19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.171 Selection of a suitable system management<br />

product<br />

Initiation responsibility: Head of <strong>IT</strong> Section<br />

Implementation responsibility: Administrators<br />

After the current system situation has been surveyed (see S 2.168) and the<br />

management strategy determined (see S 2.169), a suitable system management<br />

system must be selected. Depending on the size of the system to be managed,<br />

different implementations may be appropriate here:<br />

- For small systems, system management can be handled „manually“ by the<br />

system administration team.<br />

- For small and medium-sized systems, system management can also be<br />

performed by a collection of individual tools.<br />

- A system management system should be used for large systems.<br />

Today’s network-capable operating systems normally already incorporate<br />

functions which allow the central administration of users and user groups, for<br />

example. In the Unix world, NIS or NIS+ could be named in this connection,<br />

for example, while in the Windows world the Windows NT domain concept<br />

allows central user administration via the domain controller. Novell also offers<br />

similar opportunities with Intranetware. Generally there are also possibilities<br />

of running a network-wide policy management system.<br />

In relatively small or medium-sized networks, on the other hand, software<br />

management, management of computer configurations and the monitoring of<br />

system components are the most pressing problem areas. In this case<br />

additional software tools can then be used which can take over the individual<br />

tasks. Consideration can be given to using a network management tool,<br />

especially in areas that are also covered by the disciplines of network<br />

management (configuration management, monitoring).<br />

Various tools could be mentioned for the Windows environment, such as the<br />

Novell Zero Administration Kit, which supports administrators in the<br />

installation of new computers, the Microsoft Management Console, which<br />

provides a uniform centralised view of all administration tools, and the<br />

Microsoft Systems Management Server (SMS). <strong>The</strong> SMS product, for<br />

example, offers administrators the following possibilities:<br />

- Drawing up inventories of hardware and software components<br />

- Installation and distribution of data and applications on network computers<br />

- Checking the execution of network applications<br />

- Support for the administration of computers via the network<br />

- Monitoring of network traffic<br />

SMS is not designed for a heterogeneous environment, however. Moreover,<br />

remote maintenance is only semi-automatic and requires an administrator to<br />

be available on site, which means that its use is only appropriate for relatively<br />

small and geographically compact networks.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!