Khi phát triển một đánh giá rủi ro kinh doanh, bạn phải đi vào xem xét nhiều kịch bản khác nhau có thể ảnh hưởng đến kinh doanh, tất nhiên, rủi ro khácđảm bảo phù hợp với" (i) các yêu cầu của Tiểu chương này, "(ii) chính sách và thủ tục có thể được theo quy định của Giám đốc, | 386 Chapter 21 Evaluating the Certification Package for Accreditation Table continued Examples of Compliance Checks for Operational Controls Description of Audit Pass Source of ID No. Check on Operations Fail NA Comments Requirement O-41 Has a Configuration Management Plan been developed O-42 Are baselines defined in the Configuration Management Plan O-43 Have adequate baselines been established in the Configuration Management Plan O-44 Has the configuration management system been adequately described O-45 Are roles and responsibilities defined in the Configuration Management Plan O-46 Has the change management process been adequately described in the Configuration Management Plan O-47 Is the change management process acceptable O-48 Is a copy of the Change Management Form depicted in the Configuration Management Plan Continued Evaluating the Certification Package for Accreditation Chapter 21 387 Table continued Examples of Compliance Checks for Operational Controls Description of Audit Pass Source of ID No. Check on Operations Fail NAComments Requirement O-49 Are adequate parameters indicated on the Change Management Form O-50 Are emergency change management procedures documented in the Configuration Management Plan O-51 Are the emergency change management procedures adequate O-52 Are configuration management terms defined in the Configuration Management Plan O-53 Do all documents archived in the configuration management system have a unique ID number O-54 Are appropriate background investigations performed on staff before access is given to systems and applications Continued 388 Chapter 21 Evaluating the Certification Package for Accreditation Table continued Examples of Compliance Checks for Operational Controls Description of Audit Pass Source of ID No. Check on Operations Fail NA Comments Requirement O-55 Are appropriate background investigations performed on contractors before they are granted access to systems