19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.53 Restrictive allocation of access rights to files<br />

and directories underWindows NT<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

Under Windows NT, a distinction is made between access rights at the share<br />

level, and access rights at the file and directory level, termed NTFS rights in<br />

the following. Access rights at the share level are described in S 2.94 Sharing<br />

of directories under Windows NT.<br />

As opposed to share rights, access rights at the file and directory level are only<br />

available on data media with the NTFS file system. As a rule, these rights are<br />

assigned by the creator or owner of an object (directory or file). On servers,<br />

this is usually done by the administrator. Under Windows NT 4.0, NTFS<br />

permissions are granted typically using the Windows NT Explorer or "My<br />

Computer" desktop symbol. <strong>The</strong> menu item designated "Attributes / Security"<br />

is to be selected in the context menu of the related directory or file. <strong>The</strong><br />

following access control list is then invoked:<br />

Under Windows NT 3.51, the access control list is to be found under "Security<br />

/ Authorisations" in the File Manager. Existing user groups and users can be<br />

added to this list; furthermore, rights can be granted to, and withdrawn from,<br />

every user group and user here. It is also possible to remove user groups and<br />

users from the access control list. By activating the option labelled "Replace<br />

permissions on existing files", the rights specified for the directory can be<br />

transferred to all the files located therein. If the option labelled "Replace<br />

permissions on subdirectories" is selected, the specified rights are also<br />

transferred to all subdirectories. This allows easy realisation of standard<br />

permission profiles.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!