19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

maintain confidentiality and integrity (see also S 5.64 Use of Secure Shell). It<br />

is also possible using tunnelling to operate ftp with secure encryption. If ssh is<br />

used, then if possible these services should be disabled to ensure that the<br />

security safeguards cannot be circumvented. However, this presupposes that<br />

all communication partners have suitable implementations of ssh.<br />

Additional controls:<br />

- Is the /etc/ftpusers file updated regularly?<br />

- Are access attempts via telnet, ftp and rexec logged?<br />

- Is ssh used to provide protection?<br />

- Is tftp disabled?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!