19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.79 Determining responsibilities in the area of<br />

standard software<br />

Initiation responsibility: Agency/company management<br />

Implementation responsibility: Head of <strong>IT</strong> Section, Head of organisation<br />

Prior to the introduction of standard software, a number of responsibilities<br />

must be determined, such as for the drawing up of a requirement catalogue,<br />

the pre-selection of products, testing and approval, and the installation.<br />

Below is a proposal of how these responsibilities may be sensibly allocated.<br />

As titles vary from organisation to organisation, some functions are described<br />

according to their tasks:<br />

- <strong>The</strong> specialist department is the user of the standard software. This<br />

department states its need for new software and thus initiates<br />

procurement. It is involved in the pre-selection and testing stages in<br />

order to include the requirements of the user.<br />

- <strong>The</strong> agency/company management is responsible for the approval of<br />

the standard software. This responsibility is mostly delegated to the<br />

Head of the Specialist Department. After approval of the software,<br />

responsibility for correct usage of the standard software is transferred<br />

to the specialist department.<br />

- <strong>The</strong> <strong>IT</strong> area has the task of providing <strong>IT</strong> solutions to fulfil the tasks of<br />

the specialist department and of guaranteeing correct and reliable<br />

operation of the <strong>IT</strong>.<br />

- <strong>The</strong> procurer must ensure the interoperability and compatibility of<br />

the standard software and the adherence to internal standards and legal<br />

stipulations. <strong>The</strong>re are often <strong>IT</strong> Co-ordinators in the individual<br />

departments who assume the tasks of the procurer and co-ordinate the<br />

budgetary funds of the departments.<br />

- <strong>The</strong> budget is responsible for accounting, the <strong>IT</strong> budget management<br />

and for the provision of the necessary budgetary funds.<br />

- <strong>The</strong> <strong>IT</strong> Security Officer must check whether an appropriate security<br />

level can be guaranteed with the products used or to be purchased. As<br />

part of the <strong>IT</strong> Security Management (c.f. Chapter 1), he must ensure<br />

<strong>IT</strong> securing during current operation.<br />

- <strong>The</strong> Data Privacy Officer must ensure adherence to the provisions<br />

relating to data protection and adequate protection of person-related<br />

data.<br />

- <strong>The</strong> staff or work council must in most cases be involved in the<br />

selection of new standard software, particularly if this means<br />

considerable changes to work processes or if the software is suitable<br />

for performance monitoring (see S 2.40 Timely Involvement of the<br />

Staff / Factory Council).<br />

Throughout the entire process concerning "standard software", it must be<br />

determined for each step which of the above are implementation responsibility<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!