Objet : Eurocopter international network with subisidiaries. Security

As all the Eurocopter plants will then be in the same network, we will have to apply common security rules in all the Eurocopter plants, especially for subsidiaries ...
95KB taille 6 téléchargements 344 vues
Marignane, 2001-09-26

Objet : Eurocopter international network with subisidiaries. Security rules and needed access control means We are currently working to connect the Eurocopter subsidiaries to the IT telecommunication data network of the Eurocopter Group, in order to develop a common information system and improve communication between all Eurocopter sites in the world. We bought a global service to a unique supplier, T-systems, subsidiary from Deutsche Telekom : this service includes network installation, lines encryption, backup lines, and end equipment management. As all the Eurocopter plants will then be in the same network, we will have to apply common security rules in all the Eurocopter plants, especially for subsidiaries which are connected to Internet. We must protect our internal network from unauthorized outside access and ensure confidentiality of business information exchange, with the same security level everywhere in our network. The security rules as listed in annex 1 should be applied to all the plants which are connected to the network. We describe in the technical annex 2, to be used by IT specialists, the technical systems which must be implemented to be compliant, and give a rough estimation of the costs in Euros for each system. These means depend on the way your site is currently connected to Internet. We defines three connection types : Type 1 : permanent two ways connection to Internet, inbound and outbound. Type 2 : permanent one way outbound connection to Internet Type 3 : Dial-up one way outbound connection to Internet The needed investments decrease from type 1 to type 3. Some of the required means can be already installed in your site and will need no extra costs, some are not and must be bought and installed. A here attached written commitment is requested to you, to commit yourself to be compliant with all the security rules at the dates specified. Please send back the signed commitment. . If you have questions, please contact Markus Steinke.

Copie(s) :

EUROCOPTER GROUP INTERNATIONAL IT NETWORK SECURITY RULES

1) Each Eurocopter Group entity is responsible for controlling his connection point and monitoring the activities on the network. The monitoring organization and means in each Eurocopter entity can be audited by Eurocopter Group security teams 2) The ECG entity is responsible for the accessors to the Eurocopter network. Accessors are submitted to individual authorization and to reinforced authentication system (ex : one session password). 3) The internal network must be isolated for Internet physically or through a filtering device (firewall or filtering router). 4) The link connecting each entity plants must be encrypted, using hardware or software from European origin (this is covered by Tsystems services). The encryption keys management must be done by Eurocopter or EADS security teams 5) In case of intrusion or serious incident affecting systems integrity or preventing correct operation the Eurocopter entity must inform Eurocopter Group security teams and other subsidiaries. 6) All electronic communication between Eurocopter entities should pass through the encrypted network and not through Internet.

I undersigned CEO of ……. , commit myself that all my plants which are or will be connected to the Eurocopter Group Wide Area network will be compliant with the following security rules as each Eurocopter entity plant : 1) Each Eurocopter entity is responsible for controlling his connection point and monitoring the activities on the network. The monitoring organization and means in each Eurocopter entity can be audited by Eurocopter Group security teams 2) Each Eurocopter entity is responsible for the accessors to the Eurocopter network. Accessors are submitted to individual authorization and to reinforced authentication system. 3) The Eurocopter entity internal network must be isolated for Internet physically or through a filtering device (firewall or filtering router). 4) The link connecting each Eurocopter entities plants must be encrypted, using hardware or software from European origin. The encryption keys management must be done by Eurocopter or EADS security teams 5) In case of intrusion or serious incident affecting systems integrity or preventing correct operation the Eurocopter entity must inform Eurocopter Group security teams and other subsidiaries. 6) All electronic communication between Eurocopter entities should pass through the encrypted network and not through Internet. Rules number 1 to 5 will be applied as soon as the Eurocopter entity is connected to the network. Rule number 6 will be applied before end 2002.

Signature