19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Personnel Remarks<br />

____________________________________________________________________ .........................................<br />

S 3.19 Instructions concerning the correct use of the<br />

security functions in Peer-to-Peer networks<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong> Security Management, Administrators<br />

Instructions concerning the correct use of security functions are particularly<br />

important in Peer-to-Peer networks under WfW and Windows 95, where the<br />

users themselves have to carry out security tasks. Each user must therefore be<br />

trained in advance regarding the following points:<br />

Data exchange using shared directories<br />

- <strong>The</strong> user must be trained in the correct use of the sharing of resources and<br />

the correct cancellation of directory sharing. Particular emphasis should be<br />

placed on the possibility of concealing shared directories or printers by<br />

adding the character "$" so that other users cannot see that sharing has<br />

been granted. It should be pointed out that the incentive for attacks can be<br />

reduced if share names are used which do not provide information on the<br />

contents and if resources are only shared for as long as required.<br />

- <strong>The</strong> meaning of the options when sharing or connecting directories or<br />

printers should be made clear and the adherence to the various settings<br />

pointed out:<br />

"share on start-up" automatic sharing when WfW is started,<br />

without user interaction<br />

"Connect on start-up" automatic connection when restarting<br />

"Save password in the password<br />

list"<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Storing of the password (critical to<br />

security) so that it does not have to be<br />

re-entered when connecting the next<br />

time<br />

Users of Windows 95 and Windows NT must take note that every enabled<br />

share must explicitly be undone, otherwise it will still apply after a restart<br />

- <strong>The</strong> names of the access rights under WfW and Windows 95 are not self<br />

explanatory and have to be explained:<br />

"Write-protected access" Right to read files and execute<br />

programs<br />

"Read/write access" Right to read/write files, execute<br />

programs, create and delete files<br />

"Access dependent on password" <strong>The</strong> right to read and write files can be<br />

granted separately<br />

Within Windows 95 all users can choose between the rights "writeprotected<br />

access", "all access rights" and "user-defined" if access<br />

protection is implemented at the user level. Users must then be notified that

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!