19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

runs of a virus detection programme). Whereas file viruses only represent a<br />

threat within a DOS emulation system, viruses which change the boot sector<br />

of Intel-based systems like PC’s can also be a threat to UNIX systems on Intel<br />

platforms; and the greatest danger to UNIX systems from computer viruses<br />

comes from PC’s which have mounted a UNIX system using NFS. Viruses<br />

which delete or alter files or directories on a PC can also access mounted<br />

directories and destroy them. So when opening directories for mounting, the<br />

access permissions must be allocated as restrictively as possible, in particular<br />

read-only access should be given for directories using the ro option (read<br />

only). Apart from this, users on UNIX should set the attributes for their files<br />

and directories as restrictively as possible, so that other users cannot access<br />

them, or so that no writing access is possible for files which are not regularly<br />

changed. This should be pre-set using an appropriate umask.<br />

Additional controls:<br />

- Are the permissions associated with NFS directories too wide-ranging?<br />

- Are network access points sufficiently protected (organisationally or<br />

technically)?<br />

- Are the RPC configuration files correctly set?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!