19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.131 Separation of administrative tasks for<br />

database systems<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong> Security Management, Administrators<br />

Administrators need to be appointed in order to ensure the proper operation of<br />

database systems. In addition to general administrative tasks, these persons are<br />

responsible, in particular, for the management of users and related access<br />

rights. <strong>The</strong>y are also responsible for fulfilling the security requirements of the<br />

database systems in use.<br />

In addition to the safeguards mentioned in S 2.26 Designation of an<br />

administrator and his deputy and S 3.10 Selection of a trustworthy<br />

administrator and his substitute, particular attention must be paid to the<br />

following items where database systems are concerned.<br />

In principle, a distinction must be made between two types of administrator<br />

roles:<br />

- General technical administration of database software<br />

- Administration for individual applications<br />

<strong>The</strong>se two types of administration tasks must be performed by different<br />

persons in order to separate application-specific and general administrative<br />

activities relating to the database.<br />

Basic operation of the database management system, maintenance of data<br />

backups and archiving of data are examples of a general technical database<br />

administration.<br />

In contrast, the application-specific administration involves fulfilling the<br />

individual requirements which applications generate for the database. This<br />

includes, for example, management of the related database objects, providing<br />

users with support in the case of problems and queries, and management of<br />

database IDs. <strong>The</strong> latter activity is only possible if the management of the<br />

database IDs of each application is supported by the database software using<br />

an appropriate authorisation concept, i.e. if it can be separated from the<br />

general access control.<br />

<strong>The</strong> general administrator configures the application-specific administrator<br />

accounts together with the related access rights. This includes, in particular,<br />

the right to create databases. In contrast, rights for individual users should be<br />

granted separately for each application-specific database, by the responsible<br />

application-specific administrator in each case.<br />

Additional controls:<br />

- Have the administrative roles been separated?<br />

- Which administrators have been appointed for the general administration<br />

of the database software and the administration of individual applications?<br />

- How is the interaction between the administrators coordinated? Have their<br />

tasks and responsibilities been specified in writing?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!