19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- CMIP requires roughly ten times as much system resources as SNMP. For<br />

this reason, it needs to be operated on powerful hardware which is only<br />

offered by a small number of active network components. <strong>The</strong> OSI<br />

protocol stack, which consumes additional resources, also needs to be<br />

implemented in general. CMOT constitutes an exception here.<br />

- Due to the complexity of this protocol and the corresponding<br />

implementations, CMIP is potentially more susceptible to errors than<br />

SNMP implementations.<br />

- Very few implementations of CMIP are presently available; except for in<br />

the area of telecommunications, this protocol is encountered very<br />

infrequently in practice.<br />

In each individual case, a detailed examination is required as to which<br />

network management protocol is suitable for the applications involved. In this<br />

context, the security requirements for the network management system need to<br />

be formulated and co-ordinated. If the TCP/IP protocol stack is already being<br />

used in the local network and the security requirements are low, it is advisable<br />

to employ SNMPv1. However, high security requirements could also call for<br />

the use of SNMPv2 or CMIP here. If the CMIP protocol is used, a<br />

consideration is required as to which protocol stack it should be used on, i.e.<br />

either the OSI stack (CMIP) or the TCP/IP stack (CMOT).<br />

Furthermore, it must be noted that CMIP and CMOT are presently not<br />

supported by all active network components and network management<br />

systems. Before a CMIP protocol is employed, a detailed check is therefore<br />

required as to whether the components and clients in use are CMIPcompatible.<br />

Additional controls:<br />

- Have the security requirements for the network management system been<br />

formulated and documented?<br />

- Have the active network components and clients been checked for<br />

compatibility with the selected SNMP version or CMIP?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!