19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> in the Area of Infrastructure<br />

_________________________________________________________________________________________<br />

4.3.1 Offices<br />

Description<br />

An office is a room where one or several staff members are<br />

present in order to fulfil their duties, possibly including <strong>IT</strong>supported<br />

tasks. Such duties may cover a wide variety of<br />

tasks: production of documents, processing of files and lists,<br />

conferences and telephone calls, reading of records and other<br />

documents, etc.<br />

However, if an office is used primarily for keeping archives<br />

of data media, reference is also to be made to Chapter 4.3.3, "Data Media Archives". If a server (LAN;<br />

PBX, or the like) is installed in an office, the safeguards in Chapter 4.3.2 (server room) should also be<br />

observed.<br />

Threat Scenario<br />

<strong>The</strong> following typical threats (T) are assumed as regards <strong>IT</strong> baseline protection of an office:<br />

Organisational Shortcomings:<br />

- T 2.1 Lack of, or insufficient, rules<br />

- T 2.6 Unauthorised admission to rooms requiring protection<br />

- T 2.14 Impairment of <strong>IT</strong> usage on account of adverse working conditions<br />

Human Error:<br />

- T 3.6 Hazards posed by cleaning staff or outside staff<br />

Deliberate Acts:<br />

- T 5.1 Manipulation or destruction of <strong>IT</strong> equipment or accessories<br />

- T 5.2 Manipulation of data or software<br />

- T 5.4 <strong>The</strong>ft<br />

- T 5.5 Vandalism<br />

Recommended Countermeasures (S)<br />

To implement <strong>IT</strong> baseline protection, selection of the required packages of safeguards ("modules"), as<br />

described in Sections 2.3 and 2.4, is recommended.<br />

In the following, the safeguard package for "Office" is set out:<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!