19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

5. Contingency planning and operational reliability<br />

<strong>The</strong> fax security guidelines should also cover contingency planning and failsafe<br />

fax operation. If availability is an important factor, it may be appropriate<br />

to have redundant fax servers. In this connection consideration should also be<br />

given to the question of whether conventional fax machines should be kept<br />

available for use in emergencies (see also S 6.69 Contingency planning and<br />

operational reliability of fax servers).<br />

6. Data backup<br />

<strong>The</strong> fax server should be included in the data backup policy of the<br />

organisation (see Section 3.4). In particular, the data backup policy must<br />

specify who is responsible for taking the backups and what should be backed<br />

up. <strong>The</strong> items subject to backup can include software, configuration data,<br />

saved or archived fax data and even log files. <strong>The</strong> intervals at which backups<br />

are taken and the number of generations which must be kept should also be<br />

specified, as must the person responsible for checking any log files generated<br />

during data backup. Finally, the fact that a backup has been performed or that<br />

the log files have been evaluated should be documented.<br />

7. Training<br />

In addition, the fax security guidelines should be supplemented by an<br />

organisation-wide training concept. As a first step, the staff responsible for<br />

administering the <strong>IT</strong> system and the fax server application must be given<br />

appropriate training. <strong>The</strong> users must then be made aware of the dangers which<br />

apply where a fax server is used in comparison with a conventional fax<br />

system.<br />

Additional controls:<br />

- Are there any security guidelines for the use of faxes?<br />

- Are the security guidelines for the use of faxes regularly updated in line<br />

with changes to the environment in which they are used?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!