19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.35 Obtaining information on security weaknesses<br />

of the system<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong> Security Management, Administrators<br />

To counter security flaws that have become known or have been disclosed in<br />

publications, the required organisational and administrative measures must be<br />

taken and/or additional security hardware or software must be employed.<br />

It is therefore very important to obtain information on vulnerabilities which<br />

have recently become known. Sources of such information include:<br />

- Bundesamt für Sicherheit in der <strong>Information</strong>stechnik (BSI), P.O.B. 20 03<br />

63, D-53133 Bonn; telephone: 0228-9582-444, fax:-427, E-Mail:<br />

cert@bsi.de, WWW: http://www.bsi.bund.de/bsi-cert<br />

- Manufacturers or distributors of the operating system inform registered<br />

customers about security flaws identified on their systems and provide<br />

them with updated versions of the system or patches for remedying those<br />

security flaws.<br />

- Computer Emergency Response Teams (CERTs) are organisations which<br />

supply information on operating system flaws identified and on how to<br />

remedy them.<br />

Computer Emergency Response Team / Coordination Center (CERT/CC),<br />

Software Engineering Institute, Carnegie Mellon University, Pittsburgh,<br />

PA 15213-3890,<br />

Tel. ++1+412 268-7090 (24 hour Hotline), E-Mail: cert@cert.org, FTP:<br />

ftp://ftp.cert.org, WWW: http://www.cert.org<br />

CERT messages are published in News Groups (comp.security.announce<br />

and info.nsfnet. cert) and through mailing lists (inclusion by E-mail for<br />

transmission to: cert-advisory-request@cert.org).<br />

- CERT in Germany:<br />

- BSI-CERT, Bundesamt für Sicherheit in der <strong>Information</strong>stechnik<br />

(BSI), P.O.B. 20 03 63, D-53133 Bonn; telephone: 0228-9582-444,<br />

fax: -427, E-Mail: cert@bsi.de<br />

- DFN-CERT, Hamburg University, Computer Science Department,<br />

Vogt-Kölln-Strasse 30, D-22527 Hamburg, tel. +49 40-54715-262,<br />

fax -241,<br />

E-mail: dfncert@cert.dfn.de,<br />

FTP: ftp://ftp.cert.dfn.de/pub.security<br />

WWW: http://www.cert.dfn.de<br />

gopher: gopher.cert.dfn.de,<br />

Inclusion in the mailing list for CERT messages by E-mail to:<br />

dfncert-request@cert.dfn.de<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!