19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 6.44 Data back-up under Windows NT<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong>-user<br />

Under Windows NT, data backup can be carried out with the service program<br />

NTBACKUP.EXE which is integrated into the system. It must be borne in<br />

mind that this program only supports backups onto tape and is not capable of<br />

encrypting the backup tapes these must, therefore, be securely stored in a safe<br />

place.<br />

When carrying out data backup, the following points must be taken into<br />

account:<br />

- Access rights to the Windows System directory %SysRoot%\SYSTEM32<br />

(usually \WINNT\SYSTEM32) are necessary for data backup since<br />

NTBACKUP stores temporary and log files there.<br />

- Back-up software is able to back up the registry of the local computer. This<br />

should be carried out at regular intervals and after significant changes to<br />

the configuration.<br />

- Quarter-inch tapes used for data backup should be wound up properly at<br />

regular intervals (after being used approximately 20 times) via the option<br />

"Wind Tape" to avoid loose sections and possible damage due to abrasion.<br />

This safeguard is not necessary for 4 mm (DAT) and 8 mm (Video 8)<br />

tapes; the appropriate operation is not available for these tapes.<br />

- When entering the option "Delete Tape", "Secure Deletion" should be<br />

selected if the tape contained valuable data as this will ensure that the old<br />

data is overwritten. If this option is not selected, a large portion of the data<br />

originally stored on the tape remains available and can be reconstructed<br />

without a great deal of effort.<br />

- When carrying out a backup operation the opportunity to create a log-file<br />

absolutely must be used. Once the operation is completed, the log-file can<br />

be used to check whether all the relevant data was really backed up or if<br />

any faults occurred during the backup. <strong>The</strong> option "Log all entries" is<br />

recommended, since it can thus also be determined if all relevant data was<br />

backed up and whether the directories to be backed up were, in fact,<br />

included in the backup.<br />

- When reproducing backed up files, their access protection will also be<br />

reproduced, given that the directory into which they are reproduced does<br />

not assert any explicit access controls on the files saved therein. If,<br />

however, such control is specified in the directory, this then applies to the<br />

files and the original access control information is ignored.<br />

- <strong>The</strong> choice of files and directories to be backed up cannot be saved under<br />

the graphic user interface. To regularly back up the same directories,<br />

Scripts can be created; these are, however, not designed for file selection.<br />

Due to the restrictions existing in the service program NTBACKUP.EXE,<br />

additional data backup software should be installed to ensure extensive<br />

installation or for high availability requirements. When selecting backup<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!