19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

Damage category Damage /<br />

loss =<br />

medium<br />

Violation of laws, regulations or<br />

contracts<br />

Impairment of the right to<br />

informational self-determination<br />

Impairment of the physical integrity<br />

of a person<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

D1<br />

Impaired performance of duties D2<br />

Negative effects on external<br />

relationships<br />

Financial consequences D4<br />

Damage /<br />

loss = high<br />

Damage /<br />

loss = very<br />

high<br />

Damage cases D1 to D4 are assigned the following priorities on the basis of<br />

the previous priority assignment:<br />

Priority classification method: D1 = 2, D2 = 3, D3 = 1, D4 = 3<br />

Priority rating method: D1 = 13, D2 = 15, D3 = 4, D4 = 18<br />

In both cases it would be clear that damage limitation effort should initially be<br />

concentrated on damage case D3 (negative effects on external relationships)<br />

before any attempt is made to tackle the other types of damage. In the<br />

example, to limit the negative effects on external relationships, the Internet<br />

server which has been tampered with would be taken off the network as the<br />

prelude to other measures. If the damage resulting from negative effects on<br />

external relationships had been assigned a lower priority and greater<br />

importance had been attached to impairment of the municipal authority's<br />

ability to accomplish its work, disconnecting the Internet server might not be<br />

viewed as a measure which should be implemented immediately.<br />

Additional controls:<br />

- Has the priority assignment been agreed with Management?<br />

- Has the priority assignment been notified to all the decision makers in the<br />

management system for the handling of security incidents?<br />

- When was the priority assignment last updated?<br />

D3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!