accessible view | jump to content | search | jump to site-wide navigation
Implemented LSA Windows Network Security Measures (and Recommendations)
- Make password minimum 7 characters.
- Use “strong” passwords only.
- Set expiration on passwords to 1 year.
- Extend default lockout period to 1 hour.
- Change local administrator password on all Windows systems.
- Sys Admins login with admin account only when performing administration.
- Sys Admins use “user account” when performing personal work.
- Sys Admins use RUNAS command if logged in with “user credentials”.
- Use Telnet with Kerberized Hummingbird Host Explorer or Putty (SSH)
- Minimize use of ftp; ideally use IPSEC when moving data with ftp
- Remove all local user profiles that age beyond 7 days old
- Do not use a roaming profile when logged in with administrator privileges
- Do not send passwords in e-mail unless mail is encrypted with PGP or S/MIME
- Decrease number of accounts with domain admin privileges
- Password changes to privileged accounts must be made immediately after a staff person (who knew the password) has left their LS&A position.
- Former staff accounts must be removed from privileged groups immediately after they have left their LS&A position.
- All Sys Admins must pay more attention to service pack updates to maintain secure systems.
- Sys Admins should not execute programs sent in anonymous e-mail.
- Sys Admins use PKI certificates for e-mail and web servers.
- Phase in increased use of IPSEC transmissions. Use IPSEC enabled NICs.
- Set Windows 2000 Kerberos attributes for ticket TTL to same times as used in UMCE Unix environment.
- Install Directory Services client on all downlevel clients where possible.
- Work with Thursby Software Systems to have them upgrade Dave Client to NTLM V2.
- Consider increased use of Firewall technology such as the product from CheckPoint.
- Install MacAfee Netshield on all Win2K servers.
- Turn off ports where a malicious system is causing trouble for others on network
- LSAIT may provide script to DSAs that captures critical events from user workstation logs.
- Maintain vigil to prevent users from disabling AntiVirus software.
- Sys Admins maintain a posture that locked screensavers are used when user(s) leave workstation unattended.