should not be too high.
  • Beware of floor openings and ensure that they are fenced or covered.
  • Remove refuse as soon as possible.
  • Provide sufficient lighting.
  • Familiarize with the location and the operation of fire-fighting equipment.
Safety measures
  • Before you operate a machine, ensure that the dangerous part of the machine has been installed with a guard.
  • Avoid going to any area with insufficient lighting as there may be some dangerous places which have not been provided with fencing.
  • Keep vigilant all the time and watch out for moving cranes, hooks or other lifting equipment.
  • Before you use any electrical installation or tool, check the condition of its electric cables.
  • Avoid dragging electric cables on the ground or allowing the cables to come into contact with water.
  • Use electrical tools installed with an earth leakage circuit breaker.
  • Use and handle chemicals with care.
Personal Safety
  • Wear protective equipment.
  • Do not drink or take drugs while working.
  • Pay attention to personal hygiene.
  • Do not play in the workplace.
  • Report to your supervisor immediately if you notice any unsafe condition.

Emergency Response to Accidents

You should have a good understanding of your working environment of c#.net software companies in india and the instructions given by your supervisor. When evacuation is required in an emergency, you should keep calm and find out:
  • What dangerous situation the alarm refers to.
  • The routes for evacuation.
  • The safe place that you should go to as designated by the company
When someone is found seriously injured, you should:
  • Keep calm.
  • Seek help immediately.
  • Accompany the injured person.
  • Assist in the immediate rescue work as far as possible.
  • Call the site safety staff.
  • Do not tamper with the accident scene while waiting for the arrival of the investigation team.
When a fire breaks out, you should remember:
  • Put out the fire with a fire extinguisher if it is a small fire.
  • If the blaze is out of control, do not try to extinguish the fire on your own. Call the Fire Services Department right away.
  • Always pay attention to the emergency telephone numbers posted on the notice board in the site office.

Tips for Workplace Safety

Falsework

If you are engaged in falsework operation of c#.net software companies india, you should:
  • Check whether the falsework is erected in accordance with the design.
  • Make sure that the falsework is securely erected.
  • Check whether the struts of the falsework are secure.
  • Ensure that the props are erected vertically and arranged at a suitable distance in a row.
  • Report to your supervisor when any unsafe situation is found.

Scaffold
  • Do not use scaffolds unless they have been erected by trained workmen and under the supervision of a competent person.
  • Do not use a scaffold unless it has been inspected and certified safe by a competent person before use.
  • Strictly follow the instructions of a competent person. Do not alter the scaffold unless authorized to do so. Do not work on an unfinished scaffold.
  • When it is necessary to work on a mobile scaffold, lock the wheels of the scaffold before you start working.
  • Do not work on a scaffold unless it has been provided with a suitable working platform.

Fencing
  • Do not work in a dangerous place unless its floor edges and openings have been installed with secure fencing.
  • If you notice any dangerous places that have not been installed with fencing or the fencing has been damaged, reinstall or repair the fencing. If this is beyond your capability, inform your supervisor at once.

Ladder
  • Use a ladder which is of good construction, sound material and adequate strength.
  • Examine the ladder before using it and inspect it at regular intervals.
  • Place the ladder on a level and firm footing.
  • Place the ladder at an appropriate angle.
  • Ensure that the ladder has a sufficient length. The upper end of the ladder should be at least 1 meter above the landing against which the ladder leans.
  • Do not use a ladder unless its upper or lower end has been securely fixed or secured by another worker.
  • If there are electrical installations nearby, do not use metal ladders.
  • If work is carried out 2 meters or more above the floor, use a suitable working platform.

     Courtesy: Sanika Taori

Tuesday, 19 April 2016

Information Security Processes

asp.net software companies in india

Five Ways to Future-Proof Information Security Processes

From DDoS to IP theft, cyber-attacks are taking their toll on organizations.  Realizing the potential impact to the bottom line, the business is increasingly ready to participate in managing cyber risks for asp.net software companies in india. According to the Global State of Information Security® Survey 2014, leading organizations are “enhancing security capabilities in ways that show security is now a business imperative—not just an IT challenge.” The survey reveals average losses from incidents are up 18% over last year, with big liabilities increasing faster than smaller losses. More proactive cyber risk management is required in order for organizations to innovate and prosper.

If the business is ready to be part of the security equation for asp.net software companies india, what’s the game plan for security teams? They need to establish formalized, consistent security processes that will integrate into critical business processes. Security teams will have to work closely with the business to establish goals, educate on risks, and communicate solutions. It requires an understanding of how information is used in conducting business and the best way to protect critical business processes end-to-end.

The SBIC has been championing the need for businesses to proactively manager cyber risk for some time now for asp.net software company india. Our latest report is focused on optimizing security processes and draws attention to that fact that the ad hoc processes from the days of checklist compliance and perimeter-based security won’t work to manage today’s cyber risks.  The report – Future-Proofing Processes – highlights some of the most problematic outcomes of outdated security processes:

  • Using technical terms for risk measurement makes advising business leaders difficult
  • Cumbersome manual methods for tracking risks are not business-friendly
  • Point in time piecemeal control assessments are no longer sufficient
  • The system for third-party security assessments and oversight needs fixing – fast
  • Headway needs to be made towards meaningful collection and analysis of threat data

c#.net software companies in india
Ways to future proof info sec processes

The report’s five recommendations provide guidance on how to update existing processes for c#.net software companies in india, design key new processes, and upgrade techniques to help move information security programs forward. They include:

  • Shift Focus from Technical Assets to Critical Business Processes – start documenting processes and think about how to protect the most critical business processes from end-to-end
  • Institute Business Estimates of Cybersecurity Risks – develop scenarios estimating the likelihood and impact of incidents and hone techniques to quantify risks by projecting monetary losses
  • Establish a Business-Centric Risk Assessment Process – use automated tools for tracking risks and hold the business accountable.
  • Set a Course for Evidence-Based Controls Assurance – collect relevant data to test the efficacy of controls on an on-going basis for both internal and 3rd party assessments.
  • Develop Informed Data-Collection Methods – Examine the types of questions data analytics can answer then build a set of data use cases


As information security teams for asp dot net software company india face greater demands and elevated expectations, a fresh look at key processes can be an enabler for positive change. We’re confident that this latest guidance can help your organization zero in on processes that deserve some attention.

Courtesy: Aagam Shah

Monday, 18 April 2016

Personl Quality Management with Personal Software Process Part 2

asp.net software companies in india












Career Enhancement by Reducing Both Costs and Defects


As professionals, we Software Engineers must assume responsibility for the quality of the products we produce for asp.net software companies in india. Our employers pay us for producing not just software, but good software, high-quality software.

The quality assurance organization cannot be thought of as the people who are responsible for quality. Indeed, of all members of the organization, they are in the position that is least able to affect the quality of the product. Testing and other QA activities can detect defects and make sure that they are removed, but quality cannot be tested into the product at the end. Quality must be built in or it will be absent. Therefore, the software engineers are the ones who have the most direct impact on the quality of the product of asp.net software companies in india.

It is easy to lose sight of the tremendous costs that defects cause for our employers. Integration and system test can account for 50% of development time (and most of that time is spent in remediation and re-testing to eliminate the scores of defects that are commonly found). Then post-release defect mitigation and removal can cost more than the original development effort (including testing)! Supporting customers, investigating problems and releasing patches consume huge amounts of time and effort. And the cost of defects in loss of customer good will and market image goes beyond even that.

Defect removal costs escalate with each passing lifecycle phase. Different people have estimated different costs at the various phases, but they tend to agree that the costs rise (possibly even exponentially) with each passing phase. Regardless of the specific numbers one might cite, the cost escalation is obvious from the fact that we talk about removing "defects per hour" before Integration, and spending "hours per defect" during and after Integration.

Your value to your employer will be enhanced by your ability to produce salable (or usable) software at a minimum cost. Although the early defect detection and prevention methods we will discuss all have costs associated with them, they are demonstrably less expensive than removing the same defects later in the software lifecycle. So you can reduce costs through defect prevention and early defect removal, while at the same time producing more salable or usable software with fewer delivered defects. You enhance your career and value to your employer by exercising professional responsibility and managing your own quality.

Quality of Work-Life Issues


Practitioners of Personal Quality Management have also found that it has a positive impact on the quality of their work-life.

Most of us went into programming because we enjoy building things and seeing the results of our labor for c#.net software companies india. We like the challenge of figuring out how to attack a problem, of designing the structures and algorithms that will get the job done, and even of writing the code to make it all happen. And we like to see the fruit of our labor integrated into a system that meets people’s needs or provides an important service.

But between the coding and use, there is a long and (for most of us) painful time of fighting our way past defect after defect. It starts with the compiler leading us around by our noses, complaining about every little typo and syntax error, and often totally misinterpreting what the code was supposed to say. Then after achieving a clean compile, we try over and over again to get the program to do the right thing. It loops, it hangs, it crashes; and now the debugger is the thing that is dragging us around by the nose. For each problem we fix, there seems always to be another one lurking in the shadows. And even more frustrating is that too often our fix was the cause of the ensuing problem!

But releasing the software doesn’t end this frustration. Right when we’re in the middle of designing the next interesting program, we get interrupted to fix a latent problem. There is a fuming customer and an unhappy boss, so we must drop everything to make an emergency fix. And to add insult to injury, the interruption of our design work is likely planting the seeds for future problems and their interruptions and frustrations.

Personal Quality Management allows us to gain control over defects. Instead of being ruled by the defects in our software, we can gain the upper hand. We can understand them, find them, remove them earlier and even avoid them altogether. That means that we will spend a much greater proportion of our time on the tasks we enjoy, and less on the problems we missed. That is a significant improvement in our work-life!

Bibliography

  1. http://www.askprocess.com/consult/quality.html
  2. http://en.wikipedia.org/wiki/Personal_software_process
  3. http://www.methodsandtools.com/archive/archive.php?id=60


Courtesy : Sanika Taori

Personl Quality Management with Personal Software Process Part 1

asp.net software companies india


















Software development organizations have a variety of mechanisms at their disposal to help in managing and improving the quality of the products they produce for asp.net software companies in india. Quality Assurance organizations, problem reporting systems, software process improvement and peer reviews (to name just a few) are important tools for product quality enhancement. But an often-overlooked piece of the quality puzzle may well provide the most effective means to improve product quality: the individual software engineer.

After a short introduction to what the Personal Software Process (PSP) is, we will highlight the ways in which individual engineers (and their organizations) can benefit from adding the PSP’s Personal Quality Management techniques to their professional repertoires. We will take a brief look at the benefits that have been achieved by those who have already learned to apply these principles in their work for asp.net software companies india. Then we will examine in more detail the specific activities PSP-trained engineers engage in to manage the quality of the software they produce. We will look at everything from simple defect logging, to personal and peer reviews, to developing a personal quality plan and using it to guide your work.

What is the PSP?

The concepts and activities discussed in this article are the quality management aspects of the Personal Software Process (PSP) developed by Watts S. Humphrey of the Software Engineering Institute (SEI).

The PSP is more than just training; it is a boot camp consisting of about 40 hours of classroom instruction, 10 programming assignments, and 3 data-analysis exercises, requiring a total of about 150 hours for the average programmer to complete for asp.net software company in india.

The result of the PSP boot camp is that the programmers don’t just learn about good processes, they actually improve their own processes, measure the effects of those process changes, quantify the benefits they have experienced, and set goals for further improvements. The PSP achieves these results by leading students through three steps.

In PSP step0, they lay a simple foundation for the learning to come:
  • Following simple process scripts,
  • Collecting three basic measures of their work (time spent, size of products produced, and defects corrected), and
  • Performing a simple post-project analysis.
In PSP step1, they begin to build the capability to plan and manage their own work, setting the stage for Personal Quality Management:
  • Following a defined project planning process,
  • Using their own prior data to make increasingly more accurate estimates for each programming assignment, and
  • Planning their work at a level of detail that allows them to track and manage their progress.

In PSP step2, they focus on achieving significant quality improvements by learning how to engage in Personal Quality Management:
  • Using their prior data to plan for incremental improvements in the quality of their programs,
  • Removing defects early using personal review techniques guided by their own prior defect performance, and
  • Identifying and capitalizing on defect prevention opportunities in their program design and implementation methods.

Those who complete the PSP boot camp emerge with the knowledge and skills to make accurate plans, work to those plans, and produce superior quality products.

The Motivation for Personal Quality Management


Most programmers have never learned to apply personal quality management techniques like those described in this article in their work for asp dot net software companies in india. This is because our educational system has generally ignored the topic, and in the software business, "quality assurance" often refers to little more than testing. This is unfortunate, because vast opportunities for improving the quality of the software we produce are being missed as we continue with business as usual.

This is surprising, given that these techniques are anything but new. Other engineering disciplines have embraced them for decades and manufacturers and engineering companies have been applying them for nearly fifty years.

Watts Humphrey, in the PSP has given programmers the opportunity to understand these methods and apply them to software development. Those who have done so have found the effects on their work to be dramatic, with the improvement in the quality of their software the most obvious and rewarding aspect. These individuals have begun to take control of the task of writing programs, and are taking the first steps toward changing "software engineering" into a true engineering discipline.

Defect Content as a Dimension of Quality


When we think of software quality, we tend to think about defects. This is a natural tendency, since defective software isn’t good for much. But a defect (or more correctly, lack of defects) is not the only, or even the most important dimension of quality. Other dimensions of quality include Usability, Maintainability, Install-ability, Security, and Reliability. In any product, each of these dimensions is important to one degree or another and every development project must be careful to pay appropriate attention to them. But from the point of view of Personal Quality Management, defect management is first priority. This is true for two reasons:

  • The other dimensions of quality are issues of either product requirements or organizational standards. While the individual software engineer can affect these things, they are not under his or her direct control.
  • Defect injection is a purely personal phenomenon. Each person’s defect numbers, types and patterns are unique, and require personalized actions to effectively detect and eliminate them.
You may note throughout this article that I will never refer to "bugs". I believe that this term trivializes a very important issue, making it sound minor, or even cute. In fact, defective software wastes millions of dollars for companies and individuals throughout the world. And as we become more and more dependent on software for critical functions, it is becoming important to organization’s and individual’s health and life. In order to focus on defects as a quality management priority, we must understand their nature. This nature can be summed up this way:
  • Software that contains one or more defects is "defective".
  • Defects are the result of human errors.
  • All humans make errors.
  • All software engineers are human.
Therefore, defect management must be the first quality management focus for all Software Engineers.

Courtesy: Sanika Taori

Sunday, 17 April 2016

Overview and Evolution of Firewalls

asp.net software company in india






















Firewalls are the first line of defense between the internal network and untrusted networks like the Internet. You should think about firewalls in terms of what you really need to protect asp.net software company in india , so you will achieve the right level of protection for your environment.

Firewalls have been one of the most popular and important tools used to secure networks since the early days of interconnected computers. The basic function of a firewall is to screen network traffic for the purposes of preventing unauthorized access between computer networks.

First introduced conceptually in the late 1980s in a whitepaper from Digital Equipment Corporation, “firewalls” provided a then new and important function to the rapidly growing networks of the day for asp.net software comapany india. Before dedicated hardware was commercially available, router-based access control lists were used to provide basic protection and segregation for networks. However, they proved to be inadequate as emerging malware and hacking techniques rapidly developed. Consequently, firewalls evolved over time so their functionality moved up the OSI stack from layer three to layer seven.

The Evolution of Firewalls

First-Generation Firewalls were simply permit/deny engines for layer three traffic, working much like a purposed access control list appliance. Originally, first-generation firewalls were primarily used as header-based packet filters, capable of understanding source and destination information up to OSI layer four (ports). However, they could not perform any “intelligent” operations on the traffic other than “allow or deny it from this predefined source IP address to this predefined destination IP address on these predefined TCP and UDP ports.”

Second-Generation Firewalls were able to keep track of active network sessions for asp.net software companies in india, putting their functionality effectively at layer four. These were referred to as stateful firewalls or, less commonly, circuit gateways. When an IP address (for example, a desktop computer) connected to another IP address (say, a web server) on a specific TCP or UDP port, the firewall would enter these identifying characteristics into a table in its memory. This allowed the firewall to keep track of network sessions, which could give it the capability to block Man-In-The-Middle (MITM) attacks from other IP addresses. In some sophisticated firewalls, a high-availability (HA) pair could swap session tables so that if one firewall failed, a network session could resume through the other firewall.

The Third Generation of firewalls ventured into the application layer—layer seven. These “application firewalls” were able to decode data inside network traffic streams for certain well-defined, preconfigured applications such as HTTP (the language of the web), DNS (the protocol for IP address lookups), and older, person-to-computer protocols such as FTP and Telnet. Generally, they were unable to decrypt traffic, so they were unable to check protocols like HTTPS and SSH. They were designed for c#.net software company in india with the World Wide Web (WWW) in mind, which made them well suited to detecting and blocking web site attacks that were generating a great deal of concern at the time, like cross-site scripting and SQL injection.

Consider these in comparison to today’s current generation of firewalls (commonly termed the fourth generation), which have the intelligence and capability to look inside packet payloads and understand how applications function. As silicon has increased in speed, advanced router-based firewalls exist today that can provide IP inspection as a software component of a multipurpose router, although they do not provide the speed or sophistication of today’s industrial-strength firewalling solutions. In addition, Unified Threat Management (UTM) devices have combined sophisticated, application-layer firewalling capability with antivirus, intrusion detection and prevention, network content filtering, and other security functions. These are true layer seven devices.

Fourth-Generation Firewalls can run application-layer gateways, which are specifically designed to understand how a particular application should function and how its traffic should be constructed and patterned (traffic that conforms predictably to an application’s well-defined communication protocol is referred to as “well formed”). There are Fifth-Generation Firewalls, which are internal to hosts and protect the operating system kernel for c# dot net software company in india, and some Sixth-Generation Firewalls have been described (meta firewalls), but most network appliances you will find today fall into the generally accepted fourth-generation firewall definition. Some manufacturers call their devices “Next-Generation Firewalls” or “Zone-Based Firewalls,” and these essentially function under the same guiding principles of the fourth-generation designs. In this chapter, we primarily focus on fourth-generation firewalls and the key functionality that they enable.


Courtesy: Sanika Taori

Thursday, 14 April 2016

Organization of Information Security Part 3

Mobile Computing and Teleworking

Policies for use of mobile computing devices and work in off-site settings (“tele-work”)  for asp.net software company in india should aim for information security commensurate with that for work in on-site settings and for non-mobile devices, where operationally and technically feasible.


Mobile computing and tele-working controls

Controls should be implemented that are in proportion with settings of mobile/tele-working use, the types of users and sensitivity of the data and applications being accessed from mobile/tele-working settings.


Applicability

Controls on mobile computing and tele-working should extend to any non-traditional or extra-institutional work setting where the information of the organization is accessed. Controls on following could be included:
• "Smart" phone-PDAs and mobile phones
• Desktop computers used off-premises
• Media and portable storage devices 
• Any other type of component capable of displaying, using, transmitting and storing the information of the organization.
• Notebook, palmtop computers and laptop


Portable devices and media controls

Appropriate security measures should be required for mobile computing and communications activities for asp.net software companies india.  Following Guidelines and/or requirements could be included:
• Regular data backups for stored sensitive data
• Physical security measures
• Prohibition or minimization of data storage on devices in off-premises locations or mobile devices, particularly sensitive data
• Secure communication methods for transmitted data such as Virtual Private Network
• Updates for operating system and other software updating
• Independent validation of appropriate device configuration
• Access control and  appropriate user authentication (biometric-based) 
• Cryptographic methods for sensitive data
• Protective software such as anti-virus and others


Controls against malicious mobile code

Proper controls should be implemented for response, detection and prevention to mobile versions of malicious code also including appropriate user awareness.


Tele-working controls

Appropriate security measures should be required for "tele-working" activities.  Following could be included:
• Policies regarding organizational property used at the site (e.g., organization’s software and hardware)
• Environmental and physical security measures
• Policies concerning safety of private property used at the site 
• Appropriate user access control and authentication, given reasonably anticipated threats from other users at the site
• Security measures for wireless and wired network configurations at the site
• Specification of financial responsibility for equipment replacement or repair and Insurance coverage.
• Cryptographic techniques for communications from/to the site and data storage
• Data backup at regular intervals and security measures for those backup copies
• Intellectual property  policies created or used at the site which includes software licensing



References:
3. Teleworking and Mobile Working Procedures--www.derbyshire.gov.uk
Courtesy: Sanika Taori

Organization of Information Security Part 2

asp.net software companies india











Allocation of responsibilities

Information security responsibilities for asp.net software companies india should be defined clearly.  Following points could  be included:
·  Identification of the individual/individuals responsible for security of each information facility
· Clear definition and identification of assets and associated security controls for each information facility

Coordination of efforts

All the Information security activities should be coordinated by representatives from different parts of the organization with appropriate security job functions and roles.  Following points could  be included:

  • Coordinated efforts to assess the adequacy and effectiveness of  already implemented controls and to recommend additional measures based on the assessments
  • To ensure that all information security controls are executed in compliance with the organization’s information security policies and privacy
  • Identifying significant vulnerability changes and threat, both external and internal, and recommending appropriate action to deal with them
  • Proposing refinements to assessment processes and methodologies (e.g., risk assessment) subject to approval by management
  • Promoting training and security awareness programs for all persons affiliated with the organization.
  • Evaluating information security incident management (ISMS) data from across the organization,  as well as reporting these data to appropriate management personnel, and recommending appropriate action based on this data

Authorization processes

A management authorization process for new information processing capabilities and facilities, and for significant changes to existing capabilities and facilities for C# software company in india, should be defined as well as implemented.  Following points could  be included:

  • Certification that software/hardware used by the new or changed existing system meets standards of the organization
  • Formal approval of use and purpose for each new system, or for existing systems that are changed materially
  • Approval of any non-standard users, functions or locations, including approval of any personal, extra-organizational or privately-owned software/hardware/facilities to be used
  • Certification that the new or changed existing system complies with all applicable and relevant security controls mandated by the security policy of the organization

Confidentiality and non-disclosure agreements

Requirements for confidentiality and non-disclosure agreements for C# software company india should reflect the needs of organization for protection of information.  These agreements should be reviewed periodically.  Following points could  be included:

  • Responsibilities of signatories, which includes adherence to security controls and limitations on disclosure or use of information
  • Definition of the information, information system(s) or information type(s) that are to be protected
  • Actions required when the agreement is terminated that includes requirements to destroy or return information
  • Processes for notice of and reporting of breaches
  • Confidentiality and non-disclosure agreements for that information rendered in legally-enforceable, clear terms, that accord with all relevant statutory-regulatory and private certificatory authorities
  • Expected agreement duration
  • Right to monitor compliance with the agreement
  • Terms of ownership of information that includes both intellectual property or trade secret requirements
  • Expected actions that need to be taken in the event of a breach

Contacts with authorities

Appropriate contacts should be maintained with external authorities.  Following points could  be included:

  • Specification of the manner and timing in which breaches shall be communicated to external authorities so as to ensure appropriate reporting
  • Development of procedures, policies and contact lists that specify by whom and when external authorities should be contacted

Contacts with special interest groups

Appropriate contacts should be maintained with special interest groups or other professional associations and specialist security forums.

Contracts and contacts with external parties

Agreements with third parties for C# software companies india that involve processing, accessing, managing or communicating the organization's information or information processing facilities should cover all relevant security requirements. Such agreements could include following content:

  • Requirements for system administrator and user training efforts and awareness
  • The applicable information security policy/policies of all contracting organizations
  • Specific and clear process of change management
  • Appropriate definitions of verifiable performance criteria
  • Overall reporting formats, report contents and frequency, and reporting structure
  • Essential controls to ensure compliance with the security policies
  • Responsibilities related to software/hardware configuration and selection
  • Specific and clear process of incident management that includes requirements for notification, reporting and investigation
  • Ownership of data and intellectual property rights
  • Problem resolution processes that includes escalation steps
  • Conditions for termination/ renegotiation of the agreements
  • Rights to audit and monitor activities
  • Levels of service continuity and unacceptable/acceptable service
  • Policies regarding subcontractors

Contacts and contracts with customers

Before giving customers access to the organization's information or assets identified security requirements should be addressed. The control considerations are similar to those for other external parties mentioned above.
Independent review of information security

The organization's approach to managing information security and its implementation should be reviewed independently at planned and regular intervals as well as when there are significant changes to the external environment or the internal structure.