19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.193 Establishment of a suitable organisational<br />

structure for <strong>IT</strong> security<br />

Initiation responsibility: Agency/company management<br />

Implementation responsibility: Agency/company management; <strong>IT</strong> Security<br />

Management Team<br />

<strong>IT</strong> security is of particular importance to all <strong>IT</strong> projects, all <strong>IT</strong> systems and all<br />

<strong>IT</strong> users in an organisation. <strong>The</strong> aspired-to level of <strong>IT</strong> security can only be<br />

achieved if the <strong>IT</strong> security policy is implemented throughout the<br />

agency/company. This organisation-wide character of the <strong>IT</strong> security process<br />

makes it necessary to specify particular roles within the agency/company.<br />

Appropriate tasks must be assigned to each role, and these roles must be<br />

served by staff with the appropriate skills. This is the only way to ensure that<br />

all important aspects are taken into consideration and that all tasks are carried<br />

out efficiently and effectively.<br />

<strong>IT</strong> security management depends on the size, nature and structure of the<br />

organisation concerned. <strong>The</strong> following central roles should be defined in every<br />

case:<br />

- the <strong>IT</strong> Security Officer, who builds up his own specialist expertise in <strong>IT</strong><br />

security and is responsible for all <strong>IT</strong> security issues in the organisation; and<br />

- the <strong>IT</strong> Security Management Team, which in larger organisations<br />

regulates all organisation-wide matters of <strong>IT</strong> security and develops plans,<br />

procedures and guidelines.<br />

To guarantee direct access to Management, these should both be organised as<br />

special staff functions.<br />

Basic rule:<br />

<strong>The</strong> most important considerations in the definition of roles in <strong>IT</strong> security<br />

management are:<br />

- overall responsibility for the proper and reliable fulfilment of tasks (and<br />

thus <strong>IT</strong> security) rests with Management<br />

- responsibility for <strong>IT</strong> security at the various workstations should be<br />

delegated in precisely the same manner as responsibility for the original<br />

task.<br />

Organisational structure of <strong>IT</strong> security management<br />

Depending on the size of the organisation, there are three possible ways of<br />

structuring <strong>IT</strong> security management. <strong>The</strong>se are illustrated in the diagrams<br />

below. <strong>The</strong> first diagram shows the organisational structure for <strong>IT</strong> security<br />

management in a large organisation. <strong>The</strong> second diagram shows the<br />

organisational structure in a medium-sized organisation in which the roles of<br />

the <strong>IT</strong> Security Management Team and <strong>IT</strong> Security Officer are merged. <strong>The</strong><br />

third diagram presents an organisational structure for <strong>IT</strong> security management<br />

in a small organisation, where all the tasks are performed by the <strong>IT</strong> Security<br />

Officer.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Roles and tasks<br />

Central roles<br />

Tailored to the size of<br />

the organisation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!