19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.175 Setting up a WWW server<br />

Initiation responsibility: Agency/company management<br />

Implementation responsibility: Head of <strong>IT</strong> Section, Administrator<br />

Commissioning a WWW server<br />

In order to set up a WWW server, in addition to appropriate hardware it is also<br />

necessary to procure corresponding software. A large number of products are<br />

available for this purpose. When the products are selected, apart from stability<br />

particular importance must be attached to the security mechanisms (for notes<br />

on procurement and installation see also Chapter 9.1 Standard software).<br />

Adapting the organisational structure<br />

Consideration must be given to what information is to be made available on<br />

the Internet or in an intranet. It is also necessary to clarify how and where<br />

documents are compiled, who produces which documents, which documents<br />

are used where, and who requires these documents. Guidelines on presenting a<br />

uniform identity for documents, file names and directory names should then<br />

be drawn up on the basis of these findings, and if possible standardised<br />

development tools should be specified.<br />

Nominating responsible personnel<br />

During operation of a WWW server, whether internally or externally, it should<br />

not be possible for every user to load files at will. One responsible member of<br />

staff should therefore be nominated for loading information, and this person<br />

should also check new files to ensure that they conform to the guidelines.<br />

Depending on the size of the organisation, other staff members can also be<br />

given subsidiary responsibility for individual organisational units or specific<br />

areas of the WWW server. <strong>The</strong> assignment of rights and the directory<br />

structure on the WWW server must also be specified in accordance with the<br />

chosen organisational structure. In particular, every person responsible for a<br />

subsection should have access only to those subdirectories which they are<br />

managing.<br />

In order to ensure that the files and directories that are created always meet the<br />

respective guidelines, observance of the guidelines should be checked<br />

automatically, for example using appropriate scripts or macros. A prepared<br />

program should be made available to everyone, and should be invoked every<br />

time a change is made. Particular attention should be paid to checking the<br />

following points:<br />

- Whether the access rights have been correctly set for all directories<br />

- Whether the access rights have been correctly set for all files<br />

- Whether the access rights have been correctly set for all CGI scripts (if set<br />

up)<br />

A file detailing the changes that have been made should also be generated<br />

directly.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!