19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

Note: <strong>The</strong> rights outlined above, which are allocated under Windows NT as<br />

standard, must all be reviewed separately with a view to determining whether<br />

they are compatible with the security strategy laid down (see S 2.91<br />

Determining a security strategy for the Windows NT client-server network).<br />

Thus, for example, the right “Access to this computer from the network“<br />

should be withdrawn from the group “Everyone“. Whether it is granted<br />

alternatively to the group “Users“ must be clarified in detail.<br />

<strong>The</strong> following pre-defined groups are available under Windows NT:<br />

- Administrators - <strong>The</strong> "Administrators" group is the most powerful group in<br />

Windows NT. <strong>The</strong> members of this group administrate the overall<br />

configuration of the system. <strong>The</strong> pre-defined "Administrator" user account<br />

is a member of the "Administrators" group. If a computer belongs to a<br />

domain, the "Domains admins" group is automatically a member of the<br />

"Administrators" group of this computer.<br />

Note: User accounts of this group should only be used for system<br />

management tasks which require full control over the system. Tasks which<br />

can be carried out under restricted rights should, if possible, be performed<br />

from user accounts which belong to one of the other groups, in order to<br />

reduce endangerment to the system from tasks with unrestricted rights. In<br />

particular, a user account which only belongs to the group "Users" or one<br />

or more freely-defined groups should be created for every administrator for<br />

performing daily routine tasks. <strong>The</strong> number of user accounts in the group<br />

"Administrators" should be kept as small as possible.<br />

Administrators are subject to normal access control and do not<br />

automatically have access to every file. Where required, an administrator<br />

can assume ownership of a file and thereby access it. However, in such a<br />

case the administrator cannot pass the file back to the original owner, as<br />

Windows NT does not provide a function for this purpose.<br />

- Domain admins - <strong>The</strong> global group "Domain admins" is a member of the<br />

local group of administrators for the domain in question and of the local<br />

groups of administrators of each computer in the domain, with the result<br />

that the domain administrators can administrate the domain controllers,<br />

every server and all other computers in the domain. <strong>The</strong> pre-defined<br />

administrator account of the domain controller is a member of the "Domain<br />

admins" group.<br />

- Power users - <strong>The</strong> local group "Power users" defined under Windows NT<br />

Workstation makes restricted administrative functions available to the user<br />

accounts of its members. A power user can share directories in the<br />

network, set the internal clock of the computer, install, share and<br />

administrate printers, and create general program groups. <strong>The</strong>y can create<br />

user accounts and groups, change or delete the user accounts and groups<br />

that they have created, and add or remove members from the groups<br />

"Power users", "Users" and "Guests".<br />

However, power users cannot change or delete the groups<br />

"Administrators", "Domain admins", "Accounts operators", "Back-up<br />

operators", "Print operators" and "Server operators", neither can they<br />

change or delete any administrators’ user accounts.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!