OW5000 System Security Guidelines - NEC Corporation of America
OW5000 System Security Guidelines - NEC Corporation of America
OW5000 System Security Guidelines - NEC Corporation of America
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
4-14Securing the DatabaseChapter TopicsThe database is a vital component <strong>of</strong> the <strong>OW5000</strong> <strong>System</strong> and to yourorganization. Sensitive data related to users, phones, and hardware isstored in a database. A hacker can use this data to launch a maliciousattack against your organization.Any database server that is not kept up-to-date with the latest securitypatches and critical updates can become infected with a worm.A worm attacks vulnerabilities in database applications, which cancripple your network and render your hardware useless. To avoid thistype <strong>of</strong> attack, check nightly for s<strong>of</strong>tware updates and enforce strongpasswords for all system administrator accounts.The <strong>OW5000</strong> supports the following SQL Servers:. Micros<strong>of</strong>t SQL Server 2005 Express Edition SP2 or later. Micros<strong>of</strong>t SQL Server 2005 Standard Edition SP2 or later. Micros<strong>of</strong>t SQL Server 2008 Express Edition SP1. Micros<strong>of</strong>t SQL Server 2008 Standard Edition SP1• SQL Installation and Settings• Backup and RecoverySQL Installation and Settings<strong>System</strong> Administrator (sa) Passwords<strong>System</strong> Administrator (sa) passwords are the main line <strong>of</strong> defenseagainst hackers and malicious s<strong>of</strong>tware. Hackers can access freeprograms designed to guess a sa password. The program generates testpasswords using a combination <strong>of</strong> common words and numbers to gainaccess to the server.Complex passwords are much more secure. Never, under anycircumstance, use a blank sa password.IMPORTANTNever use example passwords found in installation manuals. For instance, do notuse the example sa password, Ow5000db1!, found in the <strong>OW5000</strong> InstallationGuide.UCE Application Platform (UNIVERGE <strong>OW5000</strong>) <strong>System</strong> <strong>Security</strong> <strong>Guidelines</strong> - Revision 7