19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

Care must be exercised here, as faulty settings in the registry might impair the<br />

operability of the system, thus preventing it from starting up properly the next<br />

time. Consequently, the settings mentioned here should first be used in a<br />

separate test system and checked critically for proper functionality under real<br />

conditions before being put into regular operation.<br />

Network access to the registry<br />

Access to the registry via the network should be disabled, unless this function<br />

is absolutely necessary. This is allowed by version 4.0 or higher, by setting the<br />

entry "winreg" in the key<br />

\System\CurrentControlSet\Control\SecurePipeServers in the area<br />

HKEY_LOCAL_MACHINE to the value REG_DWORD = 1.<br />

Version 3.x does not allow an explicit blockage of the registry against network<br />

access. In this case, it is helpful to withdraw the right of "All" to access the<br />

root of the area HKEY_LOCAL_MACHINE (but not the underlying keys!), so<br />

that only administrators have access to this area. This modification must, on<br />

all accounts, be checked in a test system as it could paralyse certain<br />

applications. It must be noted that such a change only remains effective until<br />

the system is restarted.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!