HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 6.8 Alert plan

S 6.8 Alert plan

Initiation responsibility: Agency/company management

Implementation responsibility: Head of IT Section; Head of Organisational Section; IT Security Management; staff responsible for the individual IT applications

An alert plan contains a description of the reporting channel through which the units/individuals concerned are to be notified when an emergency has occurred. The alert can be given, for instance, over the telephone, by fax, by paging systems, or by courier. It must be laid down who notifies whom, who is alternatively to be notified and what action should be taken if this person/unit cannot be contacted. For this purpose, address and telephone lists might have to be kept.

The alert plan must be available to all persons responsible for emergency procedures and, in addition, a redundant copy must be held centrally (e.g. entrance control staff, guards). The individuals listed in the alert plan must be familiar with the part concerning them. All staff members must know the contact persons to whom the occurrence of an incident, which might lead to an emergency, can be reported.

Different alert plans may have been established for different damaging incidents (fire, water, breakdown of data transmission). In that case, care must be taken to cover all types of incidents.

In addition to the compilation of an alert plan, the establishment of an on-duty service should be considered.

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
July 1999
home