19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 6.12 Emergency preparedness exercises<br />

Initiation responsibility: Agency/company management; <strong>IT</strong> Security<br />

Management<br />

Implementation responsibility: Head of <strong>IT</strong> Section; staff responsible for<br />

emergency preparedness (contingency<br />

planning); Administrators<br />

Emergency preparedness exercises serve to check the effectiveness of<br />

measures in the field of contingency planning. On the one hand, the effective<br />

and smooth execution of a contingency plan will be tested in an emergency<br />

preparedness exercise, and on the other hand, previously undiscovered<br />

shortcomings will be detected. Typical exercises are:<br />

- alerting exercise;<br />

- conducting fire drills (c.f. S 6.17 Alert plan and fire drills);<br />

- functional testing of generators;<br />

- restart after failure of a selected <strong>IT</strong> component; and<br />

- restoring of data backups.<br />

<strong>The</strong> results of an emergency preparedness exercise must be documented.<br />

Emergency preparedness exercises are to be held at regular intervals. Since<br />

such exercises can have a disruptive effect on normal operations, their<br />

frequency should be geared to the threat scenario; however, the pertinent<br />

exercises should, as a minimum, be held once a year. Staff training activities<br />

(first-aid, fire-fighting, etc.) must be carried out to a necessary extent.<br />

Before an emergency preparedness exercise is held, prior approval must be<br />

obtained from the agency/company management.<br />

Additional controls:<br />

- Are emergency preparedness exercises held at regular intervals?<br />

- Do detected shortcomings give rise to a revision of contingency plans?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!