Goal: Implement procedures for periodic testing and revision of contingency plans.
The purpose of this policy is to establish a formal, documented policy and procedures that describes what the organization should do to conduct regular testing of its disaster recovery plan to ensure that it is up-to-date and effective.
Procedure: The Security Manager shall update the contingency plan every time new software or hardware is integrated into the system. Modification of systems, updates and upgrades may also require revision of the plan. At the very least, the contingency plan shall be tested and revised at random intervals but under no circumstances shall the gap between updates exceed one year. Testing and revisions will be documented by the Security Manager.