19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

under which the s bit is ignored for the relevant file system. When<br />

exchangeable data media are used, consideration should be given as to<br />

whether to use this option.<br />

When sharing directories which can be mounted by other computers, the<br />

restrictions mentioned in S 5.17 Use of NFS security mechanisms must be<br />

observed. In particular, no directories with root rights should be shared;<br />

directories with write authority should only be shared when this is necessary.<br />

This measure is complemented by the following:<br />

- S 1.32 Adequate siting of the console, devices with exchangeable data<br />

media, and printers<br />

- S 4.18 Administrative and technical means to control access to the systemmonitor<br />

and single-user mode<br />

Additional controls:<br />

- Can the su command be executed only by the Administrator?<br />

- Is use of the su command automatically logged?<br />

- Who has write access to the relevant configuration files?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!