19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Threats Catalogue Deliberate Acts Remarks<br />

____________________________________________________________________ .........................................<br />

T 2.27 Lack of, or inadequate documentation<br />

Various forms of documentation may be considered: the product description,<br />

the administrator and user documentation required to use the product, and the<br />

system documentation.<br />

If documentation on the <strong>IT</strong> components used is inadequate or lacking, this can<br />

have significant effects both on the selection and decision-making processes<br />

regarding a product, and in terms of damage occurring during actual<br />

operation.<br />

If the documentation is inadequate in the case of damage such as hardware<br />

failure or malfunctioning of programs, error diagnosis and rectification may<br />

be delayed considerably or rendered completely impractical.<br />

Examples:<br />

- If a program stores working data in temporary files without sufficient<br />

documentation of that process, this can lead to the situation that temporary<br />

files are unsuitably protected and confidential information being exposed.<br />

If these files are not sufficiently protected against user access, or if sectors<br />

which are only used temporarily are not correctly deleted physically,<br />

information can become accessible to unauthorised persons.<br />

- When a new software product is installed, existing configurations are<br />

changed. Other programs which have run correctly hitherto are then<br />

incorrectly parameterised and crash. If the changes resulting from the<br />

installation of new software were described in detail, the error could be<br />

located and eliminated in less time.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!