19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.32 Physical deletion of data media before and<br />

after usage<br />

Initiation responsibility: <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong> Procedures Officer<br />

In addition to the instructions on deletion and destruction of data carriers<br />

mentioned in measure S 2.167 Secure deletion of data media, the following<br />

items must be observed for the exchange of data media:<br />

Magnetic data media intended for exchange should be physically erased<br />

before being written with the information to be transmitted. This is to prevent<br />

the transmission of residual data which the recipient has no authority to<br />

receive.<br />

Physical erasure sufficient for medium-level protection can be achieved by<br />

overwriting the entire data medium or at least the used sectors with a certain<br />

pattern. Another alternative is to format the data medium, if this cannot be<br />

undone again (e.g. DOS version 5.0: format/u). Certain commercially<br />

available products even allow the physical erasure of individual files.<br />

As a rule, transmitted data also requires protection by the recipient. Once the<br />

data has been received, the data medium should again be physically erased.<br />

Optical data media (in this case: WORM) should not be used for data<br />

exchange if they bear other information which is not meant for the recipient<br />

and cannot be erased.<br />

Additional controls:<br />

- Are the persons responsible for the exchange of data media familiar with<br />

the process of physical erasure?<br />

- Do these employees have access to suitable programs for physical erasure?<br />

- Are the recipients of confidential information notified about its data<br />

protection requirements?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!