19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.172 Developing a concept for using the WWW<br />

Initiation responsibility: Agency/company management; <strong>IT</strong> Security<br />

Management<br />

Implementation responsibility: Head of <strong>IT</strong> Section, Administrator<br />

Before use is made of WWW services, a concept must first be drawn up<br />

describing which services are to be used and which are to be offered. This<br />

must include consideration of how the WWW server will be secured, as well<br />

as the WWW clients and the communication links between them.<br />

WWW servers can be used solely as an internal information database, as the<br />

central point of an intranet, or as an external WWW server that offers a variety<br />

of services. <strong>The</strong> security demands made of the WWW server also vary<br />

according to the form that the planned implementation is to take.<br />

In a small organisation in which a WWW server is operated as an intranet<br />

server with no critical applications, the requirements are quite different from<br />

those imposed on a WWW server that is to be connected to the Internet and<br />

perhaps even contains data that should not be retrievable by just anyone.<br />

If it is intended to offer WWW services both in the intranet and on the<br />

Internet, it is advisable to use two separate systems: one intranet WWW server<br />

and one Internet WWW server. If it is intended to connect the Internet WWW<br />

server to the internal network, the connection to the internal network must be<br />

protected by a firewall. Factors which have to be taken into account regarding<br />

the configuration of information servers are also described in S 2.77 Secure<br />

configuration of other components.<br />

<strong>The</strong> connection to the Internet can only be implemented when it has been<br />

checked that all risks can be handled by the chosen WWW concept and the<br />

personnel and organisational conditions.<br />

A WWW server used for an organisation’s Internet presence does not have to<br />

be operated by the organisation itself. If the running costs or administration<br />

costs are too high, or if the residual risks appear too incalculable, it is also<br />

possible to make use of the services of Internet service providers or other<br />

service companies and have them operate a WWW server.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!