19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

and which have to be involved. A sensible proposal for distributing<br />

responsibilities is summarised in the following table::<br />

Compiling the<br />

requirement<br />

catalogue<br />

Selection of a<br />

suitable product<br />

Testing<br />

Approval<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

responsible to be involved<br />

Specialist Department,<br />

<strong>IT</strong> Area<br />

Procurer<br />

Specialist Department<br />

and <strong>IT</strong> Area<br />

Management of<br />

Agency/Company, -<br />

maybe delegated to<br />

Head of Specialist<br />

Department<br />

Procurer, Budget Manager, <strong>IT</strong><br />

Security Officer, Data Privacy<br />

Officer, Staff or Works Council<br />

<strong>IT</strong> Area, Specialist Department<br />

<strong>IT</strong> Security Officer, Data<br />

Privacy Officer, Staff or Works<br />

Council<br />

Procurement Procurer Budget Department<br />

Ensuring integrity<br />

of the software<br />

Installation and<br />

configuration<br />

Version checking<br />

and licence<br />

management<br />

<strong>IT</strong> Area<br />

<strong>IT</strong> Area<br />

<strong>IT</strong> Area<br />

Deinstallation <strong>IT</strong> Area<br />

Checking <strong>IT</strong><br />

operation<br />

<strong>IT</strong> Security officer<br />

<strong>The</strong> allocation of these responsibilities should be set down in writing and it<br />

should be checked on a regular basis that the relevant procedures are correctly<br />

adhered to.<br />

Additional controls:<br />

- Which provisions are in force?<br />

- Are all employees aware of existing regulations and the monitoring of<br />

these regulations?<br />

- Are all relevant bodies (e.g. staff council, budget department, Data Privacy<br />

Officer) involved to the appropriate extent?<br />

-<br />

-<br />

-<br />

-<br />

-<br />

-

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!