HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 2.210 Planning the use of Lotus Notes in an intranet with browser access

S 2.210 Planning the use of Lotus Notes in an intranet with browser access

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: IT Security Management, Administrator

If a Notes server within the intranet is also to be accessed via a browser, then the relevant security issues must be considered and planned for.

Compared with access via the Notes client, the Web interface generally offers less functionality. In particular it should be noted that, compared with access from a Notes client, quite different security mechanisms are used for authentication on the Web interface. Again, data security at database level is only supported here to a limited extent. Decryption and encryption of document fields is currently not offered on the Web interface. Another restriction is the lack of any facility for replicating databases locally on clients in order to enable offline processing.

Since browser access inevitably carries certain IT security risks, this is not recommended. It should therefore be made as restrictive as possible, i.e. enabled only when this is absolutely necessary.

If browser access is still to be enabled despite the additional security problems, the following issues must be considered at the planning stage:

Depending on the specific operational scenario, there may be other issues which need to be considered where Lotus Notes is to be used in an intranet with browser access.

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
July 2001
home