19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 6.9 Contingency plans for selected incidents<br />

Initiation responsibility: Head of <strong>IT</strong> Section; Head of Organisational<br />

Section; <strong>IT</strong> Security Management; staff<br />

responsible for the individual <strong>IT</strong> applications<br />

Implementation responsibility: Staff responsible for emergency<br />

preparedness(contingency planning)<br />

Contingency plans contain instructions on action to be taken and rules of<br />

conduct in case of specific damaging incidents. <strong>The</strong>se are incidents<br />

jeopardising parts of the <strong>IT</strong> system which are of vital importance. A<br />

contingency plan is aimed at ensuring restoration of availability as quickly as<br />

possible.<br />

A contingency plan must also take account of the interaction of a damaging<br />

incident and of the respective contingency measure taken. For instance, a fire<br />

can be controlled by means of a sprinkler. However, the use of water can, in<br />

its turn, give rise to new threats, e.g. to power supply, to data media archives,<br />

etc.<br />

Depending on the factors in the operational environment, contingency plans<br />

will have to be established to provide against the following incidents:<br />

- fire<br />

- water ingress<br />

- power failure<br />

- failure of the air-conditioning system<br />

- explosion<br />

- breakdown of data transmission (cf. S 6.10)<br />

- sabotage.<br />

<strong>The</strong> effectiveness of contingency plans is to be verified by means of<br />

emergency preparedness exercises (cf. S 6.12).<br />

Additional controls:<br />

- Do contingency plans exist?<br />

- Has the effectiveness of contingency plans been verified?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!