19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.110 Secure installation of the RAS system<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Team<br />

Implementation responsibility: Administrators<br />

After the hardware and software necessary for implementation has been<br />

purchased as part of the organisational preliminary work, the individual<br />

components must be installed and operated. Generally a RAS system can only<br />

be securely operated if care has previously been taken over the installation. A<br />

pre-requisite to secure installation is the selection of suitable hardware and<br />

software for RAS access (quality, interoperability, compliance with existing<br />

standards) through the previous decision process (see S 2.186 Selection of a<br />

suitable RAS product). This goes to show once again how important it is for<br />

the decision process to be thorough and systematic.<br />

<strong>The</strong> physical components of a RAS system consist of conventional <strong>IT</strong><br />

systems: generally there are at least one server and several clients, network<br />

switching elements, modems or other technical devices. <strong>The</strong> physical security<br />

of these items must be assured as for all other components of a computer<br />

network. Hence at the outset the general safeguards for each of these<br />

components must be implemented, as described in Chapters 3 to 9.<br />

<strong>The</strong> following additional points should be considered specifically with<br />

reference to installation:<br />

- It must not be possible either for users or external third parties to access<br />

either the RAS system or any part of it during the installation phase. No<br />

connections to the productive LAN or to the telecommunications systems<br />

should be active.<br />

- <strong>The</strong> installation must be performed by appropriately skilled personnel.<br />

- <strong>The</strong> installation should follow the procedures specified during planning of<br />

the RAS system.<br />

- <strong>The</strong> installation and configuration must be documented. This can take the<br />

form of either separate installation documentation or a confirmation that<br />

the installation agrees with the planning premises.<br />

- If during installation any departures from the planning premises (e.g.<br />

different cable arrangement, additional equipment) occur, these must be<br />

documented and a note should be entered in the planning documents<br />

explaining why the change was made. This documentation is especially<br />

important as a means of improving future planning.<br />

- <strong>The</strong> correct functioning of each individual component must be established<br />

(e.g. through function testing or self-test).<br />

- For every security-relevant setting, a function test of the security<br />

mechanisms must be carried out. For example, encryption of<br />

communications should be tested using a network analyser.<br />

- Once the installation work is complete, the correct functioning of the entire<br />

system must be verified (acceptance and approval of installation).<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Meticulous<br />

documentation of<br />

installation<br />

System test before<br />

approval

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!