19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

Note: Data back-ups and the recovery of saved data should be carried out<br />

by a member of this group. For this it is not necessary to use an<br />

administrator account.<br />

- Print operators - <strong>The</strong> members of the local group "Print operators"<br />

defined on domain controllers can administrate printers on the domain<br />

controllers. <strong>The</strong>y can also log on to these servers and shut them down.<br />

Note: <strong>The</strong> administration of printers should be carried out by members of<br />

this group in order to avoid the unnecessary use of administrator accounts.<br />

- Server operators - <strong>The</strong> members of the local group "Server operators"<br />

defined on domain controllers can administrate the printer and network<br />

shares on the domain controllers. Furthermore, they can save and recover<br />

files and directories, block and release the domain controller, format the<br />

hard disks of the domain controller and alter the system time. Finally, they<br />

can also log onto the domain controller and shut it down.<br />

Note: Routine tasks involved in controlling the domain controllers should<br />

be carried out by members of this group, insofar as they can be carried out<br />

with the rights of this group. Only tasks which require full control over the<br />

system should be carried out from administrator accounts.<br />

- Replication operators - <strong>The</strong> local group "Replication operators" defined on<br />

computers under Windows NT supports the functions of directory<br />

replication. A domain user account used for logging on the replication<br />

service of the workstation should be the sole member of the group<br />

"Replication operators" .<br />

Note: No users accounts should be added to this group, and the user<br />

account present there should not have the rights "Local log-on" and<br />

"Access to this computer of the network".<br />

Special groups<br />

In addition to the above-mentioned pre-defined groups, Windows NT creates a<br />

number of special, internal groups which are not listed by User Manager. In a<br />

good many cases, however, they are listed in the group list, for example when<br />

permissions are assigned to directories, files, released network directories or<br />

printers.<br />

- Everyone - Everyone who works on the computer. Included here are all<br />

local and remote users (i.e. the groups "INTERACTIVE" and "NETWORK"<br />

put together). <strong>The</strong>y can access the network, connect with the shared<br />

network directories of the workstation and use the printer of the<br />

workstation.<br />

- INTERACTIVE - Everyone who works locally on the computer.<br />

- NETWORK - All users who are connected with this computer via the<br />

network.<br />

- SYSTEM - <strong>The</strong> operating system.<br />

- CREATOR-OWNER - <strong>The</strong> user who has created or owns the following: a<br />

directory, a file in a directory, a printer or a document that was sent to a<br />

printer.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!