19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.55 Secure installation of Windows NT<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

Before installation of Windows NT, a number of observations should be made<br />

which are briefly outlined below.<br />

Secure system version<br />

Even during the process of acquisition, a decision must be made as to whether<br />

the English or German version of Windows is to be run. Furthermore, to be on<br />

the safe side, Windows NT must be operated from at least version 3.51<br />

onwards, together with the current version of Service Pack4 (also refer to S<br />

4.xx02 Reliable system versions of Windows NT). If an older Windows NT<br />

installation exists, this should, if possible, be updated to version 4 or at least to<br />

version 3.51.<br />

Partitions and file systems<br />

Alongside its own file system NTFS, Windows NT also supports the DOS file<br />

system FAT and the OS/2 file system HPFS. A large part of the settings<br />

relevant to security are, however, only valid under NTFS. when installing<br />

Windows NT, you should ensure that no HPFS or DOS partitions are created,<br />

as no access protection applies to them, with the result that such partitions can<br />

be misused to undermine the protection of Windows NT. Instead, all partitions<br />

must be formatted using the NTFS file system or, if earlier data is to be kept,<br />

they must be converted to this file system.<br />

However, support of the FAT file system for floppy disks is necessary as, due<br />

to its size, the NTFS file system cannot be accommodated on diskettes. For<br />

this reason, access to disk drives should be limited (see S 4.52 Equipment<br />

protection under Windows NT).<br />

Configuration of the log-on procedure<br />

At log-on, Windows NT usually displays the name of the last user who has<br />

logged in on the computer concerned. This display should be prevented by<br />

entering/changing the value "DontDisplayLastUserName" in the key<br />

"SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon" of the<br />

sector HKEY_LOCAL_MACHINE of the registry to the value REG_SZ = "1".<br />

In order to warn unauthorised users against illegal access to the system, before<br />

the actual log-on procedure a window containing an appropriate text should be<br />

displayed. This is achieved by inputting suitable wording into the two entries<br />

"LegalNoticeCaption" and "LegalNoticeText" in the key<br />

"SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon" of the<br />

sector HKEY_LOCAL_MACHINE of the registry.<br />

<strong>The</strong> relevant changes can be made with the help of Registry Editor (of the<br />

program REGEDT32.EXE in the Windows system directory<br />

%SystemRoot%\SYSTEM32). When doing this particular caution should be<br />

exercised, as incorrect settings in the registry can lead to a situation in which<br />

the system is no longer able to run. From version 4.0 of Windows NT<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!