The following is the domain checklist:
- Is the data encrypted?
- Will the data that is sent over the network be encrypted?
- Is the data storage distributed?
- Does a backup and recovery system containing procedures and executables exist for:
- Periodic saving of a coherent set of copies of datasets
- Logging of all transactions starting from the last generation
- Reprocessing of all logged transactions
- Does the back-up procedure determine when the datasets and database need to be secured and how long these back-ups should be kept?
- Is a description of the required authorizations available?
- Is a procedure for the maintenance of the authorizations available?
- Is a specific application present and in use for security (that is, RACF)?
- Do specific ...