19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

invalid log-on attempts which lead to the lockout of the account, should be set<br />

to a figure between 3 and 10. <strong>The</strong> option "Reset count after", which specifies<br />

the maximum number of minutes (1 to 99999) between two invalid log-on<br />

attempts, should be set at approximately half an hour. If, for example, for<br />

"Lockout after" the figure 5 and for " Reset count after " the figure 30 is<br />

specified, a lockout occurs after 5 invalid log-on attempts made within a<br />

timeslot of 29 minutes.<br />

In general, by activating the option "Forever" it should be stipulated that<br />

lockout remains active until an administrator cancels it. Should this place too<br />

heavy a burden on the administrators, a suitable figure can also be specified<br />

as "Lockout duration", so that account lockout is only maintained for a limited<br />

period. If it is intended to investigate the causes of account lockout directly, a<br />

sufficiently long time interval, e.g. 1,440 minutes (1 day) should be specified,<br />

otherwise a figure of approximately 30 minutes should be chosen.<br />

In order to avoid complete locking of the system (see S 4.55 Secure<br />

Installation of Windows NT), it should be noted that the pre-defined<br />

administrator account is not included in this automatic lockout..<br />

<strong>The</strong> option "User must log on in order to change password" should not be<br />

activated. Together with the setting "User must change password on next log<br />

on" this would lead to new users having no access to the system.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!