19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

Hidden (H): <strong>The</strong> file will be labelled as hidden; it will not show up in a<br />

contents list under DOS, neither can it be copied or deleted. I<br />

System (S): This file (e.g. bindery Files -NET$OBJ.SYS, NET$PROP.SYS,<br />

NET$VAL.SYS) is used by the network operating system; it will not show<br />

up in a contents list under DOS, it can neither be copied nor deleted.<br />

Backup of important system files<br />

<strong>The</strong> server start files AUTOEXEC.NCF and STARTUP.NCF should be saved<br />

by the system administrator in their respective present versions on secured and<br />

stored in a safe place secured against unauthorised access. It is wise to<br />

supplement these files with comments so that the respective set parameters<br />

can be understood when problems arise.<br />

Furthermore, the bindery (NET$OBJ.SYS, NET$PROP.SYS, NET$VAL.SYS) of<br />

a Novell Netware server should be regularly backed up with the help of the<br />

SYS:SYSTEM\BINDFIX.EXE program. <strong>The</strong> backed up bindery<br />

(SYS:SYSTEM\*.OLD) should then be saved on a data medium and stored in a<br />

safe place secured against unauthorised access.<br />

In any case, after executing SYS:SYSTEM\BINDFIX.EXE the integrity of the<br />

new bindery should be tested. If in doubt, the old bindery can be restored with<br />

the help of SYS:SYSTEM\BINDREST.EXE.<br />

User access to the present bindery is withdrawn during execution of<br />

SYS:SYSTEM\BINDFIX.EXE. For reasons of operational security, no user,<br />

apart from a supervisor or an equivalent-to-a-supervisor user, should be<br />

logged on to the Novell Netware server when backing up the server bindery.<br />

Restricted use of a supervisor or an-equivalent-to-a-supervisor account<br />

<strong>The</strong> supervisor account should not be used for daily administrative tasks.<br />

Rather, it should only be used in case of emergency. Nonetheless, to ensure<br />

system administration, an equivalent-to-a -supervisor account should be set<br />

up for every user with the "supervisor" network security level, with which the<br />

system administration is normally be carried out. If administrative tasks are<br />

not performed on a full-time basis, additional accounts need to be created<br />

specifically for each non-administrative activity.<br />

Furthermore, a supervisor or an equivalent-to-a-supervisor account should<br />

only be used on the workstations defined for that purpose, since under some<br />

circumstances the integrity of other workstations can be manipulated by users.<br />

Delegation of system administration<br />

In larger networks (many Novell Netware servers or various locations) or with<br />

a large number of users, delegation of certain system administration tasks is<br />

recommended. For this purpose Novell Netware 3.x offers the possibility of<br />

assigning users with user-account-manager or workgroup-manager accounts.<br />

User-account-managers can administrate users and groups which have been<br />

allocated to them by the system administrator. Thus, besides being able to<br />

alter user-data (password, operating time, etc.) they can pass on all the<br />

privileges which they themselves possess. Furthermore, user-account<br />

managers may allocate individual users to a group. In this case, the groups as<br />

well as the users must be administrated by the respective user-account-<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!