19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- Organisational unit<br />

An organisational unit can only be created within an organisation and is<br />

intended for further partitioning of the NDS. For example, offices,<br />

departments and project groups can be divided into organisational units.<br />

<strong>The</strong> organisational unit is an optional item used to improve structuring in<br />

accordance with the number of leaf objects involved.<br />

Leaf objects include, for example, users, groups, printers, servers and data<br />

volumes. It is not possible to create additional objects under leaf objects. <strong>The</strong><br />

following leaf objects are used most frequently:<br />

- Netware server<br />

This object represents a Netware server in a network, which must contain<br />

at least one such server. <strong>The</strong> object is referred to by many other objects<br />

which use the services provided by the server, and is created by the<br />

installation program.<br />

- printer<br />

This object represents a printer present in the network, and is always<br />

accompanied by the printer queue and print server objects.<br />

- Users<br />

This object is intended to manage and store information on network users,<br />

particularly their rights to access network resources.<br />

- Groups<br />

Although several users can be assigned to a group, it represents a leaf<br />

object, not a container object. It is intended to simplify administration, as<br />

the rights of a group can be transferred to its members.<br />

- Volume<br />

This object represents a physical volume for storing data. As a rule, volume<br />

objects are created by the installation program.<br />

A detailed description of the remaining leaf objects is provided in Netware<br />

manuals. <strong>The</strong>re are no restrictions on the number of objects, as objects can be<br />

added or deleted by applications.<br />

As already mentioned, the directory objects and their attributes are managed in<br />

a database which constitutes an essential element of the NDS. In networks<br />

possessing WAN links, it is advisable to partition this database into logical<br />

segments which are then copied to various Netware servers. When planning<br />

the replications, it is important to take slow WAN links into account.<br />

This logical segmentation is termed partitioning. <strong>The</strong> process of copying<br />

logical segments to Netware servers is termed replication.<br />

Every partition consists of at least one container object and any additional<br />

objects contained therein. Additionally, several read or read/write copies of a<br />

partition, but only one master partition, can exist.<br />

<strong>The</strong> physical partitioning of the NDS is transparent for users, i.e. internal<br />

Netware mechanisms ensure that this partitioning is not noticed by the users.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!