19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.196 Implementation of the <strong>IT</strong> security concept in<br />

accordance with an implementation plan<br />

Initiation responsibility: <strong>IT</strong> Security Management Team<br />

Implementation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Team<br />

Once the <strong>IT</strong> security concept has been prepared, it must be put into practice. A<br />

distinction must be made here between a conceptual design phase and the<br />

actual implementation.<br />

During the conceptual design phase the basic suitability of every safeguard<br />

recommended for use on existing <strong>IT</strong> assets must be checked and the<br />

recommendations regarding safeguards must be fleshed out so that they can be<br />

used to generate organisation-specific rules. <strong>The</strong> <strong>IT</strong> security concept must<br />

therefore specify not only initiation responsibilities but also responsibilities<br />

for the implementation of the safeguards.<br />

Initiation responsibility covers performing the groundwork necessary for<br />

effective implementation and also specification of objectives. This<br />

presupposes that the responsible person has the necessary resources available<br />

to him by right.<br />

Initiation generally includes:<br />

- specification of objectives together with a description of the expected<br />

planned state or the expected behaviour,<br />

- the allocation of resources (working time, financial resources) and<br />

- a realistic time target.<br />

Implementation responsibility may be broken down into the formulation of<br />

rules, creation of aids, design of processes and the provision of information to<br />

the staff concerned. Strictly speaking, implementation terminates when a<br />

safeguard is applied in practice. Responsibility for implementation and<br />

application can be divided between several people. Implementation includes:<br />

- the design of technical or organisational sequences of operations at the<br />

workplace,<br />

- modification of task descriptions,<br />

- the provision of instructions and information for security awareness<br />

promotion measures and training courses, and<br />

- the provision of aids and implementation of the safeguard at the workplace.<br />

Depending on the range and type of safeguard (technical or organisational), it<br />

may not always be possible to draw a clear-cut line between initiation and<br />

implementation. <strong>The</strong> implementation of safeguards frequently requires cooperation<br />

between several different positions. Thus, for example, persons with<br />

system responsibility are needed to procure, install and maintain technical<br />

facilities - for example, in the establishment of security interfaces - while on<br />

the other hand persons with organisational responsibility are needed to create<br />

and document the appropriate rules regarding their use.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Conceptual design<br />

phase<br />

Initiation<br />

Implementation<br />

Co-operation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!