19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- Adhering to internal regulations and legal stipulations (e.g. sufficient<br />

data protection when processing person-related data)<br />

Brief examples:<br />

- <strong>The</strong> product must comply with the principles of proper EDPcontrolled<br />

auditing systems.<br />

- As person-related data are processed, it must be possible to meet the<br />

requirements stipulated in the Federal Data Privacy Act.<br />

- Requirements regarding user-friendliness, characterised by how easy<br />

the system is to operate, understand and learn, i.e. particularly by the<br />

quality of the user interface and documentation, and the help functions.<br />

Brief examples:<br />

- An on-line help function must be available.<br />

- <strong>The</strong> user interface must be designed in such a way that unskilled<br />

persons can become familiar with the basic functions within two<br />

hours.<br />

- <strong>The</strong> documentation should be available in the local language.<br />

- Requirements concerning serviceability for the user are mainly based on<br />

the handling of errors.<br />

Brief examples:<br />

- <strong>The</strong> amount of administration involved must not be too high.<br />

- <strong>The</strong> provider must offer a hotline for questions.<br />

- <strong>The</strong> product must be easy to install and configure.<br />

- <strong>The</strong> product must be easy to deinstall.<br />

- <strong>The</strong> maximum costs resulting from the purchase of this product are<br />

predetermined. Not only the immediate purchase costs should be taken into<br />

consideration, but also costs arising at a later date, e.g. for updating<br />

hardware, personnel costs or training.<br />

Brief examples:<br />

- <strong>The</strong> product may cost a maximum of DM 15,000.<br />

- <strong>The</strong> training costs must not exceed DM 2,000.<br />

- <strong>The</strong> requirements concerning documentation must highlight which<br />

documents are required and in which quality (completeness,<br />

comprehensibility).<br />

Brief examples:<br />

- <strong>The</strong> user documentation must be easy to understand and suitable for<br />

reading without instruction. All functions of the product should be<br />

described.<br />

- <strong>The</strong> system manager documentation must include troubleshooting<br />

information.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!