19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

- “Enforce alphanumeric passwords“ should be set. Thus letter and numeral<br />

combinations become obligatory.<br />

- <strong>The</strong> options “Request confirmed log-on in Windows NT or LAN manager<br />

domain“ and “Allow caching of passcode words“ are not considered at this<br />

point as the interplay of WfW with Windows NT or LAN manager was not<br />

investigated.<br />

<strong>The</strong> administrator settings must be specified:<br />

- <strong>The</strong> administrator must specify a password for the created configuration<br />

file WFWSYS.CFG, which may only be known to himself and his<br />

substitute. This password must be deposited securely (cf. S 2.22 Depositing<br />

of Passwords).<br />

- Pre-set security profiles may be accepted from a server via “Update<br />

options“. Furthermore, it is also possible to set them so that at the start of a<br />

client, the security configuration file of the server is checked, and, in the<br />

event of changes, the local file is updated. This makes central<br />

administration of the WfW network, simple addition of further WfW<br />

computers and changing of the password for the configuration files easier<br />

for the WfW administrator.<br />

When configuring a Windows-for-Workgroups computer, the administrator<br />

also needs to consider the following points:<br />

- <strong>The</strong> pre-set option “Share again on startup“ must be deactivated in the<br />

sharing dialogues (file and print manager).<br />

- <strong>The</strong> pre-set option “Store password in password list“ must be deactivated<br />

in the connection dialogues (file and print manager).<br />

- In the program group SYSTEM CONTROL under network, the computer<br />

name, the name of the work group and the standard log-on name should be<br />

pre-set in accordance with the name convention.<br />

- <strong>The</strong> WfW protocol must be activated (in the program group SYSTEM<br />

CONTROL under network). In this case, all events should be recorded and<br />

the protocol file should be set up to be sufficiently large (e.g. 32 KB).<br />

- In the program group SYSTEM CONTROL under network, an option<br />

should be set up via the button start indicating whether the computer’s own<br />

applications or access by others should be treated with priority. If access by<br />

others is subordinate, priority in favour of more rapid execution should be<br />

selected.<br />

- During the use of Schedule+, the right granted by default to view open and<br />

assigned time blocks must be deactivated for all unauthorised WfW users.<br />

Otherwise every user at the same post office will be able to view individual<br />

appointments in the time schedule.<br />

If a post office is configured for use by several persons for the purpose of<br />

communications or joint appointment scheduling, a corresponding data<br />

backup should be performed at appropriate time intervals. This is required to<br />

prevent inadvertent or intentional deletion of the post office, which is not<br />

protected automatically under WfW.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!