The transferring of data, whether internally or to external recipients, carries additional security risks. Employees must therefore:
You should never assume that internal or external messages are necessarily private and confidential, even if marked as such. The Internet is not a secure means of communication and third parties may be able to access or alter messages that have been sent or received. So do not send any information in an email which you would not be happy being publicly available. The confidentiality of internal communications can only be ensured if they are sent by internal post or delivered personally by hand or included in a password protected online document.
The CIO is responsible for creating, implementing and maintaining an adequate Disaster Recovery Plan for the Company’s business, namely the ability to restore access and functionality to the Company’s IT infrastructure after a disaster event, whether natural or caused by human action or error, to ensure that critical business functions are operational as soon as possible after a disruptive event occurs.
Cybersecurity is an increasingly common area where disaster recovery is critical to handling threats.
Maintenance requires the proper replication and backing up of data and IT infrastructure to specific restore points in order to regain functionality and control over systems that become infected, breached, or rendered inoperable for any reason.
The CIO periodically conducts disaster recovery tests to help identify any weaknesses or gaps in the Company’s Disaster Recovery Plan and to ensure that the strategic processes in place will effectively restore critical systems and data in the event of an incident, enabling the Company to regain control over its IT systems.
CSCSP 10/2025