19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

Basic:<br />

- Confidentiality of information is not required.<br />

- Errors can be tolerated, provided they do not render the fulfilment of<br />

tasks impossible.<br />

- Long-term failure should be avoided, moderate periods of downtime<br />

are, however, acceptable.<br />

Summary: damage causes only minor disruption within the<br />

agency/company.<br />

Achievement and maintenance of a given degree of <strong>IT</strong> security requires a<br />

corresponding effort. <strong>The</strong>refore when specifying the <strong>IT</strong> security level for a<br />

given organisation, care should be taken to ensure that the costs associated<br />

with attaining this level are appropriate to the circumstances and are also<br />

affordable.<br />

<strong>The</strong> diagram below is intended to illustrate the relationship between<br />

financial outlay and the aspired-to level of <strong>IT</strong> security. <strong>The</strong> diagram<br />

conveys an idea of the personnel, time and monetary resources required to<br />

achieve the <strong>IT</strong> security level. As a point of orientation, the financial outlay<br />

in private industry for <strong>IT</strong> security per year is an average of 5% of the total<br />

<strong>IT</strong> investment.<br />

niedrig<br />

mittel<br />

Text zum Bild:<br />

Security<br />

Basic - Moderate -<br />

High - Maximum<br />

<strong>Baseline</strong> protection<br />

[Grundschutz]<br />

Enhanced [erhöht]<br />

hoch<br />

maximal<br />

Grund schutz erhöht maximal<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Cost-effectiveness<br />

Cost-benefit trade-off

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!