19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Personnel Remarks<br />

____________________________________________________________________ .........................................<br />

S 3.14 Briefing personnel on correct procedures of<br />

exchanging data media<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong> Security Management<br />

Inadequate briefing and instruction of employees often causes restrictions on<br />

the forwarding of information to be ignored or neglected. Consequently, the<br />

persons involved in the exchange of data media should on all accounts be<br />

informed of specifications as to which communications partners should<br />

receive which data when (S 2.42 Determination of potential communications<br />

partners). Furthermore, the fundamental steps comprising the exchange of<br />

data media are to be defined (as work regulations, if required) and adherence<br />

to them made obligatory for employees.<br />

Employees involved in the exchange of data media are also to be familiarised<br />

with threats which could materialise before, during or after the transport of<br />

data media, as well as the safeguards required to avert these threats.<br />

If certain <strong>IT</strong>-supported procedures are used to protect data while it is being<br />

exchanged (e.g. encryption or checksums), employees involved in the<br />

exchange of data must be briefed adequately on handling these procedures.<br />

Additional controls:<br />

- Are all employees authorised for communication aware of the related<br />

regulations?<br />

- Are employees familiar with encryption or checksum procedures being<br />

implemented?<br />

- Are the persons responsible for the exchange of data media sufficiently<br />

aware of the potential threats involved?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!