Laserfiche WebLink
City of Elk River <br />L3 Assessment with Roadmap <br />Phase 1— Administrative Security Controls is further segmented into the following 10 control categories which contain a total of 45 subcategories: <br />•� <br />7.1 Mobile device policy <br />7.2 Teleworking <br />7.3 Documented operating procedures <br />7.4 Change management <br />7S Controls against malware <br />7.6 Information backup <br />7.7 Event logging <br />7.8 Installation of software on operational systems <br />7.9 Management of technicaV vulnerabiVities <br />7.10 Information systems zudit controls <br />7.11 Network security <br />7.12 Information transfer policies and procedures <br />7.13 Information security requirements analysis and specification <br />7.14 System acceptance testing <br />7.15 Third party security risk management <br />8.1 Incident managemerrt roles and responsibilities <br />8.2 Incident respanse procedures <br />9.1 Planning information security continuity <br />9.2 Reco�ery pBac� details <br />. . . � <br />Identpfication of applicable legislation and contractual <br />10.1 <br />requirements <br />10.2 Privaey and protection of personally identifia6le information <br />10.3 Independent review of information security <br />10.4 Compliance with security policies and standards <br />10.5 Protections against financial fraud <br />The Administrative Controls are assessed through: <br />Documentation review <br />Interviews with the FRSecure Analyst <br />Observations made by the FRSecure Analyst <br />CONFIDENTIAL INFORNIATION <br />Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed <br />without prior permission of FRSecure. <br />Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 <br />