19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.202 Preparation of an <strong>IT</strong> Security Organisational<br />

<strong>Manual</strong><br />

Initiation responsibility: <strong>IT</strong> Security Management Team<br />

Implementation responsibility: Head of Organisational Section<br />

During the <strong>IT</strong> security process not only are the documents mentioned in the<br />

present safeguards produced but during the implementation phase additional<br />

rules covering either the entire organisation or particular jobs are developed.<br />

Procedural rules or instructions on actions to be taken are written, and these<br />

must be available to every employee as the basis for his actions or omissions<br />

at the workplace. <strong>The</strong>se rules must be compiled and made available in a<br />

suitable form to each target group. Whereas documentation of the <strong>IT</strong> security<br />

process is an essential tool for the <strong>IT</strong> Security Management Team, the <strong>IT</strong><br />

Security Organisational <strong>Manual</strong> serves as a set of guidelines for all staff<br />

affected by the <strong>IT</strong> security process. In practice, sections of these<br />

recommendations are used under names such as "PC Guidelines" or "<strong>IT</strong> User<br />

Guidelines". Different rules, which are geared towards the same key<br />

statements but also contain information on rights and duties which are specific<br />

to a given function, are needed by different target groups within the<br />

organisation. In this way sets of guidelines which specify tasks and<br />

responsibilities for different target groups are prepared. Such guidelines could<br />

be structured together with superordinate chapters in an <strong>IT</strong> Security<br />

Organisational <strong>Manual</strong> as shown below:<br />

<strong>IT</strong> Security Organisational <strong>Manual</strong><br />

Chapter 1 <strong>Information</strong> Security Policy of the organisation<br />

Chapter 2 <strong>IT</strong> security guidelines derived from the ISP<br />

2.1 <strong>IT</strong> systems<br />

2.2 <strong>IT</strong> applications<br />

Chapter 3 <strong>IT</strong> Security Management<br />

3.1 Organisational structure<br />

3.2 <strong>IT</strong> security-specific tasks<br />

3.3 Responsibilities for meeting security<br />

requirements<br />

3.4 Operational structure for the proper and secure<br />

use of <strong>IT</strong> facilities<br />

3.5 Strategic elements of <strong>IT</strong> security management<br />

Chapter 4 Guidelines on <strong>IT</strong> security<br />

4.1 Guidelines for <strong>IT</strong> users<br />

4.2 Guidelines for <strong>IT</strong> administrators<br />

4.3 Guidelines for technical managers<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

...<br />

4.n Rules for other responsibilities

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!