19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> of Generic Components<br />

_________________________________________________________________________________________<br />

2.4.2 Performing the Target Versus Actual Comparison<br />

Once all the necessary preliminary work has been completed, the actual survey can begin on the<br />

previously agreed dates. This entails working through the safeguards contained in the module for<br />

which the person being interviewed is responsible in sequence.<br />

<strong>The</strong> answers regarding implementation status for the individual safeguards may be classified into the<br />

following categories:<br />

„Unnecessary“ - Implementation of the recommended safeguards is not necessary in the form<br />

suggested as other measures (e.g. safeguards which are not contained in the <strong>IT</strong><br />

<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong> but achieve the same effect) already provide<br />

sufficient protection against the relevant threats, or else the measures<br />

recommended are not relevant (e.g. because certain services have not been<br />

implemented).<br />

"Yes" - All the recommendations in the safeguard have been implemented effectively<br />

and in their entirety.<br />

"Partially" - Some of the recommendations have been implemented, while others have not<br />

yet been implemented or only partially implemented.<br />

"No" - Most of the recommendations contained in the safeguard have not yet been<br />

implemented.<br />

Reading out the text of the recommendations contained in a given safeguard during the interview is<br />

not recommended as the manual was not designed for this purpose. Hence, the interviewer needs to be<br />

familiar with the contents of the module. If necessary, handy checklists containing keywords should be<br />

prepared in advance of the interviews. In order to be able to clarify any disagreements in case of<br />

doubt, it is nevertheless useful to have the full text of the safeguards at hand. Direct entry of the<br />

answers into a PC during the interview is likewise not recommended as it would be distracting to those<br />

involved and cause unwanted interruption to communication.<br />

If the interview begins with a few introductory words and the purpose of the basic security check is<br />

briefly introduced, this can help to create a relaxed, open and productive atmosphere. It is<br />

recommended continuing by naming and briefly explaining the safeguard. Rather than conducting a<br />

monologue, it is better to give the interviewee(s) the opportunity to go into those parts of the safeguard<br />

which have already been implemented and then discuss any items still at issue.<br />

<strong>The</strong> questions asked should always be directed at the level of standard security safeguards, and only<br />

after the basic security check has been completed should any more far-reaching aspects of highly<br />

sensitive applications be considered. If there is a requirement to verify the statements made in the<br />

interviews, this could be achieved, for example, by examining samples of the relevant procedures and<br />

concepts, in the case of the area of infrastructure by visiting the objects under investigation on-site<br />

with the contact person, and/or by checking client and/or server settings in selected <strong>IT</strong> systems.<br />

To conclude each safeguard, the interviewee should be informed of the assessment result (i.e.<br />

safeguard implementation status = Unnecessary/Yes/ Partially/No) and this decision should be<br />

explained.<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!