19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.200 Preparation of management reports on <strong>IT</strong><br />

security<br />

Initiation responsibility: <strong>IT</strong> Security Management Team<br />

Implementation responsibility: <strong>IT</strong> Security Management Team<br />

<strong>The</strong> tasks of the <strong>IT</strong> Security Management Team include supporting<br />

Management in the execution of its overall responsibility for <strong>IT</strong> security. A<br />

major tool for use here is a report on the current <strong>IT</strong> security situation. <strong>The</strong> aim<br />

of such a paper should be to provide Management with the information it<br />

needs to make the decisions it has to make.<br />

A basic distinction should be made here between two different forms of<br />

management report.<br />

1. Regular management reports<br />

<strong>The</strong> effect of submitting "<strong>IT</strong> security" management reports as regularly as<br />

possible is to ensure that this subject is kept fresh in the minds of<br />

Management. In this way, management reports serve to some extent as a tool<br />

for raising the <strong>IT</strong> security awareness of those in positions of overall<br />

responsibility. For this reason, such a report should be prepared at least once a<br />

year.<br />

<strong>The</strong> "<strong>IT</strong> Security" management report should cover the following areas:<br />

- the extent to which the requirements specified in the organisation’s <strong>IT</strong><br />

security concept have already been addressed;<br />

- areas in which security weaknesses, and hence residual risks, remain;<br />

- the extent to which the <strong>IT</strong> security level matches the organisation’s security<br />

requirements and its exposure to threats;<br />

- whether the activities performed in pursuit of <strong>IT</strong> security have been a<br />

success;<br />

- whether the <strong>IT</strong> security measures have proved a suitable means of<br />

achieving the <strong>IT</strong> security objectives.<br />

<strong>The</strong> report should also consider any further developments expected in<br />

organisation-wide <strong>IT</strong> security.<br />

2. Event-triggered management reports<br />

As well as regular management reports on <strong>IT</strong> security, it may also be<br />

necessary to prepare event-triggered management reports if <strong>IT</strong> security<br />

problems occur unexpectedly or because of risks associated with new<br />

technical developments. <strong>The</strong>se are needed above all when it turns out that<br />

these problems cannot be resolved "at shopfloor level" because, for example,<br />

extra material resources are needed over and above those approved or<br />

extensive staff-related rules need to be modified or drawn up. <strong>IT</strong> security<br />

incidents such as global computer virus attacks (e.g. Melissa or Loveletter emails)<br />

are constantly hitting the mass media headlines. It has proved<br />

appropriate to also prepare management reports in these instances in order to<br />

show the extent to which this organisation has been affected by these security<br />

incidents.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!