19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.123 Selection of a mail provider<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Head of <strong>IT</strong> section<br />

Before selecting a mail provider, the responsible persons should inform<br />

themselves about the regulations laid down by the prospective provider, for<br />

example, whether upper limits have been set for the volume of incoming and<br />

outgoing e-mail, whether e-mail is filtered and, if so, according to which rules.<br />

Confirmation of reliable operation of the provider's mail server must be<br />

obtained, i.e. the conditions specified in S 5.56 Secure Operation of a Mail<br />

Server must be fulfilled.<br />

<strong>The</strong> mail provider stores user data for invoicing purposes (name, address,<br />

user-ID, bank account) as well as connection data and transmitted contents<br />

(over a period of time which varies from one provider to another).<br />

Users should ask their mail provider for how long which items of data<br />

concerning them remain stored. When selecting a provider, it should be taken<br />

into account that German providers must comply with data privacy regulations<br />

applying to the processing of this information.<br />

Through the use of encryption, users can prevent providers from being able to<br />

read the contents of the transferred data.<br />

Large providers with their own large network have an advantage in that e-mail<br />

exchanged exclusively within this network is less susceptible to manipulation<br />

than if it were forwarded via the Internet.<br />

Many providers whose headquarters are situated abroad route all e-mail via<br />

that country. For example, AOL (and Compuserve) route all e-mail via the<br />

US. This fact should be taken into account when determining the number of<br />

gateways via which e-mail is distributed, i.e. the number of parties who might<br />

be able to monitor the e-mail.<br />

Additional controls:<br />

- According to which criteria has the mail provider been selected?<br />

- Which security measures does the mail provider implement?<br />

- According to which criteria is e-mail filtered by the mail provider?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!