Related provisions for CREDS 2.2.57
1 - 10 of 10 items.
A firm should establish and maintain appropriate systems and controls for the management of its IT system risks, having regard to:(1) its organisation and reporting structure for technology operations (including the adequacy of senior management oversight);(2) the extent to which technology requirements are addressed in its business strategy;(3) the appropriateness of its systems acquisition, development and maintenance activities (including the allocation of responsibilities
A firm should document its strategy for maintaining continuity of its operations, and its plans for communicating and regularly testing the adequacy and effectiveness of this strategy. A firm should establish:(1) formal business continuity plans that outline arrangements to reduce the impact of a short, medium or long-term disruption, including:(a) resource requirements such as people, systems and other assets, and arrangements for obtaining these resources;(b) the recovery