19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Personnel Remarks<br />

____________________________________________________________________ .........................................<br />

directories should never be approved with "all access rights". Ideally, they<br />

are user-defined with read and write privileges for other users<br />

Awareness of security<br />

- <strong>The</strong> user should be instructed in the security-relevant controls he must<br />

implement. He must also be informed of how the network monitor and log<br />

functions are to be used.<br />

- <strong>The</strong> use and exchange of passwords should be explained in accordance<br />

with the security strategy.<br />

- Under WfW and Windows 95 the user must be informed that<br />

- passwords for access to resources of other computers are stored in<br />

the file [username].pwl,<br />

- under WfW the resources of other WfW computers are entered in the<br />

file connect.dat, which are automatically connected when WfW is<br />

started,<br />

- the user's own resources are entered in the file shares.pwl, which are<br />

automatically shared when starting.<br />

<strong>The</strong>se files can be deleted by users without infringing the system integrity.<br />

This is particularly sensible for the file [username].pwl if passwords have<br />

accidentally been saved.<br />

- In the event that name conventions exist for the computers and users in the<br />

network, the users should be informed of these and any names which have<br />

already been allocated.<br />

Additional controls:<br />

- Have all users of the WfW network been sufficiently trained?<br />

- Are certain aspects of the awareness training repeated at irregular<br />

intervals?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!