19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- <strong>The</strong> administrators must have sufficient time not only to operate the RAS<br />

systems but also to seek information on current security weaknesses and to<br />

learn how to use any new components.<br />

- Existing rules regarding the separation of roles (e.g. administrator and<br />

internal auditor) should be transferred to the administration of the RAS<br />

system.<br />

- Finally the requirements regarding the availability of RAS systems must be<br />

specified. Moreover, if necessary contingency solutions which can be used<br />

as an alternative in the event of failure of a RAS system should be<br />

provided.<br />

<strong>The</strong> RAS requirements analysis and design will by its nature throw up specific<br />

requirements for the hardware and software components which should be<br />

used. <strong>The</strong>se should be refined and made specific for procurement purposes, as<br />

described in safeguard S 2.186 Selection of a suitable RAS product.<br />

Additional controls:<br />

- Does a security concept governing the use of RAS exist?<br />

- Are there any security guidelines covering RAS usage to which the users<br />

can orient themselves?<br />

- Is there an authorisation concept for remote access?<br />

- Are the safeguards contained in the RAS security concept regularly<br />

checked to ensure that they have been correctly implemented?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Availability requirements

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!