19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.97 Correct procedure for code locks<br />

Initiation responsibility: <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong>-user<br />

If protective cabinets with mechanical or electronic code locks are used, the<br />

code for these locks must be changed:<br />

- after purchase,<br />

- when there is a change of user,<br />

- after opening in the absence of the user,<br />

- if it is suspected that the code was made known to an unauthorised person<br />

and<br />

- at least once every twelve months.<br />

<strong>The</strong> code cannot consist of numbers which are easy to determine (e.g. personal<br />

data, arithmetical sequences).<br />

Each valid code of a code lock must be recorded and escrowed in a secure<br />

place (see S 2.22 Depositing of passwords in a similar application). It should<br />

be noted that escrowing of the code in the associated protective cabinet is<br />

pointless.<br />

If the protective cabinet has a further lock in addition to a code lock, a<br />

judgement should be made as to whether the code and the key are deposited<br />

together, which would allow quicker access in an emergency, or separately, so<br />

that it is more difficult for an ‘attacker’ to gain access.<br />

Additional controls:<br />

- Is the lock code changed following the occurrences outlined above?<br />

- When was the last time the lock code was changed?<br />

- Is the code for the code locks escrowed safely?<br />

- Where and how is it escrowed?<br />

- Where are any existing spare keys to the cabinet kept?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!