19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

particularly in the case of network components which can be configured<br />

automatically, such as bridges and switches. Only this ensures that the data<br />

packets of a logical group actually remain in the corresponding physical<br />

segment. In the case of bridges / switches which allow a configuration of the<br />

conceivable links on the port level (port switching), manual control of link<br />

establishment on layer 1 is also possible.<br />

Example: Systems which allow the connection of terminals to a network<br />

(terminal servers) and systems to be accessed from the terminal servers need<br />

to be assigned to a segment separated from the rest of the network by means<br />

of a bridge. Only this prevents passwords transferred from the terminal server<br />

to the addressed system from being tapped and, possibly, modified from<br />

another segment.<br />

Terminal-Server<br />

File-Server<br />

t f f d<br />

Figure 4: Separation into segments with a bridge in order to enhance integrity<br />

and confidentiality<br />

Furthermore, network components should be selected and dimensioned<br />

appropriately in order to ensure that neither an overload nor a failure of these<br />

components will result in a loss or corruption of data packets.<br />

Additional controls:<br />

- Has physical segmentation been considered as part of the design of the<br />

local network?<br />

- Have requirements concerning availability (particularly in terms of<br />

performance), confidentiality and integrity been ascertained and taken into<br />

account?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

access to file services<br />

bridge

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!