19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

rights to an NDS object, they automatically have supervisor rights to the NDS<br />

object properties as well. This phenomenon does not occur the other way<br />

round. Supervisor rights for NDS object properties are not equivalent to<br />

Supervisor rights for the NDS object itself. In must be borne in mind in this<br />

context, however, that the object property Object Trustees (ACL) is a property<br />

of each and every NDS object. If users receive supervisor rights for the<br />

properties of an NDS object or simply the right WR<strong>IT</strong>E for the property Object<br />

Trustees (ACL), they are able to grant themselves or other NDS objects any<br />

rights they choose. An important exception is the NDS object Server. If, as in<br />

the above example, the user Rzenk receives the right WR<strong>IT</strong>E for the object<br />

property Object Trustees (ACL) of the server, this is the same as receiving<br />

supervisor rights for the entire file system that is assigned to this server. <strong>The</strong><br />

property Object Trustees (ACL) of the server is therefore the interface between<br />

the NDS and the file system.<br />

Menu diagram: Netware Administrator Server NW4_GT "Trustee of this<br />

Object..."<br />

In order to prevent supervisor rights in the file system being obtained through<br />

improper allocation of NDS rights, Inherited Rights Filters (IRF) can be<br />

activated for every server. This allows the object rights to be separated from<br />

the directory rights. <strong>The</strong> supervisor right must be filtered for NDS objects and<br />

NDS object properties and the right WR<strong>IT</strong>E for the property Object Trustees<br />

(ACL) must also be filtered. It is of course preferable to be aware of the details<br />

of how particular rights take effect.<br />

Restricted usage of accounts with supervisor rights on the file level<br />

<strong>The</strong> account "Admin" should only be used in an emergency, and not as part of<br />

regular administrative activities. Nevertheless, to ensure proper system<br />

administration, every user on the Netware security level "Supervisor" should<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!