19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 6.8 Alert plan<br />

Initiation responsibility: Agency/company management<br />

Implementation responsibility: Head of <strong>IT</strong> Section; Head of Organisational<br />

Section; <strong>IT</strong> Security Management; staff<br />

responsible for the individual <strong>IT</strong> applications<br />

An alert plan contains a description of the reporting channel through which the<br />

units/individuals concerned are to be notified when an emergency has<br />

occurred. <strong>The</strong> alert can be given, for instance, over the telephone, by fax, by<br />

paging systems, or by courier. It must be laid down who notifies whom, who<br />

is alternatively to be notified and what action should be taken if this<br />

person/unit cannot be contacted. For this purpose, address and telephone lists<br />

might have to be kept.<br />

<strong>The</strong> alert plan must be available to all persons responsible for emergency<br />

procedures and, in addition, a redundant copy must be held centrally (e.g.<br />

entrance control staff, guards). <strong>The</strong> individuals listed in the alert plan must be<br />

familiar with the part concerning them. All staff members must know the<br />

contact persons to whom the occurrence of an incident, which might lead to an<br />

emergency, can be reported.<br />

Different alert plans may have been established for different damaging<br />

incidents (fire, water, breakdown of data transmission). In that case, care must<br />

be taken to cover all types of incidents.<br />

In addition to the compilation of an alert plan, the establishment of an on-duty<br />

service should be considered.<br />

Additional controls:<br />

- Is the alert reporting channel being tested sporadically?<br />

- When was the alert plan last reviewed?<br />

- Are all individuals listed in the alert plan still employed in the<br />

agency/company?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!