19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 6.59 Specification of responsibilities for dealing<br />

with security incidents<br />

Initiation responsibility: Agency/company Management, <strong>IT</strong> Security<br />

Management<br />

Implementation responsibility: <strong>IT</strong> Security Management<br />

When specifying the responsibilities for handling security incidents, it is<br />

worthwhile considering the sequence of events in a hypothetical security<br />

incident. <strong>The</strong> tasks and responsibilities of the person groups involved must be<br />

determined and an appropriate method of obligating and instructing them must<br />

be devised. To give an idea how this might be done, examples are set out<br />

below for some of the groups typically affected.<br />

<strong>IT</strong>-users<br />

Task:<br />

As soon as <strong>IT</strong>-users become aware of a security-relevant irregularity, they<br />

must observe the appropriate procedural rules and report the irregularity.<br />

Responsibility:<br />

<strong>IT</strong> users must decide what the appropriate reporting channel is in the<br />

present case (see S 6.60 Investigation and assessment of a security<br />

incident).<br />

Duty / information:<br />

Every <strong>IT</strong> user should have a duty under the in-house security guidelines to<br />

report any security-relevant irregularities. Furthermore, all users should be<br />

given written instructions informing them of the actions they should take<br />

and to whom which incidents should be reported.<br />

<strong>IT</strong> Administrator<br />

Task:<br />

<strong>The</strong> <strong>IT</strong> Administrator's task here is to receive reports regarding securityrelevant<br />

irregularities relating to <strong>IT</strong> systems for which he is responsible. He<br />

must then decide whether to take corrective action himself or whether he<br />

should report the incident to the next higher escalation level.<br />

Responsibility:<br />

An administrator must be able to decide whether there is a security<br />

problem, whether he can deal with it himself, whether he should consult<br />

other persons immediately (in accordance with the escalation plan) and<br />

whom he should inform.<br />

Duty / information:<br />

This should be specified in the job description and in the "Policy for<br />

handling security incidents".<br />

<strong>IT</strong> Security Officer / <strong>IT</strong> Security Management<br />

Task:<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Define tasks and<br />

responsibilities

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!