19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

LAN to which, in addition to the operator's console, three PCs are connected<br />

as workstations.<br />

Office<br />

Office<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

document archives<br />

server room<br />

Step 1: Division of responsibilities and separation of functions<br />

<strong>The</strong> following functions are required for the travel expenses accounting<br />

system considered here:<br />

1. LAN administration<br />

2. Auditing<br />

3. data acquisition<br />

4. casework, including ascertainment of mathematical correctness<br />

5. casework, including ascertainment of factual correctness<br />

6. casework, including authority to issue orders<br />

<strong>The</strong> following functions are not compatible with each other on account of<br />

inherent necessities:<br />

- Function 1 and Function 2 (self-control of administration must be<br />

precluded)<br />

- Function 2 and Function 6 (self-control of the person authorised to issue<br />

orders must be precluded)<br />

- Functions 4 or 5 with 6 being performed at the same time (the two-person<br />

rule would be violated with regard to orders to pay)<br />

<strong>The</strong>se functions are performed by the following persons:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!