19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.4 Maintenance/repair regulations<br />

Initiation responsibility: Head of <strong>IT</strong> section<br />

Implementation responsibility: Head of <strong>IT</strong> Section, Administrator, <strong>IT</strong> users<br />

As a precautionary measure to safeguard <strong>IT</strong> systems against failure, proper<br />

performance of maintenance work is of particular importance. Timely<br />

initiation and monitoring the execution of maintenance work should be<br />

ensured by a central unit (e.g. procurement office). Maintenance work should<br />

be carried out by trustworthy persons or companies.<br />

In-house maintenance and repair<br />

Supervisory regulations must be laid down for maintenance and repair work,<br />

especially if this is carried out by external staff: A competent person should<br />

supervise this work in such a way that he/she can assess whether unauthorised<br />

actions occur during such maintenance/repair. In addition, it must be verified<br />

whether the required maintenance has actually been carried out.<br />

<strong>The</strong> following measures before and after maintenance/repair work must<br />

be planned:<br />

- <strong>The</strong> relevant staff members must be informed of the measures.<br />

- Maintenance engineers must, upon request, establish their identity.<br />

- Data access by the maintenance engineer must be avoided to the extent<br />

possible. If and where required, data media should be previously removed<br />

or deleted (after complete backup), especially when such work is carried<br />

out externally. If deletion is not possible (e.g. because of a defect), such<br />

work must be monitored also externally or specific contractual<br />

arrangements must be made.<br />

- <strong>The</strong> entry and access permissions granted to maintenance engineers are to<br />

be confined to the absolute minimum and must be revoked or cancelled<br />

after such work.<br />

- Upon completion of maintenance or repair work, changes to the passwords<br />

will be required depending on the "penetration depth" afforded to<br />

maintenance staff. With regard to PCs, it might be expedient to make a<br />

computer virus check.<br />

- <strong>The</strong> maintenance work carried out must be documented (scope, results,<br />

time, possibly the name of the maintenance engineer).<br />

External maintenance and repairs<br />

If <strong>IT</strong> systems are sent away for maintenance or repair, all sensitive data on the<br />

data-medium must first be physically deleted. If this is not possible due to a<br />

defect preventing access to the data medium, the company responsible for the<br />

repairs is obliged to comply with the necessary <strong>IT</strong>-security measures. <strong>The</strong><br />

contractual regulations should comply with S 3.2 (Commitment of staff<br />

members to compliance with relevant laws, regulations and provisions)<br />

regarding the secrecy of data. In particular, data stored externally during<br />

maintenance must be erased meticulously after work has been completed. <strong>The</strong><br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!