19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- Can maximum response times for problem resolution be<br />

defined in the maintenance contract?<br />

- Does the vendor offer a competent technical customer service<br />

(call centre, hotline etc.) which can provide immediate<br />

assistance in the event of problems?<br />

1.3 Reliability / operational reliability<br />

- How reliable and fail-safe is the product?<br />

- Does the vendor offer high availability solutions?<br />

- Is it possible to use the product in continuous operations?<br />

1.4 User-friendliness<br />

- Is the product simple to install, configure and use? Does the<br />

product meet the relevant ergonomic regulations?<br />

- Is the user interface, especially that of the RAS client,<br />

designed so that even inexperienced users can work with it<br />

without having to accept reduced security (e.g. through the<br />

provision of context-sensitive help, on-line documentation,<br />

step-by-step guidance with comprehensible explanations,<br />

"wizards", detailed error messages)?<br />

- Is it possible to configure use of the RAS client in such a way<br />

that as far as possible users do not have to bother with<br />

technical details? Is security still guaranteed if this is the case?<br />

1.5 Costs<br />

- How much do the hardware and software cost to purchase?<br />

- What are the expected ongoing costs of the hardware and<br />

software (maintenance, operation, support)?<br />

- What are the expected ongoing staff costs (RAS administrator<br />

/ internal auditor)?<br />

- Do additional software or hardware components need to be<br />

purchased (e.g. dial-in server, server for additional<br />

-<br />

authentication services)?<br />

How much will it cost to train the staff and administrators<br />

who will be using the RAS product?<br />

2. Operation<br />

2.1 Installation and initial operation<br />

- Do the RAS system’s default settings ensure that the RAS will<br />

be securely configured after installation?<br />

- Can installation of the RAS client software be automated with<br />

predefined configuration parameters?<br />

- Is it feasible for less technically-minded staff to install the<br />

RAS client software?<br />

- Can important configuration parameters be protected against<br />

modification by users?<br />

- Does the product work with commonly available hardware<br />

and software (operating systems, plug-in cards, drivers)?<br />

- Is the RAS system compatible with commonly used system<br />

management systems?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!