19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

<strong>The</strong> passwords of the three application-specific IDs should only be known to<br />

the administrator responsible for maintaining and updating the database<br />

objects of the respective applications. In contrast, the password of the database<br />

ID used to manage the central database objects is not known to any of these<br />

administrators; instead it is placed in charge of a further administrator. This<br />

prevents an application-specific administrator from performing modifications<br />

to central database objects which might impair the functionality of the other<br />

applications.<br />

Additional controls:<br />

- What measures have been taken to ensure that actions by database<br />

administrators do not result in inconsistencies?<br />

- Have all database administrators received an additional ID with restricted<br />

rights?<br />

- Are the additional user IDs employed by default?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!