19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- After three unsuccessful attempts to enter the correct password, a lockout<br />

should be imposed which can only be cancelled by the system<br />

administrator.<br />

- During authentication of networked systems, passwords should not be<br />

transmitted in an unencrypted form.<br />

- <strong>The</strong> password must be entered covertly, i.e. the input will not be displayed<br />

on the monitor.<br />

- Passwords should be stored in the system in a way preventing unauthorised<br />

access, e.g. by means of one-way encryption.<br />

- Password alteration must be initiated by the system on a regular basis.<br />

- Re-use of previous passwords in the case of password alteration should be<br />

prevented by the <strong>IT</strong> system (password history).<br />

Additional controls:<br />

- Have users been informed on how to handle passwords correctly?<br />

- Is the password quality controlled?<br />

- Are password changes mandatory?<br />

- Has every user been provided with a password?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!