19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Personnel Remarks<br />

____________________________________________________________________ .........................................<br />

S 3.1 Well-regulated familiarisation/training of new<br />

staff with their work<br />

Initiation responsibility: Agency/company management; Head of<br />

Personnel Section<br />

Implementation responsibility: Personnel Section; superiors<br />

New staff must be made aware of the in-house <strong>IT</strong>-related regulations,<br />

practices and procedures. Without adequate training to the job, they do not<br />

know who to turn to as regards <strong>IT</strong> security issues; they do not know which <strong>IT</strong><br />

safeguards have to be implemented and what <strong>IT</strong> security policy is pursued by<br />

the agency/company. This can result in disruption and damage affecting <strong>IT</strong><br />

operations. Consequently, great importance must be attached to the wellregulated<br />

familiarisation of new staff with their work environment.<br />

Familiarisation / training should, as a minimum, include the following:<br />

- planning of the required training activities; training schemes specifically<br />

designed for the respective workplaces (cf. also S 3.4 Training before<br />

actual use of a programme and<br />

S 3.5 Education on <strong>IT</strong> security measures);<br />

- introduction of all persons acting as points of contact, particularly for <strong>IT</strong><br />

security questions;<br />

- explanation of the in-house regulations and rules as regards <strong>IT</strong> security.<br />

For the purpose of training staff for their jobs, it is useful to have an interoffice<br />

slip or a checklist showing the various activities and the familiarisation<br />

level attained.<br />

Additional controls:<br />

- What provisions have been made for training new staff to their jobs?<br />

- How much time are new staff members allowed for training to the job?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!