19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.100 Secure operation of Novell Netware servers<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

Secure operation of a Novell Netware network requires various actions which<br />

are listed below:<br />

Allocation of access rights to directories and files<br />

<strong>The</strong> allocation of access rights (Trustee Assignments) to files and directories<br />

on Novell Netware servers plays a central role in the security of Novell<br />

Netware servers.<br />

In contrast to the assignment of attributes, Trustee Assignments are assigned<br />

to individual users or user groups.<br />

Directories and files can be assigned to specific tasks via the access rights.<br />

This ensures that user groups and users are only granted access to the<br />

directories and files which they require for performing their respective tasks.<br />

For a clearer overview, easier administration and improved auditing<br />

capability, access rights should be assigned primarily to user groups.<br />

To prevent accidental release of directories by users, system administration<br />

should ensure that the directories allocated to users and user groups do not<br />

contain "Supervisory" (S) and "Access Control" (A) privileges.<br />

If certain properties (e.g. write-protected files) are allocated to files or<br />

directories with the help of Netware Attributes, attention should be paid to the<br />

fact that users possessing the "Modify" (M) privilege for the corresponding<br />

files and directories are able to change these attributes. <strong>The</strong> number of users<br />

with this access right should thus be restricted (see below Allocation of<br />

Netware Attributes to files and directories).<br />

Allocation of access rights to directories and files<br />

Besides granting access rights to users and groups for files and directories, the<br />

allocation of Netware-Attributes to files and directories can increase data<br />

security. Attributes always concern files or directories, i.e. they are<br />

independent of the allocated access rights and are valid for all users including<br />

the supervisor.<br />

Users, who have been granted the "Modify (M)" privilege for the files and<br />

directories concerned, can change the Netware-Attributes and thereby carry<br />

out every action permitted by their effective privileges.<br />

By installing Netware-Attributes, security will take the form of a subsystem in<br />

file and directory security.<br />

When allocating Netware-Attributes to files and directories, the following<br />

properties of Netware-Attributes should be taken into account.<br />

- Directory Attributes:<br />

Hidden (H): <strong>The</strong> directory will be labelled as hidden; it will not show up<br />

in a contents list under DOS, neither can it be copied or deleted.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!