19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Threats Catalogue Deliberate Acts Remarks<br />

____________________________________________________________________ .........................................<br />

T 4.33 Poor-quality or missing authentication<br />

Authentication mechanisms can be used to authenticate users or components,<br />

or to determine the origin of data. If authentication mechanisms are missing or<br />

if the quality is too poor, there is a risk that<br />

- unautorised persons can gain access to <strong>IT</strong> systems or data,<br />

- the causes of problems cannot be identified or<br />

- the source of data cannot be determined.<br />

Gaps occur in the security<br />

- when users are authenticated, for example if users choose passwords which<br />

are easy to guess or if they never change their password,<br />

- when components are authenticated, for example if default passwords are<br />

not replaced by individually-chosen ones following the installation of an <strong>IT</strong><br />

system, if the passwords which are permanently entered in many <strong>IT</strong><br />

systems are never changed again, or if the passwords are not kept safely<br />

and nobody can remember the vital password after the system has crashed.<br />

- in the choice of procedure, for example if it is completely useless or gaps<br />

in the security are known which are not reacted to while the system is in<br />

operation.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!