19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- Create (only for containers)<br />

- Delete<br />

- Rename<br />

A user with these rights over another NDS object, for example another<br />

user, is able to sequentially browse, create, delete or rename user accounts.<br />

<strong>The</strong> Supervisor right includes all of the other four rights. <strong>The</strong> Browse,<br />

Create, Delete and Rename rights do not include any object property rights<br />

or file rights. One exception to this in this special case is the Supervisor<br />

right to an object. This right also incorporates Supervisor rights to the<br />

object properties.<br />

- Object property rights<br />

Object property rights control access by trustees to stored details<br />

concerning an object, i.e. the object properties. No object rights are<br />

required for this. With the exception of the object right Supervisor, rights<br />

to object properties cannot be obtained with object rights. As can be seen in<br />

the above figure, the object property rights are as follows:<br />

- Supervisor<br />

- Compare<br />

- Read<br />

- Write<br />

- Add Self<br />

<strong>The</strong> object property rights consist of the main rights Write and Read. <strong>The</strong><br />

right Read contains the right Compare and the right Write contains the<br />

right Add Self. <strong>The</strong> supervisor right is the combination of these four rights<br />

and does not have any other effects. With the right Read, object properties<br />

such as the user's properties surname or even the log-in script can be read.<br />

In order to make changes, the right Write is required. <strong>The</strong> right Compare<br />

allows queries to be made to the NDS, such as if the surname of user XY is<br />

Mustermann. <strong>The</strong> answer is then either "true" or "false". <strong>The</strong> right Add Self<br />

is only useful for objects with which users are able to enter themselves in a<br />

list, as is the case for a group. As an object often has numerous properties,<br />

there are two ways of allocating object properties. In principle, it is<br />

possible to allocate the same right for all properties. To do this, the option<br />

All Properties must be selected in the area Property Rights. On the other<br />

hand, it is also possible to allocate specific rights for particular object<br />

properties. This is done using the option Selected Properties. It must be<br />

noted that when the function Selected Properties is used, the rights that<br />

were allocated with the option All Properties are overwritten.<br />

Rights in the NDS must be allocated even more carefully than rights in the<br />

file system. In the file system, an NDS object receives rights to a file or a<br />

directory. In the NDS, however, an NDS object receives rights to another<br />

NDS object. In the process, it must be carefully checked who is actually to<br />

receive the right to who. For example, it may well happen that a user object<br />

is supposed to receive rights to a container object, but the container object<br />

is given rights to a user object.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!