19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.84 Deciding on and developing the installation<br />

instructions for standard software<br />

Initiation responsibility: Agency/company management<br />

Implementation responsibility: Procurer, Head of Specialist Department ,<br />

Head of <strong>IT</strong> Section<br />

Following the completion of all tests, the test results must be submitted to the<br />

procurer. <strong>The</strong> decision in favour of a product must now be made by the<br />

procurer with the involvement of the Head of the Specialist Department and<br />

the Head of <strong>IT</strong> Sector on the basis of the test results and the price-performance<br />

ratio resulting from them. In this connection, the particular aspect to be set in<br />

relation to the purchase price is the level of performance of the individual<br />

products compared to the Requirements Catalogue. Also, additional functions<br />

of the products which were not listed in the Requirements Catalogue but<br />

which are nevertheless significant to their use, should be taken into account in<br />

reaching the decision.<br />

Drawing up of installation instructions<br />

After a decision is taken in favour of a product, installation instructions must<br />

subsequently be drawn up for the selected product. During testing, the<br />

configuration of the product was so determined to permit secure and efficient<br />

production working. This is the way to guarantee user-friendliness,<br />

correctness and security in the workplace.<br />

In order to guarantee the right configuration of the product in actual operation,<br />

specific parameters must be specified. Some of these must be accompanied by<br />

organisational provisions.<br />

For some features of a product the following section shows, by way of<br />

example, what can be specified in the context of installation instructions.<br />

Example:<br />

User-friendliness:<br />

- Drivers X, Y and Z (screen, printer, mouse, network) must be installed<br />

with the product to create an acceptable working environment for the user<br />

(screen flicker-free, reasonable editing, etc.).<br />

- <strong>The</strong> settings at which individual functions have the greatest processing<br />

speed must be specified if other criteria such as security are not at variance<br />

with them (the size of the swapping-out files must be fixed at at least 10<br />

MB, the verification option must be activated for data backup, although<br />

verification requires additional time).<br />

Security:<br />

- Security function parameters must be pre-set (e.g. the minimum length of<br />

passwords must be 6 characters, backups must be created each day, logging<br />

must be activated to its full extent, rights of access to personl-related log<br />

files must be arranged only for the data privacy officer, ...).<br />

- If several procedures are being supported which are relevant to security<br />

(e.g. encryption algorithm, hash functions), the ones that must be selected<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!