19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

Establishing the necessary test environment<br />

<strong>The</strong> test environment described in the test plan must be established and the<br />

products to be tested installed. <strong>The</strong> components used should be identified and<br />

their configuration described. In the event that deviations from the described<br />

configuration arise when installing the product, this should be documented.<br />

Performing the test<br />

<strong>The</strong> test must be carried out using the test plan. Each action, together with the<br />

test results, must be adequately documented and evaluated. In particular, if<br />

errors appear, these must be documented in such a way that they can be<br />

reproduced. Operating parameters suited to later production working must be<br />

determined and recorded to enable installation instructions to be drawn up<br />

later.<br />

If additional functions are detected in the product which are not listed in the<br />

Requirements Catalogue but can nevertheless be of use, a short test for them<br />

must be carried out at the very least. If it becomes apparent that this function<br />

is of particular importance for later operation, they must be tested in full. For<br />

the additional test expenditure incurred, application must be made if necessary<br />

for an extension of the time limit to the person responsible. <strong>The</strong> test results<br />

must be included in the overall evaluation.<br />

If, when processing individual test contents, it becomes apparent that one or<br />

several requirements of the Requirements Catalogue were not sufficiently<br />

specific, these must be put in more specific terms if necessary.<br />

Example: In the Requirements Catalogue, encryption is demanded to<br />

safeguard the confidentiality of the data to be processed. During testing it has<br />

become apparent that off-line encryption is unsuitable for the intended<br />

purpose. An addition must therefore be made to the Requirements Catalogue<br />

with regard to on-line encryption. (Off-line encryption must be initiated by the<br />

user and each of the elements to be encrypted must be specified; on-line<br />

encryption is carried out in a transparent way on behalf of the user with pre-set<br />

parameters.)<br />

Receipt tests<br />

Before all other tests, the following basic aspects must first be tested, as any<br />

failure in these receipt tests will lead to direct actions or the stopping of the<br />

test:<br />

- <strong>The</strong> absence of computer viruses in the product must be checked by a<br />

current virus search program.<br />

- It must be established in an installation test whether the product can be<br />

installed simply, completely and comprehensibly for the later-intended<br />

purpose. Likewise, there must be a check on how the product is completely<br />

de-installed.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!