19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.113 Requirements documents concerning<br />

telecommuting<br />

Initiation responsibility: Agency/company management; Head of<br />

Personnel Section<br />

Implementation responsibility: Personnel Section; superiors<br />

As official legislation specifically concerning telecommuting does not yet<br />

exist, certain issues need to be clarified through wage settlements, corporate<br />

resolutions, or individual agreements - as supplements to work contracts -<br />

between telecommuters and employers. This should include a clarification and<br />

settlement of a voluntary participation in telecommuting, overtime and<br />

surcharges, expenses for travelling between home and the institution,<br />

electricity and heating costs, liability (in the case of theft or damage to <strong>IT</strong><br />

equipment, as well as work-related accidents and illnesses) and the duration of<br />

telecommuting terms.<br />

Furthermore, the following issues should be clarified from the point of view of<br />

<strong>IT</strong> security:<br />

- Work periods: <strong>The</strong> allocation of working times to activities at the<br />

institution and at the home workstation needs to be regulated, in addition to<br />

the specification of fixed periods during which telecommuters should<br />

remain accessible at their home workstation.<br />

- Reaction times: Specifications should be made as regards the intervals at<br />

which information (e.g. e-mail) is to be fetched, and the time taken to<br />

respond to such information.<br />

- Work resources: Specifications can be made as regards work resources<br />

which may and may not be used by telecommuters (e.g. software which has<br />

not been approved). For example, an e-mail link can be maintained while<br />

prohibiting the use of other Internet services. Furthermore, the use of<br />

diskettes (danger of computer viruses) can be prohibited if this is not<br />

required by the home workstation.<br />

- Data backup: Telecommuters must be instructed to regularly perform data<br />

backups. In addition, one generation of each backup should be kept at the<br />

institution to improve availability.<br />

- <strong>IT</strong> security measures: Telecommuters must be instructed to observe and<br />

implement the security measures required for telecommuting. <strong>The</strong>se <strong>IT</strong><br />

security measures must be specified in writing to the telecommuters.<br />

- Privacy protection: Telecommuters must be instructed to observe<br />

regulations applying to privacy protection as well as the processing of<br />

person related data at the home workstation.<br />

- Data communications: Specifications must be made as to which data are<br />

to be transmitted using which means. This includes a stipulation of the data<br />

which are to be transmitted in encrypted form, or not at all.<br />

- Transport of folders: Specifications must be made as to the nature and<br />

safeguarding of the transport of folders between the home workstation and<br />

the institution.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!