19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Personnel Remarks<br />

____________________________________________________________________ .........................................<br />

S 3.6 Regulated procedure as regards termination<br />

of employment<br />

Initiation responsibility: Head of Personnel Section; superiors; <strong>IT</strong><br />

Security Management<br />

Implementation responsibility: Personnel Section; superiors<br />

In case of termination of employment, the following should be observed:<br />

- Before termination of employment, the designated successor of the<br />

individual concerned must be given a briefing on the tasks.<br />

- All documents, issued keys, borrowed <strong>IT</strong> equipment (e.g. laptops, data<br />

media, documentation) must be recovered. In particular, agency/company<br />

passes must be collected in from the staff member terminating his/her<br />

employment.<br />

- All entry and access rights held by the departing staff member must be<br />

revoked or deleted. This includes external access authorisations over data<br />

communications equipment. If, in exceptional cases, several persons shared<br />

one access right to an <strong>IT</strong> system (e.g. by using a common password), the<br />

access rights must be altered upon termination of employment by one of<br />

those individuals.<br />

- Before the person leaves, it should be explained to him explicitly one more<br />

time that all confidentiality agreements remain in force and that no<br />

information obtained in the course of his work may be disclosed.<br />

- If the departing staff member was assigned any functions under a<br />

contingency plan, the plan must be updated.<br />

- All persons entrusted with security tasks, especially entrance control staff,<br />

must be informed of the departure of the person.<br />

- Individuals no longer employed with the agency/company must be denied<br />

uncontrolled access to the agency/company premises, especially entry into<br />

rooms housing <strong>IT</strong> systems.<br />

- Optionally, all entry and access rights relating to <strong>IT</strong> systems may be<br />

revoked even for the period from giving notice of termination to actual<br />

termination of employment, and in addition, the individual concerned may<br />

be prohibited from entering rooms requiring protection.<br />

A useful way of doing this is to use inter-office slips which lay down the<br />

various steps to be taken by a staff member before leaving the<br />

agency/company.<br />

Additional controls:<br />

- Are regular provisions applied in case of termination of employment?<br />

- Are the relevant bodies informed of the termination of service by a staff<br />

member?<br />

- What steps are taken to ensure that all entry and access rights of a staff<br />

member terminating his/her employment are revoked and deleted?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!