19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.121 Regular deletion of e-mails<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong>-user<br />

E-mail should not remain stored on the stack of incoming mail for an<br />

unnecessarily long period of time. E-mail should either be deleted after it has<br />

been read, or relocated to a corresponding user directory if it is to be retained.<br />

If too much e-mail is archived on the incoming stack, the <strong>IT</strong> system (mail<br />

server or mail client) managing this stack will reject new incoming e-mail if<br />

the storage space becomes insufficient.<br />

Users must be informed that e-mail which they have deleted via their mail<br />

application is usually not erased irrevocably. Instead of deleting e-mail<br />

immediately, many programs transfer it to a special folder. Users must be<br />

briefed on how to completely delete e-mail on their clients.<br />

Even after having been deleted completely on a client, e-mail may still be<br />

present on a mail server. Many Internet providers and administrators archive<br />

incoming and outgoing e-mail. Instead of deleting e-mail, many mail<br />

applications transfer it to a cybernetic rubbish bin which is emptied every now<br />

and then.<br />

Users must be made aware of the fact that the confidentiality of e-mail can<br />

only be ensured by encryption, and not necessarily by quick deletion<br />

following receipt.<br />

Additional controls:<br />

- Do users know how to delete their e-mail?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!