




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)
文檔簡介
ofcriticalinfrastructure requesttoitscommiThispublicationhasbeenrepresentation,warranty,assuranceorundertaking(expressoracceptedbyBSIinrelationtreasonablenessofthispublication.Allandanysuchresporecipient'sownrisk.respecttoitsuseofthispublication.responsibleforitscorrecThisBritishStandardwaspublisheAmendments/corrigendaissuedsincepublicationDateprotectiondesinfrastructurescritiquesPrivateSicherheitsSchutzkritischerInfrastrukturen-ThisEuropeanStandardwaCENmembersareboundtocomplywithththisEuropeanStandardthestatusofanationalstreferencesconcerningsuchThisEuropeanStandardexistsintmadebytranslationundertheresponsibilityofaCENmemberintoitsownlanguageandnotManagementCentrehasthesamestatusastheoCENmembersarethenationalstandardsbodiesofAustria,Belgium,Bulgaria,Croatia,Cyprus,CzechRepublic,Denmark,Estonia,Finland,France,Germany,Greece,Hungary,Iceland,Ireland,Italy,Latvia,Lithuania,LuxemNetherlands,Norway,Poland,Portugal,RepublicofNorthMacedonia,Romania,Serbia,Slovakia,Slovenia,Spain,Sweden,EUROP?ISCHESKOMITEEFURNORMUNG2Contents 5 5 6 7 7 84.2.1Management 84.2.2Humanresourcesmanagem 9 4.6Businesscontinuitymanag 4.8Corporategoverna 5.5Customerrespo 5.7Cooperationwithotherrel 5.9Leasedworkers/agency 6.1.4Identificationofstaff 6.2.2Criteriat 7.4Operationalplanandros 7.6Contractterminationandcessationofservices 21 EuropeanforewordThisdocument(EN17483-1:2021)hasbeenpreparedbysecurityservices",tThisEuropeanStandardshallbegiventhestatusofanationalstandard,eitherbidenticaltextorbyendorsement,apossibilitythatsomeoftheelementsoffAccordingtotheCEN-CENELECInternalRegulations,thenationalstandardsorgfollowingcountriesareboundtoimplemeCroatia,Cyprus,CzechRepublic,Denmark,Estonia,Finland,France,Germany,Greece,Hungary,IcelIreland,Italy,Latvia,Lithuania,Luxembourg,Malta,Netherlands,Norway,Poland,PorofNorthMacedonia,Romania,Serbia,Slovakia,Slovenia,Spain,Sweden,Switzerland,Turkeyandthe5ThisdocumentincludesthemainoverarchingrequirementsfortheprovisionoNOTE1Thisdocumentisthefirstpartofaseriesofstanrequirementsforrelatedsbalancebetweenqualityandprice.ThisdocumentsetsouttheminimumrequiItspecifiesservicerequirementsforqualityintheorganization,profasecurityserviceproviderand/oritsindependentbranchesandestablishmentsundThisdocumentissuitablefortheselection,attribution,aproviderofsecurityservices.Thefollowingdocumentsarereferredconstitutesrequirementsofthisdocument.Fordatedreferences,onlytheeditioncitedapplundatedreferences,thelatesteditionofthereferenceddocument(includEN15602,Securityserviceproviders-Termi6Forthepurposesofthisdocument—IECElectropedia:availableat/—ISOOnlinebrowsingplatform:availableathttps://wasset,system,orapartthereof,whichisessentialforthemaintenanceofvitalsocietalfunctisafety,security,economicorsocialwell-beingofpeople,wherethedisruptionordestructionofwhichthreatposedbyunauthorisedaccess,useordisclosureofprivilegedinformation,techniqtechnology,assetsorpremisesbyanindividualwithlegitimsystematicprocessfortheidentification,analysisandevaluationofthreatstodeterminetheimpactoftheconsequencesofhazardsandthreatsrelativetotheprobabilityofthetotalofdefinedorganizational,personnel,technicalandstructuralsecuritymeasuresfortheprevenand/oravertingofdangersthroughwrittenanalysisofpossibleattackanddamagescenarioswiththeaimofachievingadefinedlevelofprotec—analysisofthreats/damagescenarios/dangers;7staffperformancemanagementpolicysystematicprocessbywhichthinimprovingorganisationaleffectiveallotindividualaccountabilitytowardsthatgoalandtrackingoftheprogressintheachievementofthegoalsassignedandevaluatingtheirindividualperformance.Thestaffperformtheindividualperformanceortheaccomplishmentofanemployee,whichevaluatesandkeepstrackofallthesetofinterrelatedorinteractingelementsofanorganisationtoestablishpoliciesandobjectprocessestoachievetresponsibilities,planning,operation,policies,practices,rules,beliefs,objectivesandNote3toentry:Thescopeofamanaidentifiedfunctionsoftheorganization,specificandidentifieNote4toentry:Thisconstitutesoneofthecommontermbusinessstatisticswhichmeasureanorganisation'sperformancemonitoringactivitieswhich(ifnotproperlyperformed)wouldlikelycausedegradationoftheperformanceofforcriticalinfrastructureifthoseaaccordancewiththenationallegalframeworks.Aprovidershallonlyprovidethoseprivatesecurityservicproviderhasobtainedthenecessaryauthorizationfromthecompetentauthorit8e.g.notbeenconvictedforanyofthefollowingcrc)fraudand/ormoneylaunf)intentionalcrimesagainh)cyberandinformationsTheyneedtoholdtherequiredlicencefortheirfunctionwherelegallyofoperation;havecodeofconductdocumentsonethics,drresponsibilityandaboutoperationalprocedures6)operateunderconfidentialityproceduresforthemanagement8)haveanoperationalpresencewithprovidedforthedurationofthecontract,oratleastforthedurationoftheprovisionoftheservices;9)disclosethestructureofitsownmanagementfortheprovis10)discloseanyunspentcriminalconvictionsanlegislationregardingtheprotectionofenvironment;13)haveamanagement9Theprovidershallhavepoliciesinplace,whichshallincludetha)maintainingaccurateinformation/dataonstaffstrb)recruitmentincludingjc)retentionofstaff;h)disciplinaryandgrievance;k)staffsatisfactionmeasurement;n)abidebylawandregulationsTheprovidershallhaveapolicyformot-methodologies—motivationmeasuringsystem;—responsibilityonthejob;—self-management(shiftwork,measuresagainstboredom);TheprovidershallinforStaffperformancemanTheprovidershallimplementaclearlydefinedstaffperformancemanagement4.3HealthandSafeWorkshallbeplannedinamannerthatitcaTheprovidershallinvestigaand/orstaffifpresent,continuouslyassessrisksandtakeallprecautionsnecessTheprovidershalldocumenttheworkingconditionsandmeasuresworkingconditions.IncaseofahealthandsafetyincidenttheprovidersTheprovidershallinstallandmaintainTheprovidershalldemonstratethatithasthenecessarycapacityiprocedurestoguaranteethefullimplementationofalltermsandclausesTheprovidershalldiscloseinfdedicatedresponsiblemanagementifapplicable,theranTheprovidershalldisclosethefollowinginformationtothepotentialc-balancesheetsandprofiscompulsoryunderthelegislationorpracticeinthecountryiwhererelevant.Attherequestofthepotentialclient,theprovidershalfinancialplan,wheretherequestedsecurityservicesthelastclosedbusinessyearoftheprovider.Theprovidershallestablishadocumentedbusinesscontinuitypoliproceduresandthetechnologiesusedforthispurpose,e.g.onthebasisofENISO9001[4].Inparticular,thecriticalprocessesshallbeidentifiedandsuitablemeasuresfTheproviderisexpectedtocomplywithinternationaland/ornatagreementsregardinginsuranTheprovider'sinsuranceshallincludeco-loss,damageorinjurytothecustomerorthirdparti(aslongastheyhavebeencausedwhilstperformingthecontractualduties).TheprovidershallprovidetotheclientitsinsurancepolicyandsuppTheprovidershallensurTheprovidershalldemonstrateastructuredprovideevidenceofits:—internalandexternalcontrolproceduresand4.9IT-SecurityManagemeTheprovidershallestablishadocumentedIT-securAwrittencontractbetwshallstatetherightsandobligationsoftheprovideofsub-contractorsaswelTheclientshallproIftheclientisnotabletoprovideasecurityanalysis,thassessmenttogetherwperformanceofthecontractualdutie-assesstheprobabilityofasecuritybreachand/orthreatandtheconsequ-clarifythattheproposedcontractmeetstheriskassessment.Thesecurityanalysis/assessmeshouldincorporatetheoptimizationoftherequiredseworkforce.ThesecurityplanthedeploymentofmanagersonIfthecustomerneedsadditionalriTheprovider'sliabilityfordamagesarisinginthecourseoftheprovisionofservices,andforwhichhallbeagreedbetweentheprovifTheamountofliabilityrequestedbytheclientshallbelimited,atleastinthecaseofsassessmentandthecontTheprovidershallappointanominatedcoorganizationandoperationofthecontract.Thispersonshallhavetmanagershallbeappointed(e.g5.5CustomerTheclientshallensuretshallagreeuponthefrequencyandeactualandforthcomingofthesecurityrisksrelevanttotheprovisionofthecontrAllnecessaryequipment,systemsandvehiclesfortheprovisionofthecTheownerofequipment,systemsanthefullmaintenanceandproperoperationaluseofit.Internaaswellasmanufacturer'sbytheownertoanotherpInternational,nationalor5.7CooperationwithotherTheprovidershallcooperatewithotherrelevantparties(eauthorities,otherproviders)whenrequired.lnotsubcontractanyofitscontractedobligationswithoutthepriorwrittenconsentftheclient.Intheeventofsuchsubcontracting,theprovidershallremainfuloftheirobligationsundercoFurthersubcontractingofservicesbythesubcontractoroftheprovideractingdirectlyonbehalfoftheTheprovidershallinformtheclientinwritingaboutthepersonnel(specificallythenamesandIDsoftheinvolvedsecuritypersonnel)assignedbythesubcontractortotheassignmentpriortunderthecontractwitsubcontractor'sstaffreceivethesamepayment,insurancetheprovider'sownstaffrespectivesubcontractorfulfilstheservicescommissioneTheprovidershallnotuseanyleasedoftheclient.Iftheproviderisusingleasedworkersoragencyworkers,itistheprovider'sresponsibilitytoguaranteethatboththeworkagencyandtheirworkersmeetalltherequiremenTheprovidershallensurethattheworkagencyguaranteesreceivethesamepayment,insurance,socialsecurityandworkingconprovider'sownstaff.Theprovidershalldemonstratethatscreened,certifiedandtrainedstafftTheproviderandtheclientshouldagreeontheimplememanagementforthestaffing.Theprojectmanagementshouldincludetheidentificationofprojectrelatedrisksinstaffingandqualificationofthofthefollowingaslongasthesetermsarenotalreadystipula)identitiesofthepartiestothb)jobtitleandbriefspecificationordescriptionofthework;d)probationaryperiod,ifapplicable;f)trainingentitlementpg)hoursanddaysofwork;h)amountofpaidleavetowhichtheworkerisentitledor,i)pensionsandj)disciplinaryandgrievanceprk)termsofterminationofemployment;m)collectivelabouragreementsgoverningtheworkerAdditionallytheprovidershallincorporatetheirownprocessfortheapplicants.Thisprocessshouldincludethecheckingofthehistoryandbackground(e.gTheprocessofsecurityscreeningincludes,butisnotnecessarilylimitedto,establishingthattheindividualpossessesanddemonstratesanappropriatelevelofintegrityandisninfluenceorcoercion.IntegrityisdefinedasposTheprovidershallhaveaninsiderthreatpolicyinpl6.1.4IdentificationofstaffTheprovidershallensurethatallshallissueanidentificationvisibleway,wherenat一identificationdetailsof一identificationdetaTheproviderisexpectedtoensurethatalltheirstaffcomplywitlegislationrelatedtoidentificationofstaff.Theprovidershallhavestrictproceduresfkeepingrecords,anddisposingofbadgesandforkeepinTheproviderisexpectedtocomplywithnationalregulatiregardinguniforms.Whenonduty,securityoffishallincludeallvisibleitemsofclothing,includingpersonalprotectiveequipment(PPSecurityofficers'/securityguards'uniformsshallcshallbereadilydistinguishablefromthoseofthecivilemergencyservicTheprovidershallensureanappProvisionsofthisparagraphwillnotbeappliedtonon-unifTheprovidershallhavedocumeofpersonnel.Theprovidershalldevelopajobdescrbytheclient,theprovidershallinformoftheirpolicyforidentifyingpotentialcandidatesecPossiblerecruitmentandtrainingcriteriashallbeadapted—righttoworkinthecountry,ifrequired;-securityvetting,seeEN15602:2008,2.2.7;-securityscree-medicaldeclarationrequiredwhererelevanttothejobdescription;-necessaryinterpersonalskillsrelevanttotheactivitytobeundertak-languageskillsinthecontractualrelevantworkinglanguagTheprovidershallrequireeachcandidatesecurityodocumentcontaining—employmentandpersonalreferences;-detailsofworkandresidencepermits,ifapplicable;-statementofcriminalrecords,ifapplicable;-drivinglicensedetails,ifapplicable;一generalinformationonphysicaland/ormedicalco—possibilitiesofgeographicalmobilityshallbeconductedbyacompetentrecTheprovidershalldocumenttheresultsof-applicationformverification;-understandingofthejobanditsrequirements;-socialattitudes(e.g.equalrights,security,colleagues,superiors,customers—integrity;—informcandidateofwage,jcompany'scodeofconduct),companydetailsandapplicablenationThefileshallcontainalldocuments,e.g..2Psychometricandpsycho-technicaltestsPeer-reviewedpsychometricandpselectiontoolwhereappTrainingpolicyandmethodologyrequia)Trainingpolicy,planning,contentsandperformanceoftrainingareexpectedtob)Theprovidershallentraining)shallbereflc)Alltrainingsessionsshallbeplannedandjobassignment.thetraineehasperformedtothelevelde)Trainingshallbeperformtomeettheexpectedresultsandrequirementsofthecorrespondinglegislation(whenappliconsiblefortheassessmf—criticalinfrastructurespenvironmentmanagement,ifapplicable;Thestartupofthecontractshallbemutuallyagreeduponbytheclientandtheprincorporatesthedefinitionofaspecifiedtimeframe,responsibilitiesofbothpartiesandpointsofcontactofallprocessrelevantpersonnel.ThetimefAllrelevantdocumentation,maTheprocessshouldbedocumentedbybothparties.Theprovisionofthecontractedservicesisbaseduponthertimes,qualitiesandquantities.TheclientandtheprovidershallagreeinwritingonaconFurthermore,awrittenagreemethemaximummonthlydeploymenthobesignedoffbythecliTheprovidershallensure,bymeansofawrittendefinitionofresponsibilitiesatindividualmalevels,thatrecordsarekept,collected,checked,distributedifnecessary,transmittedtoRecordsshallprovethattherequirementsofthetaskshavebeenqualitativelyandquantitativelyfulfilled,thatprescribedtests/evaluationshavebeencarriedout,thatinitiatedmeasuresRegularcommunicationsbetween—provisionofdailyoperationalinformation;—provisionofenhancedreportsonincid-regularcommunicationonactualthreats,specialsituationsandnecess—regularcontractualandfinancialre7.4OperationalTheprovidershalldefineanob)standardoperatingproceduresincludingqualitymanagement;g)emergencypreparebemeasurablee.g.mutuallexpectationsaswellIfSLA'sareused,theprovidershallmaintain,documentandprovidethemeasurementsystemtoregularlyandperandtoimplementcorrectivemeasures,ifandwhennTheproceduresfortheterminationofthecontractshallbeorporatesthedefinitionofaspecifiedtimeframe,responsibilitiesofbothpartiesafAllrelevantdocumentation,bytheoutgoingprovider.Theprocessshouldbedocumentedbybothparties.Examplesofcriticalinf—centralnetworknodesandcontr—defenceindustrialresearch,p一powerstations(incl.hydro一pipelines,externalcompressorandpumpingstations.—foodstorage,logistic—foodchemicalandgeneticengineeri一governmentandpublicadministration(e.g.datacentres);一parliament;一courtsandprisons.—pharmaceuticalsandvaccinesresearch,production,stor—nuclearresearch,training,production,storageanddistribut—maritimeportsandterminals,maritimetraffi—inlandwaterwaysandterminals,locks—railandundergroundsystems,s
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025年植物生長調(diào)節(jié)劑合作協(xié)議書
- 2025版權(quán)轉(zhuǎn)讓協(xié)議合同
- 2025年個人借款合同英文版
- 2025標準裝修合同模板
- 2025房屋租賃合同范文匯編
- 2025年ZRO2陶瓷磨介合作協(xié)議書
- 2025年特種氯乙烯共聚物項目建議書
- 2025年板臥式電除塵器項目建議書
- 2025年植物促生菌劑合作協(xié)議書
- 2025年單晶生產(chǎn)爐合作協(xié)議書
- GA 255-2022警服長袖制式襯衣
- GB/T 5202-2008輻射防護儀器α、β和α/β(β能量大于60keV)污染測量儀與監(jiān)測儀
- GB/T 39560.4-2021電子電氣產(chǎn)品中某些物質(zhì)的測定第4部分:CV-AAS、CV-AFS、ICP-OES和ICP-MS測定聚合物、金屬和電子件中的汞
- GB/T 3452.4-2020液壓氣動用O形橡膠密封圈第4部分:抗擠壓環(huán)(擋環(huán))
- 計劃生育協(xié)會基礎(chǔ)知識課件
- 【教材解讀】語篇研讀-Sailing the oceans
- 抗腫瘤藥物過敏反應(yīng)和過敏性休克
- 排水管道非開挖預(yù)防性修復(fù)可行性研究報告
- 交通工程基礎(chǔ)習(xí)習(xí)題及參考答案
- 線路送出工程質(zhì)量創(chuàng)優(yōu)項目策劃書
- 100T汽車吊性能表
評論
0/150
提交評論