Element 05×Business Services
Business Services in Risk
Risk Assessment and Control
What Business Services owns here
This element holds information and cyber risk — the information security management system, cyber risk management and disaster recovery.
Example documents, by tier
Policy 1
- Acceptable Use of Information SystemsIn 1 of 3 operator registersCompany-wideAlso in EI PSM · 07 Documentation, records and knowledge managementNot process safetyNot safety case critical
Process, procedure, work instruction 3
- Information Security Management SystemIn 2 of 3 operator registersCompany-wideAlso in EI PSM · 06 Hazard identification and risk assessmentNot process safetyNot safety case critical
- Cyber Risk ManagementIn 3 of 3 operator registersCompany-wideAlso in EI PSM · 06 Hazard identification and risk assessmentNot process safetyNot safety case critical
- IT Disaster Recovery CapabilityIn 1 of 3 operator registersCompany-wideAlso in EI PSM · 14 Emergency preparednessNot process safetyNot safety case critical
Why these belong here
"Cyber risk is operational risk. If control systems can be reached, process safety depends on it."
What does not live here
- →The security standards themselvesE02 Policies
- →Incident response proceduresE07 Procedures