19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

<strong>The</strong> network concept is prepared in a manner similar to that described in S<br />

2.139 Survey of the existing network environment and thus essentially involves<br />

the following steps; however, these steps need not be executed strictly in the<br />

order given below. In some case, the results of executing the individual steps<br />

influence one another mutually, so that these results need to be checked and<br />

consolidated on a regular basis.<br />

1. Conception of network topography and topology as well as physical and<br />

logical segmentation<br />

2. Conception of the network protocols to be used<br />

3. Conception of LAN / WAN connections<br />

<strong>The</strong> individual steps essentially involve the following activities:<br />

Step 1 - Conception of network topography and topology<br />

Based on the analysis profile (see above) and actual structural conditions, a<br />

suitable network topography and topology need to be selected (also refer to S<br />

5.60 Selection of a suitable backbone technology, S 5.2 Selection of an<br />

appropriate network topography and S 5.3 Selection of cable types suited in<br />

terms of communications technology). However, future requirements such as<br />

scalability also need to be considered here. <strong>The</strong> prepared concept must be<br />

documented (cabling plans, etc.)<br />

Based on the ascertained requirements and the anticipated / calculated data<br />

flow, an appropriate physical and logical segmentation must be performed<br />

during conception of the network topography and topology (refer to S 5.61<br />

Suitable physical segmentation, S 5.62 Suitable logical segmentation and S<br />

5.13 Appropriate use of equipment for network coupling).<br />

Step 2 - Conception of the network protocols<br />

This step involves the selection and appropriate conception of the required<br />

network protocols. This includes, for example, the preparation of an<br />

addressing scheme for the IP protocol and the formation of subnetworks.<br />

During the selection of the network protocols, it must be observed that these<br />

protocols are supported by the network topology as well as planned and<br />

existing active network components.<br />

Step 3 - Conception of LAN / WAN connections<br />

Based on the anticipated flow of data across the planned LAN / WAN<br />

connections as well as requirements concerning security and availability, the<br />

LAN / WAN connections can be conceived in this step. This includes the<br />

selection of suitable coupling elements (refer to S 5.13 Appropriate use of<br />

elements for network coupling) as well as their secure configuration (refer to<br />

Chapter 7.3 Firewalls and S 4.82 Secure configuration of active network<br />

components).<br />

Additional steps<br />

Based on the developed network concept, measures for preparing a network<br />

management concept can now be implemented (refer to S 2.143 Development<br />

of a network management concept, S 2.144 Selection of a suitable network<br />

management protocol and S 2.145 Requirements for a network management<br />

tool) and a realisation plan can be outlined in accordance with S 2.142<br />

Development of a network realisation plan.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!