19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> of Generic Components<br />

_________________________________________________________________________________________<br />

- Module 4.1 Buildings must be used once for every building or every sample taken from a group of<br />

buildings.<br />

- Module 4.2 Cabling must generally be applied once per building or sample of buildings (in<br />

addition to module 4.1). However, it may be that certain areas, for example the server room or<br />

control room, have special cabling requirements, in which case it may be advisable to apply<br />

module 4.2 to those parts of the building separately.<br />

- Module 4.3.1 Office must be applied to all rooms or samples of rooms in which information<br />

technology is used but to which none of modules 4.3.2, 4.3.3 or 4.3.4 is being applied.<br />

- Module 4.3.2 Server Room must be applied to every room or sample of rooms in which servers or<br />

PBXs are operated. Servers are <strong>IT</strong> systems which make services available on the network.<br />

- Module 4.3.3 Data Media Archives must be applied to every room or sample of rooms in which<br />

data media are stored or archived.<br />

- Module 4.3.4 Technical Infrastructure Room must be applied to every room or sample of rooms<br />

in which technical devices which require little or no human intervention to run are operated (e.g.<br />

distribution cabinet or standby power supply system).<br />

- Module 4.4 must be applied to every protective cabinet or sample of cabinets once. Protective<br />

cabinets can serve as an alternative to a dedicated server room.<br />

- Module 4.5 must be applied once to every working place at home or sample of the same (if<br />

corresponding groups have been defined).<br />

Tier 3: Security of the <strong>IT</strong> systems<br />

This tier is concerned with security aspects relating to <strong>IT</strong> systems, i.e. to server and client computers,<br />

hosts, terminals etc. Tier 3 is covered by modules from Chapters 5 to 9 of the <strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong><br />

<strong>Manual</strong>.<br />

By analogy with the area "Security of the infrastructure", the modules relating to the area of "Security<br />

of the <strong>IT</strong> systems" may be applied either to individual <strong>IT</strong> systems or to samples from groups. This is<br />

assumed below although no further specific reference to it is made.<br />

- Module 5.1 DOS-PC (single user) must be applied to every stand-alone computer or client on<br />

which the DOS operating system is installed.<br />

- Module 5.2 UNIX System must be applied to every stand-alone computer or client which runs<br />

under the UNIX operating system.<br />

- Module 5.3 Laptop PC must be applied to every mobile computer (laptop).<br />

- Module 5.4 PCs with a Non-Constant User Population must be applied to every stand-alone<br />

computer or client on which different users work at different times.<br />

NB it may not be necessary to apply module 5.4 to <strong>IT</strong> systems which are being modelled using<br />

modules 5.5, 5.6 or 5.9. <strong>The</strong>se modules specifically address security aspects of situations where <strong>IT</strong><br />

assets are used at different times by different users.<br />

- Module 5.5 PC under Windows NT must be applied to every stand-alone computer or client<br />

which runs under Windows NT.<br />

- Module 5.6 PC with Windows 95 must be applied to every stand-alone computer or client which<br />

runs under Windows 95.<br />

- Module 5.99 Stand-alone <strong>IT</strong> systems must be applied to every <strong>IT</strong> system for which there is no<br />

operating system-specific module in the <strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>.<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!