19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>IT</strong> <strong>Baseline</strong> <strong>Protection</strong> of Generic Components Contigenc Planning<br />

_________________________________________________________________________________________<br />

3.3 Contingency Planning<br />

Description<br />

Contingency planning comprises safeguards which, in case of<br />

failure (due to technical reasons, caused intentionally or as a<br />

result of negligence) of an <strong>IT</strong> system, are designed to restore<br />

its operating state. Depending on the time of implementation<br />

of these measures, contingency planning safeguards can be<br />

grouped into four stages:<br />

Stage 1: Contingency planning<br />

In this stage, the measures suitable and economically viable for a particular <strong>IT</strong> system are<br />

identified. It is determined which measures can be taken during operation of an <strong>IT</strong> system (e.g.<br />

smoking ban, uninterruptible power supply, service, data backup) so that an emergency situation is<br />

prevented and that damage resulting from an emergency situation is reduced. Furthermore,<br />

contingency plans, which are part of a contingency manual, stipulate which measures must be taken<br />

in case of an emergency.<br />

Stage 2: Implementing the contingency measures accompanying <strong>IT</strong> operation<br />

In stage 2, the contingency measures are implemented and maintained. <strong>The</strong>se must be carried out<br />

prior to an emergency situation in order to reduce the probability of an emergency or to allow swift<br />

and cost-effective restoration of the operating state.<br />

Stage 3: Emergency preparedness exercises<br />

Emergency drills are particularly important in connection with stage 2 in order to train the<br />

implementation of the measures listed in the Emergency <strong>Manual</strong> and to increase efficiency.<br />

Stage 4: Implementing planned measures after an emergency situation arises<br />

After it has been officially decided that an emergency situation is present, the measures set out in<br />

the Emergency <strong>Manual</strong> for this case must be implemented without delay.<br />

In order to be able to make contingency planning cost-effective, the costs incurred must be compared<br />

to the potential damage (costs due to a lack of availability in the event of an emergency) and assessed.<br />

<strong>The</strong> following costs should be considered:<br />

- Costs for compiling contingency planning<br />

- Costs for the implementation and maintenance of the safeguards accompanying <strong>IT</strong> operation<br />

- Costs for emergency drills<br />

- Costs for the restoration of the operating state<br />

_________________________________________________________________________________________<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Otober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!