19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.86 Guaranteeing the integrity of standard<br />

software<br />

Initiation responsibility: Agency/company management<br />

Implementation responsibility: Head of <strong>IT</strong> section<br />

It must be guaranteed that the standard software approved can only be<br />

installed in an unchanged condition. Accordingly, the possibility of desired or<br />

unintentional changes occurring in the interim period, e.g. as a result of<br />

computer viruses, bit errors due to technical errors or manipulation in<br />

configuration files, should be prevented.<br />

Installation must only be allowed to take place, therefore, using original data<br />

media or numbered copies of the original data medium. An alternative to the<br />

local installation from data media is the installation via a local network of a<br />

version approved specifically for this purpose. It should be guaranteed that<br />

only authorised persons have access.<br />

If the data capacity allows (e.g. CD-ROM), backup copies should be produced<br />

of the original data media. Original data media and all copies must be kept<br />

protected from unauthorised access (see S 6.21 Backup Copy of Software<br />

Used). <strong>The</strong> copies produced should be numbered and included in inventory<br />

lists. Copies which are no longer needed must be deleted. Before installation,<br />

a computer virus test must be carried out.<br />

As an option, a checksum (cf. S 4.34 Using Encryption, Checksums or Digital<br />

Signatures) can be created using the original data media or using a reference<br />

version installed during the test. With the aid of this, before installation the<br />

integrity of the data media used for it, or the versions deposited in local<br />

networks can be checked, as can correct installation. In addition to this,<br />

installed programs can also be provided with checksums for protection against<br />

unauthorised changes to the approved configuration. In this way infections by,<br />

as yet unknown computer viruses, can be detected. It can also be determined<br />

whether a virus infection has occurred before or after installation.<br />

Additional controls:<br />

- In what way is the integrity of the standard software guaranteed?<br />

- Is monitoring carried out periodically to check the integrity of the installed<br />

programs?<br />

- Are attempts at manipulation of programs and data detected?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!