19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

Access Control List (ACL)<br />

<strong>The</strong> information regarding which users can access an object and its properties<br />

and what rights they have is stored in the object itself. For this purpose, every<br />

object has a special property: Access Control List (ACL).<br />

<strong>The</strong> ACL property contains the Trustee Assignments and the Inherited Rights<br />

Filter. Every object entered in the ACL can have other Trustee Assignments. In<br />

the file system, the ACL and the IRF are stored in the Directory Entry Table<br />

(DET).<br />

Allocation of access rights to directories and files<br />

Besides granting access rights to users and groups for files and directories, the<br />

allocation of Netware-Attributes to files and directories can increase data<br />

security. Attributes are always bound to a file or directory and never to NDS-<br />

Objects. <strong>The</strong>se objects are independent of the assigned access rights and are<br />

valid for all users including administrators.<br />

Users, who have been granted the "Modify" (M) privilege for the files and<br />

directories concerned, can change the Netware-Attributes and thereby carry<br />

out every action permitted by their effective privileges.<br />

By installing Netware-Attributes, security takes the form of a subsystem in file<br />

and directory security. This means that, although users have the ER to delete a<br />

file, they may not be able to do this because the attribute "Delete inhibit" (Di)<br />

has been set.<br />

When allocating Netware-Attributes to files and directories, the following<br />

properties of Netware-Attributes should be taken into account.<br />

- Directory Attributes:<br />

Delete Inhibit (Di): <strong>The</strong> directory cannot be deleted.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!