19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

be assigned an account with the same rights as the supervisor object (explicit<br />

trustee assignment, see also <strong>Protection</strong> against a loss of administrative<br />

capability) which should usually be used to perform system administration. If<br />

administrative tasks are not performed on a full-time basis, additional<br />

accounts need to be created specifically for each non-administrative activity.<br />

<strong>The</strong> account of the administrator or that of the administrator's representative<br />

should continue to be used only in workstations defined for this purpose, as<br />

the integrity of other workstations could be manipulated.<br />

<strong>The</strong> account "Admin", which has the sole administrative rights by default,<br />

should have its rights removed because it is a target for attack. <strong>The</strong> necessary<br />

supervisor rights should be transferred to another, less conspicuous user<br />

account. However, it is possible to simply rename the Admin account,<br />

choosing a name that complies with the general regulations for assigning<br />

names within the NDS, as laid down in the planning of the NDS for the<br />

company.<br />

<strong>Protection</strong> against a loss of administrative capability<br />

A new function as of Netware Version 4.x allows a decentral administration of<br />

Novell Netware networks. This can be achieved by means of certain<br />

administrative facilities such as the definition of a separate administrator for<br />

each container object. If only one user account has been configured for this<br />

purpose and this account is deleted inadvertently, the related container can no<br />

longer be managed (refer to T 3.25 Negligent deletion of objects).<br />

To achieve the desired effect, an additional measure is thus required in the<br />

form of an explicit trustee assignment for at least one of the user objects of<br />

the user administrator. <strong>The</strong>refore, the administrator right should not result<br />

from the mechanism Security Equal To. This prevents a loss of administrative<br />

capability for the container in case the organisational function object is<br />

deleted. This applies in particular to the allocation of rights to the central<br />

administrators of a Netware 4.x network.<br />

<strong>Information</strong> on Novell Netware patches<br />

During the development of the Novell Netware network operating system,<br />

weak points and shortcomings were discovered, most of which the<br />

manufacturer subsequently remedied with the help of patches or service packs<br />

for versions 3.x and 4.x. <strong>The</strong>se patches can also be obtained from the<br />

manufacturer via the Internet (http://support.novell.com and<br />

http://support.novell.de). Shortcomings identified during operation of the<br />

network can thus be fixed by obtaining information on the network's<br />

functionality and, if necessary, loading the patches which have been made<br />

available. In particular, additionally installed software products, e.g. for the<br />

purpose of performing data backups, often require a certain patch level of the<br />

network operating system. Here though, it must be noted that the offered<br />

patches should by no means be loaded "blindly", but only after a thorough<br />

research if a concrete requirement for them has arisen ("never change a<br />

running system"). As not all patches are error-free, they should first be<br />

checked in a test configuration.<br />

Apart from the international discussion forums in the Internet (Usenet)<br />

regarding Novell Netware (at present, comp.os.netware.announce,<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!