| ENS 1 Security Policy Documents | ||||
| ENS 1.1 Security Policy High-level Documents | ||||
| ENS 1.1.1 Declaratory Document | ||||
| ENS 1.1.2 Document with the Identification of Objectives, Principles, Tools, Processes, Rules and Responsibilities | ||||
| ENS 1.2 Partial Policies / Concepts | ||||
| ENS 1.2.1 Operational Security | ||||
| ENS 1.2.2 Physical Security | ||||
| ENS 1.2.3 Information And Communication Systems Security | ||||
| ENS 1.2.4 Work Safety And Health Protection | ||||
| ENS 1.2.5 Fire Protection | ||||
| ENS 1.2.6 Environmental Security | ||||
| ENS 1.2.7 National Security / Economic Mobilization | ||||
| ENS 1.2.8 Civil Protection / Emergency | ||||
| ENS 1.2.9 Protection of Classified Information | ||||
| ENS 1.2.10 Trade Secret Protection | ||||
| ENS 1.2.11 Personal Data Protection | ||||
| ENS 1.2.12 Personal Security | ||||
| ENS 1.2.13 Administrative Security | ||||
| ENS 1.2.14 Financial Security / Risk Management | ||||
| ENS 1.2.15 Protection of Goodwill | ||||
| ENS 1.2.16 Nuclear and Radiation Protection | ||||
| ENS 1.2.17 Technical and Technological Security | ||||
| ENS 1.2.18 Top Management Security | ||||
| ENS 1.2.19 Business Continuity Planning (BCP) | ||||
| ENS 1.3 Managing Security Documentation | ||||
| ENS 1.3.1 Directives | ||||
| ENS 1.3.1.1 Personal Data Protection Directive | ||||
| ENS 1.3.1.2 Directive for Protection of Classified Information | ||||
| ENS 1.3.1.3 Trade Secret Protection Directive | ||||
| ENS 1.3.1.4 Protection and Defence Basic Directive | ||||
| ENS 1.3.1.5 ICT Security Basic Directive | ||||
| ENS 1.3.1.6 Directive for the Use of Personal Computers | ||||
| ENS 1.3.1.7 Security Directives according to the ISO 9000 System | ||||
| ENS 1.3.1.8 Security Profiles for Physical Security (Security Standard) | ||||
| ENS 1.3.1.9 Security Profiles for Information System (Security Standard) | ||||
| ENS 1.3.2 Top Management’s Directives and Orders | ||||
| ENS 1.4 Operational Security Documentation | ||||
| ENS 1.4.1 Security Handbook in Accordance with STN ISO/IEC 17799 | ||||
| ENS 1.4.2 Guidelines | ||||
| ENS 1.4.2.1 Protection of Classified Information Area | ||||
| ENS 1.4.2.2 Personal Data Protection Area | ||||
| ENS 1.4.2.3 Trade Secret Protection Area | ||||
| ENS 1.4.2.4 Information Systems Operation | ||||
| ENS 1.5 Security Management System | ||||
| ENS 1.5.1 Organization Security Management System (according to ENS 1.2.) | ||||
| ENS 1.5.2 Information Security Management System | ||||
| ENS 1.5.3 Protection of Classified Information | ||||
| ENS 1.5.4 Defence and Protection | ||||
| ENS 1.6 Security Plans | ||||
| ENS 1.6.1 Plans for Organization (according to ENS 1.2.) | ||||
| ENS 1.6.2 Plans for ICT Area | ||||
| ENS 1.7 Security Report | ||||
| ENS 1.7.1 Security Annual Report | ||||
| ENS 1.7.2 Annual Report of ICT Area | ||||
| ENS 1.8 Organization Security Committee Statute | ||||
| ENS 2 Analysis, Assessments and Audits | ||||
| ENS 2.1 Security Analysis for Organizations / Institution | ||||
| ENS 2.1.1 Security Analysis of the Organization | ||||
| ENS 2.1.2 Analysis of ICT Security Current State | ||||
| ENS 2.1.3 Security Analysis of the Specific Information System | ||||
| ENS 2.1.4 Current State Analysis of Physical Building Security | ||||
| ENS 2.1.5 Assessment of the Managing and Operational Security Documentation (according to STN ISO/IEC 17799) | ||||
| ENS 2.1.6 Assessment of the Personal Data Protection | ||||
| ENS 2.1.7 Assessment of the Trade Secret Protection | ||||
| ENS 2.1.8 Risk Assessment of Bank Information System (according to guideline - NBS No. 7/2004) | ||||
| ENS 2.1.9 Statement of Applicability (according to STN ISO/IEC 17799) | ||||
| ENS 2.2 Risk Analysis | ||||
| ENS 2.2.1 Risk Analysis of the Organization | ||||
| ENS 2.2.2 ICT Risk Analysis | ||||
| ENS 2.2.3 Risk Analysis of Technological Information Systems | ||||
| ENS 2.2.4 Risk Analysis of Specific Information System | ||||
| ENS 2.2.5 Physical Security Analysis | ||||
| ENS 2.3 Audits | ||||
| ENS 2.3.1 Information Security Audit | ||||
| ENS 2.3.2 Personal Data Protection Audit | ||||
| ENS 2.3.3 IS Auditing in accordance with SOX requirements | ||||
| ENS 3 Security Projects | ||||
| ENS 3.1 Personal data (according to the Act No. 428/2002 Coll.) | ||||
| ENS 3.1.1 Security Project Objectives | ||||
| ENS 3.1.2 Analysis of Information System Security | ||||
| ENS 3.1.3 Security Guidelines | ||||
| ENS 3.2 Classified Information | ||||
| ENS 3.2.1 Protection of Technical Devices (Security Project) | ||||
| ENS 3.2.2 Preparation of Technical Devices for Certification | ||||
| ENS 3.2.3 Security Documentation for Protected Premises | ||||
| ENS 3.2.4 Security Project of Entrepreneur | ||||
| ENS 3.3 Trade Secret | ||||
| ENS 3.3.1 Trade Secret Protection Analysis | ||||
| ENS 3.3.2 Trade Secret Classification Structure | ||||
| ENS 3.3.3 Security Standard | ||||
| ENS 3.3.4 Security Directive | ||||
| ENS 3.3.5 Guidelines (work documentation) | ||||
| ENS 4 Consultations | ||||
| ENS 4.1 Background Materials Preparation for Senior Management | ||||
| ENS 4.1.1 Background Materials Preparation for General Director Meeting | ||||
| ENS 4.1.2 Background Materials Preparation for Board of Directors | ||||
| ENS 4.1.3 Background Materials Preparation for Security Committee | ||||
| ENS 4.1.4 Background Materials Preparation for Exceptional Reports (security incident, audit findings, new legislative) | ||||
| ENS 4.2 Creation of Security Plans and Reports | ||||
| ENS 4.2.1 Organization Security Plan Structure | ||||
| ENS 4.2.2 Assessment of Organization’s Plans | ||||
| ENS 4.2.3 Preparation of Background Materials for Exceptional Reports (security incident, audit findings, new legislative) | ||||
| ENS 4.3 Industrial Security / Protection of Classified Information | ||||
| ENS 4.3.1 Security Project of Entrepreneur Preparation | ||||
| ENS 4.3.2 Preparation of Background Materials for Security Enquiry | ||||
| ENS 4.3.3 Protection of Classified Information Management | ||||
| ENS 4.3.4 Securing of Protected Premises | ||||
| ENS 4.3.5 Personal and Administration Security Execution | ||||
| ENS 4.4 Personal Data Protection | ||||
| ENS 4.4.1 Influence of the Act No. 428/2002 Coll. on the Organization | ||||
| ENS 4.4.2 Essential Changes to Internal Acts | ||||
| ENS 4.4.3 Personal Data Protection Management | ||||
| ENS 4.5 Advanced (special) security requirements fulfilment | ||||
| ENS 4.5.1 SOX requirements fulfilment | ||||
| ENS 4.5.2 SDLC (system development live cycle) Area | ||||
| ENS 4.6 To Unspecified Security Question in the Range of ENS 1.2. | ||||
| ENS 5 Training as a Part of Project Realization | ||||
| ENS 5.1 Protection of Classified Information | ||||
| ENS 5.2 Trade Secret Protection | ||||
| ENS 5.3 Personal Data Protection | ||||
| ENS 5.4 Top Management Security | ||||
| ENS 6 Other Activities in the Security Area in Accordance to Customer Requests | ||||