HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 2.18 Inspection rounds

S 2.18 Inspection rounds

Initiation responsibility: Site/Bldg Technical Service; IT Security Management

Implementation responsibility: Site/Bldg Technical Service; IT Security Management

The effectiveness of any measure will always be commensurate to the enforcement of that measure. Inspection rounds offer the simplest means of monitoring the implementation of measures and the observance of requirements and instructions.

Inspection rounds should not be aimed at the detection of offenders for the purpose of punishing them. Rather, controls should be aimed primarily at remedying perceived negligence at the earliest time possible (closing windows, taking documents into custody, etc.). As a secondary objective, the causes of such carelessness can be identified and possibly avoided in future.

Inspection rounds should indeed also be made during office hours and be used to inform staff members about how and why pertinent regulations are being applied. Thus, they will be perceived by all persons concerned as a help rather than a hinderance.


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
July 1999
home