Top Management

INF.1

INF.1 General Building

A building encloses all stationary workplaces, the information processed therein, and the installed information technology. It thus provides …

ISMS.1

ISMS.1 Security Management

(Information) security management refers to the planning, control, and oversight tasks required to establish and continuously implement a …

ORP.1

ORP.1 Organisation

Every institution requires a responsible department to manage and regulate general operations and to plan, organise, and carry out administrative …

OPS.1.2.2

OPS.1.2.2 Archiving

Archiving plays a special role in the document management process. On the one hand, it is expected that digital documents will be available until the …

CON.2

CON.2 Data Protection

Unlike information security, which primarily serves to protect the data-processing institution itself, the task of data protection is to protect …

DER.2.1

DER.2.1 Security Incident Handling

To limit damage and prevent further harm, detected security incidents must be handled quickly and efficiently. To this end, a predefined and tested …

DER.2.2

DER.2.2 Precautions for IT Forensics

IT forensics is the strictly methodical analysis of data on storage media and in data networks to investigate security incidents in IT systems.

OPS.2.2

OPS.2.2 Cloud Use

Cloud computing refers to the demand-driven provision, use, and billing of IT services over a network. The range of services offered within the …

ORP.3

ORP.3 Information Security Awareness and Training

Employees are an important success factor for a high level of information security in an institution. It is therefore important that they know the …

DER.3.1

DER.3.1 Audits and Revisions

Audits and revisions are fundamental to every successful information security management system (ISMS). Only if established security measures and …

DER.3.2

DER.3.2 Revisions Based on the IS Revision Guide

A special form of revision is the information security revision (IS revision) based on the document Information Security Revision - A Guide for IS …

DER.4

DER.4 Emergency Management

In emergencies, institutions must continue to be able to access information in order to restore a business process, an IT system, or a specialist …

ORP.5

ORP.5 Compliance Management (Requirements Management)

Every institution has relevant statutory, contractual, and other requirements, such as internal policies, that must be observed. Many of these …

INF.13

INF.13 Technical Building Management

Building management (BM), also known as facility management, is responsible for all services arising during the planning and operational phases of …