19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

structure, the rights are inherited from this position in the tree. <strong>The</strong>re is an<br />

exception to this: rights which are allocated selectively to object properties<br />

(Selected Properties) are not inherited.<br />

Example 1:<br />

SYS: RZenk [Read; File Scan]<br />

PUBLIC<br />

NWADMIN.EXE<br />

NDIR.EXE<br />

If the user RZenk is granted [Read; File Scan] rights to the SYS: volume,<br />

these rights are in this case also inherited to the PUBLIC directory and the<br />

NWADMIN.EXE and NDIR.EXE files contained in PUBLIC. It is also possible<br />

to restrict the inheritance of certain rights. This is done using the Inherited<br />

Rights Filters (IRF), which are discussed below. In the basic state, no rights<br />

are filtered. <strong>The</strong>re is another mechanism which prevents inheritance. If the<br />

same NDS object is assigned the same right again further down in the tree, the<br />

original rights that the object received further up in the tree are no longer<br />

inherited from this point.<br />

Example 2:<br />

SYS: RZenk [Read; File Scan]<br />

PUBLIC<br />

NWADMIN.EXE RZenk [Write]<br />

NDIR.EXE<br />

In example 2, the user RZenk only has the right [Write] for the file<br />

NWADMIN.EXE as the rights [Read; File Scan] of the user RZenk are not<br />

inherited to the file NWADMIN.EXE. All other NDS objects which may have<br />

received rights to the file NWADMIN.EXE are not affected by this. Even the<br />

rights which the user RZenk receives for the file NWADMIN.EXE via other<br />

mechanisms, such as groups, containers, etc., are not restricted by this. <strong>The</strong>se<br />

rights are, therefore, additive.<br />

Inherited Rights Filters (IRF)<br />

While trustee assignments grant access to an object, an object property, a file or<br />

a directory, an IRF prevents rights being inherited from an object, an object<br />

property, a file or a directory to other NDS objects, files or directories in the<br />

tree. Each object, object property, file and directory in an NDS directory or file<br />

system can have a different IRF.<br />

<strong>The</strong> only difference between the NDS and the file system concerns the right<br />

Supervisor. This right can only be filtered in the NDS. In the file system, on the<br />

other hand, this right can no longer be filtered once it has been assigned.<br />

Effective rights<br />

<strong>The</strong> combination of an Inherited Rights Filter, Trustee Assignment and Security<br />

Equivalences is called effective rights (ER). <strong>The</strong> effective rights which an NDS<br />

object has to another NDS object or its property, as well as the effective rights<br />

which an NDS object has to the file system, can be specified with the program<br />

Netware Administrator (see also previous diagrams).<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!