19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

A structured implementation plan is essential if the <strong>IT</strong> security measures<br />

identified are to be properly implemented. <strong>The</strong> <strong>IT</strong> Security Management Team<br />

is responsible for drawing up the implementation plan. Depending on their<br />

type and scope, the individual safeguards are implemented either by the user<br />

of the <strong>IT</strong> system concerned or a responsible <strong>IT</strong> adviser. Implementation of the<br />

safeguards must be supported by the <strong>IT</strong> Security Management Team. In<br />

particular, every employee must know in advance to whom he should turn in<br />

the event of any problems occurring.<br />

<strong>The</strong> following should be documented in an implementation plan:<br />

- name of the person responsible for implementation of a safeguard,<br />

- priority of the safeguard to be implemented,<br />

- statement of the time by which the safeguard must have been implemented,<br />

- person to whom implementation of the safeguard must be reported, once<br />

complete,<br />

- provision of resources (manpower, resource requirements, space<br />

requirements, costs).<br />

It is a good idea to pave the way for or accompany implementation of the<br />

safeguards by providing appropriate training for the <strong>IT</strong> users and raising their<br />

security awareness (see safeguards S 2.197 Drawing up a training concept for<br />

<strong>IT</strong> security and M 2.198 Making staff aware of <strong>IT</strong> security issues).<br />

Additional controls:<br />

- Do the recommendations regarding security measures contained in the <strong>IT</strong><br />

security concept define clearly who is responsible for initiation and<br />

implementation?<br />

- Is there an implementation plan?<br />

- Are reviews performed and documented?<br />

- Is Management informed of the results?<br />

- Are the rules for implementation of <strong>IT</strong> security measures documented?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Implementation phase

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!