19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.22 Prevention of loss of confidentiality of<br />

sensitive data in the UNIX system<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

With UNIX commands such as ps, finger, who and last, information can be<br />

obtained about a user (e.g. his work behaviour). Many UNIX derivatives<br />

contain additional commands which achieve the same effect under Solaris,<br />

e.g. listusers. Consideration should be given as to whether or not every user<br />

should be allowed to execute these commands (data privacy, unauthorised<br />

disclosure of log-in names, and the like). In case of doubt, access to these<br />

commands should be restricted.<br />

When commands are invoked, no sensitive information, e.g. a password,<br />

should be entered along with them as a parameter, as other users could view<br />

this entry via ps.<br />

If possible, log files such as wtmp, utmp, wtmpx, utmpx, should be protected<br />

against unauthorised reading through appropriate access rights, as a large<br />

amount of information about the users is contained in these files.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Restrict access to<br />

commands<br />

Do not enter passwords<br />

as command parameters

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!