
IT Security Models
IT security models – why?
Many companies and organizations do not want their information to fall into the wrong hands. Legal requirements demand the use of adequate security measures.
Quite obviously, it is not easy to fulfill these demands due to often complex company structures and many information paths.
The German Federal Office for Information Security (BSI) provides criteria for IT security analysis and corresponding measures, which make up the appropriate IT model.
IT security for the military
A detailed security analysis is required for newly planned projects in the military field as well, especially considering current threats. For military projects, however, stricter and more complex regulations have to be observed in comparison to civil projects. A project-related IT security model must be designed during the conception stage of a system and must be adapted and improved until the system is introduced.
CONDOK designs project-related IT security models for you
With the project-related IT security model the necessary security requirements are identified for the stored, processed and transmitted data and information of the technical system and, if given, its software. These requirements are determined regarding confidentiality, integrity, bindingness and availabilty. Based on this analysis, the project is assigned to a certain security class, which determines IT security requirements and security measures to be taken.
The following aspects of the technical system are analyzed:
- Technology
- Organization
- Staff
- Infrastructure / material
When security measures are determined, a test regarding their cost effectiveness and a project-specific risk analysis are carried out. Afterwards, it can be decided if the remaining risk is tolerable. Furthermore, the possible material and/or immaterial damage without the IT security measures is calculated and lower-cost alternatives are searched for.
Every IT security model includes an emergency plan, which describes how system functionality can be restored after a system breakdown.
The corresponding security measures can already be considered during the system planning stage, e.g. when developing realization and installation concepts.

IT Security Models








