- Introduction
- Your Needs
- What to Protect
- Security Policies
- Security Policy Requirements
- Incident Procedures
- Security Categories
- Software Vulnerability Control
- Hostile Software
- Network Layout
- Traffic Filtering
- Mail
- Firewall Protection
- Network Intrusion Detection
- Network Port Scanning
- Network Tools
- Passwords
- Types of Attacks
- Protocol Use
- Entry Points
- Cost
- Application Level Protection
- System Protection
- User Issues
- Other Recommendations
- Terms
- Credits
|
System Protection
- No networked computer without operating virus detection software shall be operated. Virus detection software shall be updated a minimum of once per month and a complete system scan for viruses shall be done at least once per month.
- No unprotected shares
- Disable ActiveX code in all web browsers.
- Standard settings on web browsers for Java and Javascript code.
- Systems should be set not to hide file extensions for known file types. If hiding extensions for known file types is allowed, an attacker can disguise a file with a name like "FRIENDLYFILE.TXT.exe". This file will appear to be a text file to a user. If the user attempts to open it, it can be run in their system, and... To set this correctly, do the following:
- Open "My Computer".
- On the menu, select "View" and "Folder Options".
- Select the "View" tab.
- Uncheck "Hide file extensions for known file types".
- Disable/remove Windows Scripting Host (WSH)
- Click on "Settings"
- Select "Control Panel"
- Click "Add/Remove"
- Click on the "Windows Setup" tab.
- Click "Accessories".
- Uncheck "Windows Scripting Host" and click "OK".
|
|
|
|