Recommendations (1)
Security Policy - I
- deploy one-time passwords, not reusable ones; use difficult passwords, close accounts with weak passwords
- computers must be logged-out when employees are away from offices
- account must be deactivated after a certain period of inactivity
- check traffic logs regularly; use scanning tools: tiger, SATAN, crack; install firewall and filters in routers
- install security patches from vendors, newest versions of software
- use encryption (ssh, scp, slogin)
- disable unix r-commands, finger, tftp, etc
- carefully install anonymous FTP