19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.13 Correct disposal of resources requiring<br />

protection<br />

Initiation responsibility: Agency/company management; Head of <strong>IT</strong><br />

Section; <strong>IT</strong> Security Management<br />

Implementation responsibility: Head of <strong>Site</strong>/Bldg Technical Service; staff<br />

members<br />

Resources (non-monetary resources) on which sensitive data are stored<br />

(printing paper, floppy disks, streamer tapes, magnetic tapes, hard disks, but<br />

also special toner cassettes, carbon paper or carbon ribbon) and which are no<br />

longer needed or, on account of a defect, are to be discarded, must be disposed<br />

of in such a way that no conclusions can be drawn as regards previously stored<br />

data. In the case of functioning data media, the data should be physically<br />

deleted. Non-functioning data media such as CD-ROMS should be destroyed<br />

mechanically (see S 2.167 Secure deletion of data carriers).<br />

<strong>The</strong> recommended disposal of material requiring protection should be detailed<br />

in a specific directive; adequate disposal facilities are to be provided (see also<br />

DIN 32757).<br />

If sensitive resources are collected prior to their disposal, the collected<br />

material must be kept under lock and be protected against unauthorised access.<br />

If, within the given company/agency, safe and environmentally-sound disposal<br />

cannot be ensured, the companies entrusted with this task must be put under<br />

obligation to comply with the required <strong>IT</strong> security measures. A sample<br />

contract is enclosed with this manual.<br />

Additional controls:<br />

- Are all types of material requiring protection covered by the<br />

aforementioned provisions?<br />

- Is the disposal procedure reliable?<br />

- Are the specified disposal provisions complied with?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!