19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Threats Catalogue Deliberate Acts Remarks<br />

____________________________________________________________________ .........................................<br />

T 2.26 Lack of, or inadequate software test and<br />

release procedures<br />

If new hardware or software is inadequately tested or not tested at all, and<br />

released without installation instructions, errors in the hardware or software<br />

may either not be identified or essential installation parameters may not be<br />

recognised or considered. <strong>The</strong>se hardware, software or installation errors<br />

resulting from software and release procedures that are inadequate or lacking<br />

altogether, can result in a considerable threat to <strong>IT</strong> operation.<br />

In the confidence that you will be able to install new hardware or software<br />

without difficulty, it is often not considered that the potential damage is<br />

completely out of proportion to the costs of carrying out a proper test- and<br />

release procedure. Programs or <strong>IT</strong> systems that have been inadequately tested<br />

and that still contain errors are integrated in the production environment.<br />

<strong>The</strong>se errors then have a disruptive effect on programs that had until then<br />

been working satisfactorily.<br />

Examples of such damage are listed below:<br />

- Programs or program updates cannot be used effectively because more<br />

resources (e.g. RAM, disk space) than expected are needed to achieve a<br />

reasonable processing speed.. If this is not detected during test runs it can<br />

lead to considerable amounts of unusable investments. Decisions against<br />

further investments often lead to the result that a software product, which<br />

was ordered and paid for regularly, could never be used.<br />

- Routine procedures can be badly held up after the installation of new<br />

software. <strong>The</strong> benefit originally envisaged when the program was installed<br />

only becomes apparent much later, as the key staff were not trained or<br />

informed about the new program functions.<br />

- If a new, updated DBMS software version containing bugs is loaded, the<br />

database will no longer be available, and a loss of data might occur.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!