19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> of Generic Components Organisation<br />

_________________________________________________________________________________________<br />

3.1 Organisation<br />

Description<br />

This Chapter lists general and generic measures in the<br />

organisational field which, as standard organisational<br />

measures, are required to achieve a minimum protection<br />

standard. Specific measures of an organisational nature which<br />

directly relate to other measures (e.g. LAN administration)<br />

are listed in the relevant chapters.<br />

Threat Scenario<br />

In this Chapter, the following typical threats (T) are considered as regards <strong>IT</strong> baseline protection:<br />

Organisational Shortcomings<br />

- T 2.1 Lack of, or insufficient, rules<br />

- T 2.2 Insufficient knowledge of requirements documents<br />

- T 2.3 A lack of compatible, or unsuitable, resources<br />

- T 2.4 Insufficient monitoring of <strong>IT</strong> security measures<br />

- T 2.5 Lack of, or inadequate, maintenance<br />

- T 2.6 Unauthorised admission to rooms requiring protection<br />

- T 2.7 Unauthorised use of rights<br />

- T 2.8 Uncontrolled use of resources<br />

- T 2.9 Poor adjustment to changes in the use of <strong>IT</strong><br />

- T 2.10 Data media are not available when required<br />

Human Failure<br />

- T 3.1 Loss of data confidentiality/integrity as a result of <strong>IT</strong> user error<br />

Recommended Countermeasures (S)<br />

For the implementation of <strong>IT</strong> baseline protection, selection of the required packages of safeguards<br />

("modules"), as described in Sections 2.3 and 2.4, is recommended.<br />

In the following, the countermeasure group "Organisation" is set out:<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!