HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 2.184 Development of a RAS concept

S 2.184 Development of a RAS concept

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Head of IT Section, Administrator

Establishment of a RAS system requires that a RAS concept is developed after the requirements analysis has been performed (see safeguard S 2.183 Performing a RAS requirements analysis) and prior to technical implementation of the system. Essentially the concept specifies what RAS system architecture should be chosen and what rules should apply to use of the RAS system for all those concerned. The concept can be roughly broken down into three sub-areas.

  1. The organisational concept. This covers all matters which are of interest to the organisation in relation to the RAS system. Care should be taken to ensure that the RAS system is integrated into existing organisational processes so that their homogeneity and consistency are preserved.
  1. The technical concept. This specifies the technical implementation of the RAS system. The technical concept should cover the requirements which have been identified during the requirements analysis and, as far as is implementable, it should accommodate all the access scenarios that will be necessary. With regard to technical planning, the existing technical situation must be considered in order to avoid any technical incompatibilities.
  1. The security concept. This covers the security-relevant aspects of the RAS system. As security can generally only be assured through a combination of organisational and technical safeguards, the security concept should be specified separately and not just constitute a subsection within the organisational and technical concepts.

The essential questions which need to be answered in connection with each of the sub-areas are listed below. Depending on the particular situation, there may be a special, additional need for co-ordination that is tailored to the particular organisational and technical circumstances.

The organisational concept should address the following points:

The technical concept should address the following points:

The RAS security concept should address the following points:

The RAS requirements analysis and design will by its nature throw up specific requirements for the hardware and software components which should be used. These should be refined and made specific for procurement purposes, as described in safeguard S 2.186 Selection of a suitable RAS product.

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
October 2000
home