19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 6.53 Redundant arrangement of network<br />

components<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrator, Purchase Department<br />

Central active network components need to remain highly available because a<br />

large number of users are generally dependent upon the smooth operation of a<br />

local network. To allow operations to be resumed as quickly as possible<br />

following the occurrence of a malfunction, a redundancy must be created for<br />

each area in accordance with the applicable availability requirements, so that a<br />

partial or complete failure of the related network components can be tolerated,<br />

whilst keeping the resources required for prevention within acceptable limits.<br />

<strong>The</strong>re are two different ways of achieving redundancy:<br />

- <strong>The</strong> redundant network components can be stored in a warehouse, in order<br />

to allow quick replacement in an emergency. If this is not done, longdrawn<br />

procurement routines will often be required before errors can be<br />

remedied. Alternatively, maintenance or delivery contracts can be<br />

concluded with the related manufacturers in order to guarantee a quick<br />

replacement of defective components (also refer to S 6.14 Replacement<br />

procurement plan). After that, the configuration backup data can be<br />

reloaded in order to minimise the downtime for the affected network<br />

segments (refer to S 6.52 Regular backup of configuration data of active<br />

network components).<br />

- Even during planning of the network, it is advisable to allow for a<br />

redundancy of network components. For example, all central switches and<br />

- depending on the protocols in use - all routers should be mirrored at least<br />

once in the network in order to achieve redundant server connections and<br />

redundant links between the individual network components (refer to<br />

Figure 1). Correct operation is to be guaranteed by means of a suitable,<br />

logical network configuration.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!