HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 4.49 Safeguarding the boot-up procedure for a Windows NT system

S 4.49 Safeguarding the boot-up procedure for a Windows NT system

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Administrators

Windows NT can only be operated securely if there is a guarantee right from the start of the system that a closed security environment is constructed, i.e. that there are no ways around the security functions of the operating system. This requires that all resources which are capable of being protected by Windows NT are under the control of the operating system and also that there is no possibility of starting up outside systems or open system environments which can circumvent the protection offered by Windows NT. In addition, the following aspects should be taken into account:

Under Windows NT, logging-on to the server is only possible for users to whom the user right " Local log-on " has been given. These users are restricted to the rights and permissions assigned to them. To avoid misuse of the possibilities for logging-on to the server, provision must be made for the user rights, and the allocations to user groups, to be correspondingly restrictive (see safeguards S 2.93 Planning of the Windows NT network and S 4.50 Structured system administration under Windows NT).

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
July 1999
home