19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.168 <strong>IT</strong> system analysis before the introduction of<br />

a system management system<br />

Initiation responsibility: Head of <strong>IT</strong> Section<br />

Implementation responsibility: Administrators<br />

Before a system management system is introduced, the <strong>IT</strong> systems that are to<br />

be administered in future must be examined and analysed. <strong>The</strong> resulting<br />

system documentation can then be used as a basis for planning and decisionmaking<br />

for the system management strategy being defined (see S 2.169) . It is<br />

important that if possible all relevant information about the administered<br />

systems should be available at the planning stage so as to rule out the<br />

possibility of wrong decisions being taken because of a lack of information.<br />

Specific requirements that have to be met by the management system being<br />

purchased can also be formulated on the basis of the local circumstances (K.O.<br />

criteria).<br />

<strong>The</strong> following measures (and subsidiary measures described with them) have<br />

to be taken, ideally during planning and during ongoing operation of the<br />

system in accordance with the <strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>:<br />

- Survey of the existing network environment (see S 2.139)<br />

- Documentation of the system configuration (see S 2.25): All <strong>IT</strong> systems<br />

should be recorded and documented. Especially in heterogeneous systems,<br />

for example, details of all operating systems in use must be noted so as to<br />

be able to formulate the requirements that the management system has to<br />

satisfy.<br />

- Determining and reviewing the software inventory (see S 2.10): If the<br />

system management tasks are also to include the administration of software<br />

(application management), an inventory should be taken at this stage.<br />

Alternatively, automatic establishment of the software inventory<br />

("autodiscovery", "software discovery") can be formulated as a<br />

requirement for the management system . Which of the two variants is<br />

required in each individual case is dependent on the duties to be performed<br />

in software management. For example, if the management system is<br />

acquired for the purpose of automatic management of an existing software<br />

inventory whose composition is not entirely known (because of software<br />

updates or new software being loaded), the management system must be<br />

capable of detecting the software inventory automatically after it is<br />

installed. If individual software packages are also to be administered at the<br />

application level within the framework of application management, it is<br />

necessary to examine whether the software actively supports this (for<br />

example with a suitable protocol), which means that a prior inventory of<br />

the existing software is required. Requirements then arise as to the<br />

functional scope of the management system being acquired (such as<br />

support for the application administration protocol). If a Web server is to<br />

be administered via an HTTP-based management interface, for example,<br />

the management system must have HTTP-based management functions<br />

itself or provide an expansion interface which allows the integration of<br />

your own developments.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!