19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.39 Response to violations of security policies<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security management<br />

Implementation responsibility: <strong>IT</strong> Security Management<br />

<strong>The</strong> response to violations of security policies should be laid down so as to<br />

ensure a clear and prompt response.<br />

Investigations should be carried out to establish how and where such violation<br />

has originated. Subsequently, the appropriate measures must be taken to<br />

remedy or minimise the damage caused. If required, additional loss-prevention<br />

measures must be taken. <strong>The</strong> action to be taken will depend both on the nature<br />

of the violation and on the offender.<br />

Provisions must be laid down on who is responsible for contacts with other<br />

organisations for the purpose of obtaining information on known security<br />

flaws (cf. also S 2.35 - Obtaining information on security weaknesses of the<br />

system) or of passing on information about recently detected security<br />

breaches. Care must be taken to inform any other possibly affected<br />

units/agencies by the fastest means possible.<br />

Additional controls:<br />

- Has the approach to be taken in case of suspected violations of security<br />

policies been clearly defined?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!