Security Policy - I
-
strong account management
-
use difficult passwords; close accounts with weak passwords
-
computers must be logged-out or locked when employees are away from offices
-
account should be deactivated after a certain period of inactivity
-
check traffic logs regularly; use scanning tools: tiger, SATAN, crack; install firewall and filters in routers
-
install security patches from vendors, newest versions of software
-
use encryption (ssh, scp, slogin)
-
disable unix r-commands, finger, tftp, etc
-
carefully install anonymous FTP (read only!)
|