19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

- Zone model<br />

<strong>The</strong> BSI has developed a zone model which takes account of the<br />

propagation conditions of compromising emanations in relation to<br />

particular conditions in certain buildings and on certain sites. <strong>The</strong><br />

attenuation of the radiation on its way from the originating <strong>IT</strong> device to the<br />

potential receiver is determined by metrological means. Depending on the<br />

circumstances at the place of use, it may be possible to use devices to<br />

which only minor interference suppression measures have to be applied, or<br />

no measures at all.<br />

- Emanation suppression at source<br />

Emanation suppression at source is particularly valuable when developing<br />

new <strong>IT</strong> products. This involves suppressing the compromising emanations<br />

at their place of origin within the device, or modifying them in such a way<br />

that they can no longer be utilised. This method might also allow the use of<br />

low-cost plastic housings, for example, with a negligible impact on the<br />

batch production price.<br />

- Set of radiation criteria<br />

<strong>The</strong> purpose of a detailed set of radiation criteria is the graduated testing of<br />

<strong>IT</strong> devices and systems <strong>The</strong> rationale behind this concept is to adapt the<br />

scope of the protection measures as closely as possible to the threat<br />

situation assumed to exist by the user, so as in that way to achieve an<br />

optimum of emission security with the minimum of cost.<br />

- Accelerated measurement procedures<br />

Devising accelerated measurement procedures and manipulation test<br />

procedures enables emission security to be ensured at as low a cost as<br />

possible after maintenance, repair or potentially unauthorised access.<br />

- Use of low-emission or emission-protected equipment<br />

Manufacturers of PC monitors often make use of the term "low-emission"<br />

according to MPR II, TCO or SSI in their advertising material. However,<br />

these guidelines only take account of the possible damaging effects to<br />

health of radiation from equipment. <strong>The</strong> measuring techniques and limit<br />

values for radiation are therefore entirely unsuited to producing evidence of<br />

compromising emanations and do not allow any assessment to be made of<br />

security against the unauthorised interception of data via compromising<br />

emanations.<br />

In addition, special emission-protected <strong>IT</strong> systems are also offered by some<br />

suppliers. <strong>The</strong>re are numerous levels of emission protection provided in<br />

this field. In order to allow the classification of <strong>IT</strong> systems with high<br />

protection requirements, in particular, the BSI developed a set of criteria<br />

known as TEMPEST (Temporary Emission and Spurious Transmission)<br />

criteria. Whether a manufacturer includes emission protected devices<br />

conforming to the TEMPEST criteria in its range of products should be<br />

clarified by asking the manufacturer or the BSI, or by checking the official<br />

product overview in BSI 7206. <strong>The</strong> statement that a device has been<br />

awarded TEMPEST approval should always be accompanied by indication<br />

of the level of approval.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!