19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

hierarchy by the application of established criteria. <strong>The</strong> information security<br />

authorities of several countries have each set up a national certification<br />

scheme according to these criteria.<br />

<strong>The</strong> use of a certified product provides a guarantee that the security<br />

functionality of the product has been independently tested and does not fall<br />

below the standard specified in the evaluation level (see also S 2.66<br />

Consideration of the contribution of certification to procurement).<br />

Imported products<br />

In several countries, especially in the USA, the export of strong cryptography<br />

is at present (still) subject to severe restrictions. In particular, the strength of<br />

essentially strong encryption products is artificially diminished (by reducing<br />

the number of possible keys). <strong>The</strong>se artificially weakened procedures do not<br />

generally reach the mechanism strength necessary for medium-level protection<br />

requirements.<br />

In Germany and most other countries, cryptographic products are not subject<br />

to any restrictions when used within the national boundaries. When imported<br />

products are used, attention should always be paid to whether they provide the<br />

full range and scope of capabilities.<br />

Transnational use<br />

Many companies and agencies are increasingly faced with the problem that<br />

they also want to secure their international communications, for example with<br />

overseas subsidiaries, by cryptographic means. First it is necessary to examine<br />

the following points:<br />

- Whether restrictions on the use of cryptographic products have to be<br />

observed in the countries concerned<br />

- Whether any export or import restrictions applying to products under<br />

consideration have to be observed<br />

Security against improper use and malfunctions<br />

<strong>The</strong> dangerous aspect of cryptographic products is that they lull users into a<br />

(sometimes false) sense of security: no problem: it’s all encrypted"! This is<br />

why measures against being compromised as a result of operating errors or<br />

technical failure are particularly important, because their consequences cannot<br />

be limited to a simple defect but may immediately lead to a security breach.<br />

However, there is a large range in terms of redundant system design and<br />

additional monitoring functions - and hence equipment costs - so that in this<br />

regard the measures have to be determined in each individual case, in<br />

accordance with requirements.<br />

Implementation in software, firmware or hardware<br />

Cryptographic algorithms can be implemented in software, firmware or<br />

hardware. Software implementations are usually controlled by the operating<br />

system of the respective <strong>IT</strong> system. <strong>The</strong> term firmware covers programs and<br />

data which are permanently stored in hardware in such a way that the stored<br />

contents cannot be dynamically altered, nor can they be modified during<br />

execution. Hardware solutions entail the implementation of cryptographic<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!