19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.79 Secure access mechanisms for local<br />

administration<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

Some active network components can be administered via local access. Such<br />

local access is generally implemented by means of a serial interface (normally<br />

of type V.24 or EIA-232-E). <strong>The</strong> following measures must be observed to<br />

ensure secure local access:<br />

- <strong>The</strong> active network components and their periphery, such as connected<br />

terminals, must be installed securely (refer to S 1.29 Adequate siting of an<br />

<strong>IT</strong> system).<br />

- Local access for the purpose of administering local components must be<br />

disabled by means of software and / or hardware.<br />

- Any existing default password for local access must be modified<br />

immediately after putting the active network component into operation (for<br />

selection of a new password, refer to S 2.11 Provisions governing the use<br />

of passwords).<br />

- <strong>The</strong> security features of permanently connected terminals and computers,<br />

such as automatic screen lock and auto logout, must be activated (refer to S<br />

5.11 Blocking the server console and active network components).<br />

A local administration offers the following advantages:<br />

- <strong>The</strong> danger of intercepting passwords is reduced.<br />

- Administration is still possible after a failure of a network segment<br />

containing the active component, or after a failure of the entire network.<br />

A local administration has the following disadvantages:<br />

- As a rule, active network components can be configured such that they can<br />

be administered either locally or centrally. No general recommendations<br />

can be made concerning the selection of the appropriate configuration<br />

technique. However, it must be noted that if an exclusively local<br />

administration has been configured, central administration of the active<br />

network components is no longer possible. <strong>The</strong>se components must then<br />

always be administered directly on-site. This also increases reaction times<br />

in the event of a failure, as longer distances possibly need to be covered in<br />

order to reach the components.<br />

- Local access by means of a V.24 or EIA-232-E interface is generally<br />

slower than remote access via the network.<br />

Additional controls:<br />

- Have the default passwords for local access been replaced by secure ones?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!