S 2.358 Documenting the system settings of storage systems

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator

The documentation of the system settings for the storage system provides verification that the technical and organisational specifications were implemented and describes the custom configuration for the organisation. The documentation forms the basis for administration during normal operations and for planning and implementing changes. In addition, correct and up-to-date documentation forms the basis of contingency planning.

Data relevant in an emergency must be accessible in all emergency scenarios. Remember, though, that information on the system settings is confidential and must therefore be protected accordingly against unauthorised access.

The following information in particular must be documented:

Organisation:

Technology:

Administration:

The organisational documentation should be checked regularly (at least every 6 months) to see if it reflects the actual rights assignments and if the rights assignments still meet the security requirements and are appropriate for the tasks currently performed by the users.

The technical documentation (or at least samples of the documentation) should be checked more often since it forms the basis for contingency planning.

Review questions: