19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.22 Escrow of passwords<br />

Initiation responsibility: Head of <strong>IT</strong> section<br />

Implementation responsibility: <strong>IT</strong>-user<br />

If access to an <strong>IT</strong> system is protected by means of a password, provisions must<br />

be made to ensure that, in case of absence of a staff member, e.g. vacation or<br />

illness, his/her substitute will have access to the <strong>IT</strong> system. For this purpose,<br />

the current password must be deposited by each staff member in an<br />

appropriate place (in a sealed envelope) and must be updated whenever the<br />

password is altered. If the need arises to use that escrowed password, this<br />

should be done according to the two-person rule.<br />

In the case of telecommuters, it should be ensured that their passwords are<br />

also deposited at the institution, so that if an emergency arises, a stand-in can<br />

access the data stored on the telecommuting computer.<br />

For all systems attended to by administrators, especially for networked<br />

systems, regular inspections must ensure that the current system administrator<br />

password has been escrowed.<br />

Additional controls:<br />

- Are the escrowed passwords complete and up to date?<br />

- Have provisions been made to ensure proper use of the given escrowed<br />

password?<br />

- Is the system of password changes being controlled on the basis of the<br />

updating entries for escrowed passwords?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!