19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> of Generic Components Personnel<br />

_________________________________________________________________________________________<br />

3.2 Personnel<br />

Description<br />

This Chapter states the generic <strong>IT</strong> baseline protection<br />

safeguards which, on a standard basis, should be implemented<br />

with regard to personnel matters. A wide variety of<br />

safeguards are required, commencing with the taking on of<br />

new staff until the termination of their employment.<br />

Personnel-related safeguards linked to a specific function, e.g.<br />

the appointment of a system administrator of a LAN, are<br />

listed in the <strong>IT</strong>-specific chapters.<br />

Threat Scenario<br />

In this Chapter, the following typical threats (T) are considered as regards <strong>IT</strong> baseline protection:<br />

Force Majeure<br />

- T 1.1 Loss of personnel<br />

Organisation deficiencies<br />

- T 2.2 Insufficient knowledge of requirements documents<br />

Human Failure:<br />

- T 3.1 Loss of data confidentiality/integrity as a result of <strong>IT</strong> user error<br />

- T 3.2 Negligent destroying of equipment or data<br />

- T 3.3 Non-compliance with <strong>IT</strong> security measures<br />

- T 3.8 Improper use of the <strong>IT</strong> system<br />

Deliberate Acts:<br />

- T 5.1 Manipulation/destruction of <strong>IT</strong> equipment or accessories<br />

- T 5.2 Manipulation of data or software<br />

- T 5.42 Social engineering<br />

Recommended Countermeasures (S)<br />

For the implementation of <strong>IT</strong> baseline protection, selection of the required packages of safeguards<br />

("modules") as described in chapters 2.3 and 2.4, is recommended.<br />

In the following, the safeguard package for "Personnel" is set out:<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!