19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.48 Password protection under Windows NT<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

For each user, access to a Windows NT system must be protected by a<br />

password. User accounts without a password are not allowed to exist, as they<br />

constitute a potential weakness in the system. It is important that users too are<br />

familiar with the protective function of the passwords, since the co-operation<br />

of users naturally contributes to the security of the overall system.<br />

Setting up a new user is performed with the aid of the utility User Manager via<br />

the command "New User". At the same time an initial password with a<br />

maximum of 14 characters must be entered in the fields "Password" and<br />

"Confirm Password". For passwords under Windows NT, the use of upper and<br />

lower case letters must be observed. A meaningful initial password should be<br />

allocated which is notified to the user. Always choosing the same initial<br />

password or making this password identical to the user name opens up a<br />

security gap which can be avoided with a little effort.<br />

<strong>The</strong> option "User Must Change Password At Next Log-On" should be set with<br />

all new accounts, so that the log-on password is not retained. On the other<br />

hand, the option "User Cannot Change Password" should only be used in<br />

exceptional cases, for instance for pre-defined accounts in the training<br />

operation. <strong>The</strong> option "Password Never Expires" should only be used for user<br />

accounts to which a service is assigned with the aid of the system control<br />

option "Services" ( the reproduction service, for example), as it cancels the<br />

setting "Maximum Password Age" in the Accounts Policy and prevents the<br />

password from expiring.<br />

Policy for user accounts, user rights and system monitoring can be stipulated<br />

via User Manager. In the User Accounts Policy the figure 6 should be entered<br />

as the minimum password length, for higher security requirements the figure 8<br />

should be entered (see also S 2.11 “Provisions governing the use of<br />

passwords“).<br />

Password history should always be activated and should include at least 6<br />

passwords. <strong>The</strong> duration of validity of the password ("Maximum Password<br />

Duration") should be limited to a maximum period of 6 months. By fixing a<br />

figure for "Minimum Password Duration", users can be prevented from<br />

changing their password several times in a row with the object of by-passing<br />

history validation. However, a period greater than 1 day should not be chosen<br />

for “Minimum Password Duration“, in order to enable the user to change a<br />

password at any time.<br />

Note: <strong>The</strong> parameter "Allow Changes Immediately" must not be chosen under<br />

version 3.51 of Windows NT, as otherwise validation of password history is<br />

deactivated.<br />

User accounts should be locked out following repeated invalid password<br />

entries, in order to make attempts to guess the passwords of users more<br />

difficult. <strong>The</strong> option "Account lockout" should in any case be activated. At the<br />

same time the option "Lockout after", which fixes the number (1 to 999) of<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!