19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

system control, are stored in the standing file called Profiles in the file<br />

NTUSER.DAT.<br />

<strong>The</strong> following options can be used under version 3.51, in order to restrict the<br />

capabilities of users for working with Windows NT in various respects:<br />

- Settings for Program Manager: It can be specified here whether programs<br />

may be started via “File - Execute“, whether the current settings may be<br />

stored and whether general program groups are listed. In addition, the autostart<br />

group can be determined.<br />

- Settings for program groups: Here, access to designated program groups<br />

can be locked out and for program groups which are not locked out,<br />

various amendment authorisations can be allocated.<br />

- Users can be allowed or forbidden to connect and disconnect network<br />

printers via Print Manager.<br />

- Waiting for the execution of the log-on script can be forced before Program<br />

Manager is started. This option should always be activated, so that the<br />

actions specified in the log-on script are performed in any event.<br />

As from version 4.0, the following restrictions can be laid down with the aid<br />

of System Policy Editor:<br />

- Control Panel: Here, access can be limited to the control panel option<br />

"Display". If this option was chosen, in addition the register cards<br />

"Background", "Screen Saver", "Appearance" and "Settings" can be still be<br />

masked individually, and the option "Display" can also be deactivated as a<br />

whole.<br />

Access to the control panel should be withdrawn from normal users, as<br />

unintentional changes to the system settings can cause problems. If, in<br />

addition, access to the control panel option "Display" and the register card<br />

"Screen Saver" is withdrawn, users can be prevented from deactivating the<br />

screen lock. <strong>The</strong>n, when setting up users, the administrator naturally has to<br />

activate the screen lock.<br />

- Shell: Here the following restrictions can be laid down:<br />

- Remove "Execute" command<br />

- Remove folder under Settings in the "Start" menu<br />

- Remove "Task bar" under settings in the "Start" menu<br />

- Remove "Find" command<br />

- Mask drives in the "My Computer" window<br />

- Mask network environment<br />

- No "Entire Network" symbol in the network environment<br />

- No workgroups computers in network environment<br />

- Mask all desktop components<br />

- Deactivate "Shut Down" command<br />

- Do not store settings when ending<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!