19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> of Generic Components<br />

_________________________________________________________________________________________<br />

clients in the HR Department. <strong>The</strong>y have access to server S1 in the HR Department in Bonn. C2 and<br />

C3 represent the 10 clients in the Administration Department and the 75 clients in the end-user<br />

departments in Bonn. <strong>The</strong> only differences here are in relation to the application programs used.<br />

Finally, group C4 represents the clients in end-user departments in Berlin. <strong>The</strong>se differ from<br />

groups C1 to C3 in the environmental infrastructure and their integration into the overall network.<br />

Collecting information about the <strong>IT</strong> systems<br />

<strong>The</strong> next step relevant to the assessment of protection requirements and modelling of the <strong>IT</strong> assets to<br />

be subsequently performed is to prepare a list of the existing and planned <strong>IT</strong> systems in tabular form.<br />

<strong>The</strong> term "<strong>IT</strong> system" refers here not only to computers in the narrower sense, but also to other active<br />

network components such as network printers, private branch exchanges (PBX) etc. <strong>The</strong> focus here is<br />

on the technical implementation of an <strong>IT</strong> system, e.g. stand-alone PC, Windows NT server, PC client<br />

under Windows 95, UNIX server, PBX. At this point, only the system as such (e.g. UNIX server)<br />

should be recorded, rather than the individual elements which make up the <strong>IT</strong> system (i.e. CPU,<br />

keyboards, monitors etc. should be omitted).<br />

Both networked and non-networked <strong>IT</strong> systems should be recorded, i.e. in particular, any <strong>IT</strong> systems<br />

which are not already included in the network plan previously considered. <strong>IT</strong> systems which have been<br />

grouped together as part of the exercise of simplifying the network plan can be viewed from now on as<br />

a single object. Again, the <strong>IT</strong> systems which are not included on the network plan should be checked<br />

to see whether it would be logical to group some of them together. For example, this might be possible<br />

if there is a large number of stand-alone PCs which satisfy the conditions stated as being necessary for<br />

grouping in the "Reducing complexity by identifying groups of similar assets" section above.<br />

When collecting the data, the following information which will be needed at subsequent stages should<br />

be noted down:<br />

- a unique name for the <strong>IT</strong> system,<br />

- description (type and function),<br />

- platform (e.g. hardware architecture/operating system),<br />

- number of <strong>IT</strong> systems included in each group,<br />

- installations site of the <strong>IT</strong>-system,<br />

- status of the <strong>IT</strong> system (operational, in test stage, in planning stage)<br />

- user/administrator of the <strong>IT</strong> system.<br />

Example: Bundesamt für Organisation und Verwaltung (Federal Agency for Organisation and<br />

Administration, BOV) - Part 2<br />

As an example, the table below shows an excerpt from the list of <strong>IT</strong> systems in the BOV. (<strong>The</strong><br />

complete list is included in the auxiliary aids provided on the CD-ROM.)<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!