S 2.455 Defining a security policy for Groupware

Initiation responsibility: Head of IT

Implementation responsibility: Administrator, IT Security Officer

Just like for any other client/server system used in a government agency or a company, a suitable security policy must also be defined for the use of groupware servers and clients. This security policy describes all regulations which must be observed by groupware administrators and groupware users.

It makes sense to divide the groupware security policy into a part for users and a part for administrators in order to be able to draw it up in a more understandable form. In the security policy for groupware, specifications must be made for users, for example:

Among other things, the groupware security policy for administrators should include the following aspects:

In the groupware security policy, it would be necessary to define, for instance, which users with which rights may access Microsoft Exchange objects when using Microsoft Exchange. Since Microsoft Exchange systems integrate very closely into the Windows environment, specifically into the Active Directory, the Windows security policy must be taken into consideration.

Review questions: