19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> of Generic Components<br />

_________________________________________________________________________________________<br />

<strong>The</strong> staff concerned must also receive training as to how to implement and apply the new <strong>IT</strong> security<br />

safeguards correctly. If this training is left out, it is possible that the safeguards might not be<br />

implemented and/or that they might fail to achieve the desired effect. Another consequence would be<br />

that staff would feel inadequately informed, and this in turn often results in a negative attitude towards<br />

<strong>IT</strong> security.<br />

After the new <strong>IT</strong> security measures have been implemented, the <strong>IT</strong> Security Officer should check to<br />

ensure that staff have fully accepted them. Should it turn out that the new measures have not gained<br />

acceptance, they are doomed to failure. <strong>The</strong> causes of the lack of acceptance should be investigated<br />

and, if necessary, those concerned should be given an additional briefing.<br />

Example:<br />

Excerpts from a fictitious example are provided below in order to illustrate the steps listed above in<br />

more detail. <strong>The</strong> table below shows the consolidated list of safeguards to be implemented, together<br />

with estimates of the associated costs, which is generated as a result of steps 1 to 3.<br />

Target object Mod<br />

ule<br />

Entire organisation 3.1 S 2.11 Provisions Governing the<br />

Use of Passwords<br />

Server room R 3.10 4.3.2 S 1.24 Avoidance of Water<br />

Pipes<br />

Server room R 3.10 4.3.2 A1 Installation of metal sheets<br />

to take water away, with<br />

monitoring via a water alarming<br />

device which alerts the porter.<br />

Server S4 6.5 S 1.28 Local Uninterruptible<br />

Power Supply<br />

C1 group of clients 5.5 A2 Smart card-supported<br />

authentication plus local<br />

encryption of hard disks<br />

...<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000<br />

Safeguard Priority Costs Notes<br />

1 2 3<br />

P a) euro 0<br />

b) 2 working days<br />

c) euro 0 p.a.<br />

d) 0 working days<br />

p.a.<br />

X a) euro 20,000<br />

b) 12 working days<br />

c) euro 0 p.a.<br />

d) 0 working days<br />

p.a.<br />

a) euro 4,000<br />

b) 3 working days<br />

c) euro 0 p.a.<br />

d) 0 working days<br />

p.a.<br />

X a) euro 1,000<br />

b) 1 working day<br />

c) euro 0 p.a.<br />

d) 0 working days<br />

p.a.<br />

a) euro 1,400<br />

b) 2 working days<br />

c) euro 0 p.a.<br />

d) 2 working days<br />

p.a.<br />

Key:<br />

- Safeguard<br />

A1 = additional measure 1 (additional to the <strong>IT</strong> baseline protection safeguards)<br />

- Priorities<br />

P = partially implemented, X = missing, has not been implemented<br />

- Costs:<br />

a) = one-off investment cost<br />

This safeguard is not costeffective<br />

to implement.<br />

Instead, safeguard A1 will be<br />

implemented.<br />

Replaces safeguard S 1.24.<br />

This additional measure<br />

replaces safeguard S 4.1.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!