19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.170 Requirements to be met by a system<br />

management system<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

<strong>The</strong> purpose of a system management system is to provide support to an<br />

administrator of a local network (or virtual local network). A system<br />

management system therefore has to satisfy certain prerequisites in order to be<br />

able to give the administrator appropriate support. <strong>The</strong> requirements that any<br />

such system has to meet, however, are substantially dependent on the planned<br />

use (see S 2.169 Developing a system management strategy) and on the<br />

chosen architecture of the system management system (see S 2.171 Selection<br />

of a suitable system management product).<br />

A system management system should provide the following functions:<br />

- User management<br />

This includes adding, changing and deleting user accounts and group<br />

accounts.<br />

- Policy management<br />

It should be possible to manage access rights both for access to and from<br />

the local network and for access to and from the Internet.<br />

- Software management<br />

<strong>The</strong> system management system should allow the addition, deletion and<br />

updating of software components.<br />

As well as this, the automatic detection of installed software may be<br />

important, especially during the introductory phase. Although the<br />

administration of software licenses would be desirable, this is rarely<br />

supported by today’s systems (see also application management below.<br />

Exception: licenses may be available in the form of files, so it may be<br />

possible to manage the license files within the framework of the file<br />

distribution mechanisms of a management system).<br />

- Determination, modification and administration of system configuration<br />

data<br />

- Administration of application data<br />

It must be possible to manage files in a database system or configuration<br />

files belonging to an application so as to allow the distribution of a new<br />

version of a database, for example, or the distribution of new configuration<br />

files.<br />

- Monitoring of system components<br />

This may also make sense for external components which are not subject to<br />

an administration system of their own, for example for the router of an<br />

Internet service provider (ISP) via which an Internet connection is<br />

implemented.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!