19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.203 Establishment of a pool of information on <strong>IT</strong><br />

security<br />

Initiation responsibility: <strong>IT</strong> Security Management Team<br />

Implementation responsibility: Management, <strong>IT</strong> Procedures Officer<br />

Now that <strong>IT</strong> is used widely, traditional work routines are undergoing a<br />

transformation which requires not only adaptation of organisational structures<br />

but also a change in the skills and competence of staff.<br />

It is therefore not sufficient just to compile the necessary rules together from<br />

an objective point of view, but active steps must also be taken using didactic<br />

techniques to change the skills and competence of staff. <strong>IT</strong> security awareness<br />

promotion and training programmes can assist with this, but at the same time<br />

the opportunities presented by the new technologies should also be used to<br />

make the necessary information available at the workplace in a contextspecific<br />

manner. With this objective in mind, the BSI has created an <strong>IT</strong><br />

Security information desk ("Info Desk") which makes general information,<br />

key security policy statements and specific guidelines available online over a<br />

graphical user interface in the Intranet of an organisation.<br />

A demo version of this "Info Desk" will be found on the CD-ROM for the<br />

manual (see appendix on Additional Aids, German version only). <strong>The</strong><br />

application is designed so that it can be adapted to the particular circumstances<br />

of different agencies or companies. <strong>The</strong> BSI offers support with setting this up<br />

through a set of correspondence course lessons. Beginning with modification<br />

of the user interface to reflect the organisation's corporate identity, over a<br />

cycle of 18 months the organisation’s own information security policy and<br />

specific <strong>IT</strong> security concepts are integrated into the Info Desk. <strong>The</strong><br />

correspondence course lessons are sent out by e-mail, which is also used for<br />

experience sharing. Further information may be obtained from<br />

schulung@bsi.de.<br />

Additional controls:<br />

- Has a pool of information on <strong>IT</strong> security been set up on the Intranet?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!