UCF ID: 00881 |
Control Type: Configuration |
Status: Live |
Supporting and supported controls
This control directly supports:
- • Establish and maintain a systems hardening standard and procedures. [UCF Control ID 00876]
This control has the following supporting controls:
- • Configure the system to restrict core dumps to a protected directory. [UCF Control ID 01513]
• Configure the system to enable stack protection. [UCF Control ID 01514]
• Configure the system to restrict NFS client requests to privileged ports. [UCF Control ID 01515]
• Configure the system to use better TCP sequence numbers. [UCF Control ID 01516]
• Configure the system to a default secure level. [UCF Control ID 01519]
• Configure the system to block users from viewing un-owned processes. [UCF Control ID 01520]
• Configure the system to block users from viewing processes in other groups. [UCF Control ID 01521]
• Add the "nosuid" option to /etc/rmmount.conf. [UCF Control ID 01532]
• Configure the system to block non-privileged mountd requests. [UCF Control ID 01533]
• Add the "nodev" option to the appropriate partitions in /etc/fstab. [UCF Control ID 01534]
• Add the "nosuid" and "nodev" option for removable media in /etc/fstab. [UCF Control ID 01535]
• Configure the sticky-bit on world-writable directories. [UCF Control ID 01540]
• Ensure system files are not world-writable. [UCF Control ID 01546]
• Ensure patch back-up directories are not accessible. [UCF Control ID 01547]
• Run hp_checkperms. [UCF Control ID 01548]
• Run fix-modes. [UCF Control ID 01549]
• Convert the system to "Trusted Mode," if possible. [UCF Control ID 01550]
• Configure the sadmind service to a higher security level. [UCF Control ID 01551]
• Find files and directories that have extended attributes. [UCF Control ID 01552]
• Configure all.rhosts files to be readable only by their owners. [UCF Control ID 01557]
• Set symlink hosts.equiv to /dev/null. [UCF Control ID 01558]
• Configure the default locking screen saver time-out to a predetermined amount of time. [UCF Control ID 01570]
• Configure the Security Center (Domain PCs only). [UCF Control ID 01967]
• Configure the system to use certificate rules for software restriction policies. [UCF Control ID 04266]
• Enable the safe DLL search mode. [UCF Control ID 04273]
• Configure the computer to stop generating 8.3 style filenames. [UCF Control ID 04274]
• Configure the system to immediately protect the computer when the screen saver is activated by setting the time before the screen saver grace period expires to a predefined amount. [UCF Control ID 04276]
• Configure the "Do not allow drive redirection" setting. [UCF Control ID 04316]
• Configure the "Turn off the 'Publish to Web' task for files and folders" setting. [UCF Control ID 04328]
• Configure the "Turn off Internet download for Web publishing and online ordering wizards" setting. [UCF Control ID 04329]
• Configure the "Turn off Search Companion content file updates" setting. [UCF Control ID 04331]
• Configure the "Turn off printing over HTTP" setting. [UCF Control ID 04332]
• Configure the "Turn off downloading of print drivers over HTTP" setting. [UCF Control ID 04333]
• Configure the "Turn off Windows Update device driver searching" setting. [UCF Control ID 04334]
• Configure the "Display Error Notification" setting. [UCF Control ID 04335]
• Configure the "Turn off Windows error reporting" setting. [UCF Control ID 04336]
• Configure the "Disable software update shell notifications on program launch" setting. [UCF Control ID 04339]
• Configure the "Make proxy settings per-machine (rather than per-user)" setting. [UCF Control ID 04341]
• Configure the "Security Zones: Do not allow users to add/delete sites" setting. [UCF Control ID 04342]
• Configure the "Security Zones: Do not allow users to change policies" setting. [UCF Control ID 04343]
• Configure the "Security Zones: Use only machine settings" setting. [UCF Control ID 04344]
• Configure the "Allow software to run or install even if the signature is invalid" setting. [UCF Control ID 04346]
• Configure the "Internet Explorer Processes (Scripted Window Security Restrictions)" setting. [UCF Control ID 04350]
• Configure the "Internet Explorer Processes (Zone Elevation Protection)" setting. [UCF Control ID 04351]
• Configure the "Prevent access to registry editing tools" setting. [UCF Control ID 04355]
• Configure the "Do not preserve zone information in file attachments" setting. [UCF Control ID 04357]
• Configure the "Hide mechanisms to remove zone information" setting. [UCF Control ID 04358]
• Configure the "Notify antivirus programs when opening attachments" setting. [UCF Control ID 04359]
• Configure the "Configure Outlook Express" setting. [UCF Control ID 04360]
• Configure the "Disable Changing Automatic Configuration settings" setting. [UCF Control ID 04361]
• Configure the "Disable changing certificate settings" setting. [UCF Control ID 04362]
• Configure the "Disable changing connection settings" setting. [UCF Control ID 04363]
• Configure the "Disable changing proxy settings" setting. [UCF Control ID 04364]
• Configure the "Turn on the auto-complete feature for user names and passwords on forms" setting. [UCF Control ID 04365]
• Configure the system to require a password before it unlocks the screen saver. [UCF Control ID 04443]
• Configure the NetWare bindery contexts. [UCF Control ID 04444]
• Configure the SECURE.NCF settings in the NetWare console. [UCF Control ID 04445]
• Configure the CPU Hog Timeout setting. [UCF Control ID 04446]
• Configure the "Check Equivalent to Me" setting. [UCF Control ID 04463]
• Configure the /etc/sshd_config file. [UCF Control ID 04475]
• Configure the .Mac preferences. [UCF Control ID 04484]
• Configure the fast user switching setting. [UCF Control ID 04485]
• Configure the recent items list (servers, applications, documents) setting. [UCF Control ID 04486]
• Configure Apple's Dock preferences. [UCF Control ID 04487]
• Configure the Energy Saver preferences. [UCF Control ID 04488]
• Configure the local system search preferences to directories that do not contain restricted data or information. [UCF Control ID 04492]
• Digitally sign and encrypt all e-mail. [UCF Control ID 04493]
• Manage temporary (tmp) files, as necessary. [UCF Control ID 04847]
• Configure the computer-wide, rather than per-user, use of Microsoft Spynet Reporting for Windows Defender properly. [UCF Control ID 05282]
• Enable or disable the ability of users to perform interactive startups, as appropriate. [UCF Control ID 05283]
• Set the NIS file inclusions in the /etc/passwd file properly. [UCF Control ID 05284]
• Configure the "Turn off Help Ratings" setting properly. [UCF Control ID 05285]
• Configure the "Decoy Admin Account Not Disabled" policy properly. [UCF Control ID 05286]
• Configure the "Additional restrictions for anonymous connections" policy properly. [UCF Control ID 05287]
• Configure the "Anonymous access to the registry" policy properly. [UCF Control ID 05288]
• Configure the File System Checker and Popups setting properly. [UCF Control ID 05289]
• Configure the System File Checker setting properly. [UCF Control ID 05290]
• Configure the System File Checker Progress Meter setting properly. [UCF Control ID 05291]
• Configure the Protect Kernel object attributes properly. [UCF Control ID 05292]
• Configure the "Delete Cached Copies of Roaming Profiles" policy properly. [UCF Control ID 05293]
• Ensure authorized X-clients are listed in the X*.hosts file. [UCF Control ID 05294]
• Ensure all files are owned by an existing account or group. [UCF Control ID 05295]
• Ensure programs executed through the aliases file are owned by an appropriate user or group. [UCF Control ID 05296]
• Ensure programs executed through the aliases file reside in a directory with an appropriate user owner. [UCF Control ID 05297]
• Ensure the at directory is owned by an appropriate user or group. [UCF Control ID 05298]
• Ensure the at.allow file is owned by an appropriate user or group. [UCF Control ID 05299]
• Ensure the at.deny file should be owned by an appropriate user or group. [UCF Control ID 05300]
• Ensure the crontab directories are owned by an appropriate user or group. [UCF Control ID 05302]
• Ensure the cron.allow file is owned by an appropriate user or group. [UCF Control ID 05303]
• Ensure the cron.deny file is owned by an appropriate user or group. [UCF Control ID 05304]
• Ensure crontab files are owned by an appropriate user or group. [UCF Control ID 05305]
• Ensure the /etc/resolv.conf file is owned by an appropriate user or group. [UCF Control ID 05306]
• Ensure the /etc/named.boot file is owned by an appropriate user or group. [UCF Control ID 05307]
• Ensure the /etc/named.conf file is owned by an appropriate user or group. [UCF Control ID 05308]
• Ensure the /var/named/chroot/etc/named.conf file is owned by the appropriate user or group. [UCF Control ID 05309]
• Ensure home directories are be owned by an appropriate user or group. [UCF Control ID 05310]
• Ensure the inetd.conf file is owned by an appropriate user or group. [UCF Control ID 05311]
• Ensure /etc/exports is owned by an appropriate user or group. [UCF Control ID 05312]
• Ensure exported files and directories are owned by an appropriate user or group. [UCF Control ID 05313]
• Ensure the /etc/services file is owned by an appropriate user or group. [UCF Control ID 05314]
• Ensure the /etc/notrouter file is owned by an appropriate user or group. [UCF Control ID 05315]
• Ensure the /etc/samba/smb.conf file is owned by an appropriate user or group. [UCF Control ID 05316]
• Ensure the smbpasswd file and smbpasswd executable are owned by an appropriate user or group. [UCF Control ID 05317]
• Ensure the aliases file is owned by an appropriate user or group. [UCF Control ID 05318]
• Ensure the log file configured to capture critical sendmail messages is owned by the appropriate user or group. [UCF Control ID 05319]
• Ensure shell files are owned by an appropriate user or group. [UCF Control ID 05320]
• Ensure the snmpd.conf file is owned by an appropriate user or group. [UCF Control ID 05321]
• Ensure the /etc/syslog.conf file is owned by an appropriate user or group. [UCF Control ID 05322]
• Ensure the traceroute executable is owned by an appropriate user or group. [UCF Control ID 05323]
• Ensure the /usr/lib/sendmail file is owned by an appropriate user or group. [UCF Control ID 05324]
• Ensure the /etc/passwd file is owned by an appropriate user or group. [UCF Control ID 05325]
• Ensure the /etc/shadow file is owned by an appropriate user or group. [UCF Control ID 05326]
• Ensure the /etc/security/audit/config file is owned by an appropriate user or group. [UCF Control ID 05327]
• Ensure the /etc/security/audit/events file is owned by an appropriate user or group. [UCF Control ID 05328]
• Ensure the /etc/security/audit/objects file is owned by an appropriate user or group. [UCF Control ID 05329]
• Ensure the /usr/lib/trcload file is owned by an appropriate user or group. [UCF Control ID 05330]
• Ensure the /usr/lib/semutil file is owned by an appropriate user or group. [UCF Control ID 05331]
• Ensure system files are owned by an appropriate user or group. [UCF Control ID 05332]
• Ensure the default/skeleton dot files are owned by an appropriate user or group. [UCF Control ID 05333]
• Ensure the global initialization files are owned by an appropriate user or group. [UCF Control ID 05334]
• Ensure the /etc/rc.config.d/auditing file is owned by an appropriate user or group. [UCF Control ID 05335]
• Ensure the /etc/init.d file is owned by an appropriate user or group. [UCF Control ID 05336]
• Ensure the /etc/hosts.lpd file is owned by an appropriate user or group. [UCF Control ID 05337]
• Ensure the /etc/auto.master file is owned by an appropriate user or group. [UCF Control ID 05338]
• Ensure the /etc/auto.misc file is owned by an appropriate user or group. [UCF Control ID 05339]
• Ensure the /etc/auto.net file is owned by an appropriate user or group. [UCF Control ID 05340]
• Ensure the /boot/grub/grub.conf file is owned by an appropriate user or group. [UCF Control ID 05341]
• Ensure the /etc/lilo.conf file is owned by an appropriate user or group. [UCF Control ID 05342]
• Ensure the /etc/login.access file is owned by an appropriate user or group. [UCF Control ID 05343]
• Ensure the /etc/security/access.conf file is owned by an appropriate user or group. [UCF Control ID 05344]
• Ensure the /etc/sysctl.conf file is owned by an appropriate user or group. [UCF Control ID 05345]
• Ensure the /etc/securetty file is owned by an appropriate user or group. [UCF Control ID 05346]
• Ensure the /etc/audit/auditd.conf file is owned by an appropriate user or group. [UCF Control ID 05347]
• Ensure the audit.rules file is owned by an appropriate user or group. [UCF Control ID 05348]
• Ensure the /etc/group file is owned by an appropriate user or group. [UCF Control ID 05349]
• Ensure the /etc/gshadow file is owned by an appropriate user or group. [UCF Control ID 05350]
• Ensure the /usr/sbin/userhelper file is owned by an appropriate group. [UCF Control ID 05351]
• Ensure all syslog log files are owned by an appropriate user or group. [UCF Control ID 05352]
• Ensure the /etc/anacrontab file is owned by an appropriate user or group. [UCF Control ID 05353]
• Ensure the /etc/pki/tls/ldap file is owned by an appropriate user or group. [UCF Control ID 05354]
• Ensure the /etc/pki/tls/ldap/serverkey.pem file is owned by an appropriate user or group. [UCF Control ID 05355]
• Ensure the /etc/pki/tls/CA/cacert.pem file is owned by an appropriate user or group. [UCF Control ID 05356]
• Ensure the /etc/pki/tls/ldap/servercert.pem file is owned by an appropriate user or group. [UCF Control ID 05357]
• Ensure the /var/lib/ldap/* files are owned by an appropriate user or group. [UCF Control ID 05358]
• Ensure the /etc/httpd/conf/* files are owned by an appropriate group. [UCF Control ID 05359]
• Ensure the /etc/auto_* file is owned by an appropriate user. [UCF Control ID 05360]
• Ensure the /etc/rmmount.conf file is owned by an appropriate user or group. [UCF Control ID 05361]
• Ensure the /var/log/pamlog file is owned by an appropriate user or group. [UCF Control ID 05362]
• Ensure the /etc/security/audit_control file is owned by an appropriate user or group. [UCF Control ID 05363]
• Ensure the /etc/security/audit_class file is owned by an appropriate user or group. [UCF Control ID 05364]
• Ensure the /etc/security/audit_event file is owned by an appropriate user or group. [UCF Control ID 05365]
• Ensure the /usr/aset/userlist file is owned by an appropriate group. [UCF Control ID 05366]
• Ensure the /var directory is owned by an appropriate user. [UCF Control ID 05367]
• Ensure the /var/log directory is owned by an appropriate user. [UCF Control ID 05368]
• Ensure the /var/adm directory is owned by an appropriate user. [UCF Control ID 05369]
• Restrict the daemon debug log file owner and group owner. [UCF Control ID 05370]
• Restrict the Cron log file owner and group owner. [UCF Control ID 05371]
• Restrict the system accounting file owner and group owner. [UCF Control ID 05372]
• Restrict audit log file ownership and group ownership. [UCF Control ID 05373]
• Set the X server timeout properly. [UCF Control ID 05374]
• Configure the authentication mechanism (SYSTEM attribute) properly for each user. [UCF Control ID 05375]
• Enable or disable SELinux, as appropriate. [UCF Control ID 05376]
• Set the SELinux state properly. [UCF Control ID 05377]
• Set the SELinux policy properly. [UCF Control ID 05378]
• Configure Dovecot properly. [UCF Control ID 05379]
• Configure the "Prohibit Access of the Windows Connect Now Wizards" setting properly. [UCF Control ID 05380]
• Configure the "Allow remote access to the PnP interface" setting properly. [UCF Control ID 05381]
• Configure the "Do not create system restore point when new device driver installed" setting properly. [UCF Control ID 05382]
• Configure the "Turn Off Access to All Windows Update Feature" setting properly. [UCF Control ID 05383]
• Configure the "Turn Off Automatic Root Certificates Update" setting properly. [UCF Control ID 05384]
• Configure the "Turn Off Event Views 'Events.asp' Links" setting properly. [UCF Control ID 05385]
• Configure the "Turn Off Handwriting Reconition Error Reporting" setting properly. [UCF Control ID 05386]
• Configure the "Turn Off Help and Support Center "Did You Know?" Content" setting properly. [UCF Control ID 05387]
• Configure the "Turn Off Help and Support Center Microsoft Knowledge Base Search" setting properly. [UCF Control ID 05388]
• Configure the "Turn Off Internet File Association Service" setting properly. [UCF Control ID 05389]
• Configure the "Turn Off Registration if URL Connection is Referring to Microsoft.com" setting properly. [UCF Control ID 05390]
• Configure the "Turn Off the 'Order Prints' Picture Task" setting properly. [UCF Control ID 05391]
• Configure the "Turn Off Windows Movie Maker Online Web Links" setting properly. [UCF Control ID 05392]
• Configure the "Turn Off Windows Movie Maker Saving to Online Video Hosting Provider" setting properly. [UCF Control ID 05393]
• Configure the "Don't Display the Getting Started Welcome Screen at Logon" setting properly. [UCF Control ID 05394]
• Configure the "Turn off Windows Startup Sound" setting properly. [UCF Control ID 05395]
• Configure the "Allow only Vista or later connections" setting properly. [UCF Control ID 05396]
• Configure the "Turn on bandwidth optimization" setting properly. [UCF Control ID 05397]
• Configure the "Prevent IIS Installation" setting properly. [UCF Control ID 05398]
• Configure the "Turn off Active Help" setting properly. [UCF Control ID 05399]
• Configure the "Turn off Untrusted Content" setting properly. [UCF Control ID 05400]
• Configure the "Turn off downloading of enclosures" setting properly. [UCF Control ID 05401]
• Configure the "Allow indexing of encrypted files" setting properly. [UCF Control ID 05402]
• Configure the "Prevent indexing uncached Exchange folders" setting properly. [UCF Control ID 05403]
• Configure the "Turn off Windows Calendar" setting properly. [UCF Control ID 05404]
• Configure the "Turn off Windows Defender" setting properly. [UCF Control ID 05405]
• Configure the "Turn off Heap termination on corruption" setting properly. [UCF Control ID 05406]
• Configure the "Turn off shell protocol protected mode" setting properly. [UCF Control ID 05407]
• Configure the "Prohibit non-administrators from applying vendor signed updates" setting properly. [UCF Control ID 05408]
• Configure the "Report Logon Server Not Available During User logon" setting properly. [UCF Control ID 05409]
• Configure the "Turn off the communitication features" setting properly. [UCF Control ID 05410]
• Configure the "Turn off Windows Mail application" setting properly. [UCF Control ID 05411]
• Configure the "Prevent Windows Media DRM Internet Access" setting properly. [UCF Control ID 05412]
• Configure the "Turn off Windows Meeting Space" setting properly. [UCF Control ID 05413]
• Configure the "Turn on Windows Meeting Space audting" setting properly. [UCF Control ID 05414]
• Configure the "Disable unpacking and installation of gadgets that are not digitally signed" setting properly. [UCF Control ID 05415]
• Configure the "Override the More Gadgets Link" setting properly. [UCF Control ID 05416]
• Configure the "Turn Off User Installed Windows Sidebar Gadgets" setting properly. [UCF Control ID 05417]
• Configure the "Do not allow Digital Locker to run" setting properly. [UCF Control ID 05418]
• Configure the "Turn Off Downloading of Game Information" setting properly. [UCF Control ID 05419]
• Configure the "Turn on Responder (RSPNDR) driver" setting should be configured correctly for the domain profile. [UCF Control ID 05420]
• Enable the ExecShield, as appropriate. [UCF Control ID 05421]
• Configure kernel support for the XD/NX processor feature, as appropriate. [UCF Control ID 05422]
• Configure the XD/NX processor feature in the BIOS, as appropriate. [UCF Control ID 05423]
• Configure the shell for the bin account properly. [UCF Control ID 05424]
• Configure the shell for the nuucp account properly. [UCF Control ID 05425]
• Configure the shell for the smmsp account properly. [UCF Control ID 05426]
• Configure the shell for the listen account properly. [UCF Control ID 05427]
• Configure the shell for the gdm account properly. [UCF Control ID 05428]
• Configure the shell for the webservd account properly. [UCF Control ID 05429]
• Configure the shell for the nobody account properly. [UCF Control ID 05430]
• Configure the shell for the noaccess account properly. [UCF Control ID 05431]
• Configure the shell for the nobody4 account properly. [UCF Control ID 05432]
• Configure the shell for the adm account properly. [UCF Control ID 05433]
• Configure the shell for the lp account properly. [UCF Control ID 05434]
• Configure the shell for the uucp account properly. [UCF Control ID 05435]
• Ensure ExecShield has been randomly placed in virtual memory regions. [UCF Control ID 05436]
• Set the noexec_user_stack parameter properly. [UCF Control ID 05437]
• Set the no_exec_user_stack_log parameter properly. [UCF Control ID 05438]
• Set the noexec_user_stack flag on the user stack properly. [UCF Control ID 05439]
• Set the TCP max connection limit properly. [UCF Control ID 05440]
• Set the TCP abort interval properly. [UCF Control ID 05441]
• Enable or disable the GNOME screenlock, as appropriate. [UCF Control ID 05442]
• Set the ARP cache cleanup interval properly. [UCF Control ID 05443]
• Set the ARP IRE scan rate properly. [UCF Control ID 05444]
• Set the FileSpaceSwitch variable to an appropriate value. [UCF Control ID 05445]
• Set the wakeup switchpoint frequency to an appropriate time interval. [UCF Control ID 05446]
• Enable or disable the setuid option on removable media, as appropriate. [UCF Control ID 05447]
• Configure TCP/IP PMTU Discovery as appropriate. [UCF Control ID 05991]
• Configure SSH to enable or disable empty passwords as appropriate. [UCF Control ID 06016]
• Configure the Screen Saver Executable Name for each user. [UCF Control ID 06027]
• Configure the NIS+ server to operate at an appropriate security level. [UCF Control ID 06038]
• Configure the "restrict guest access to system log" policy as appropriate. [UCF Control ID 06047]
• Configure the "Block saving of Open Xml file types" setting as appropriate. [UCF Control ID 06048]
• Enable or disable user-initiated system crashes via the CTRL+SCROLL LOCK+SCROLL LOCK sequence for keyboards. [UCF Control ID 06051]
• Configure the Syskey mode as appropriate. [UCF Control ID 06052]
• Configure the Trusted Platform Module (TPM) platform validation profile, as appropriate. [UCF Control ID 06056]
• Configure the "Allow Remote Shell Access" setting as appropriate. [UCF Control ID 06057]
• Configure the "Prevent the computer from joining a homegroup" setting as appropriate. [UCF Control ID 06058]
• Enable or disable the requirement for a password after waking, as appropriate. [UCF Control ID 06059]
• Enable or disable the standby states, as appropriate. [UCF Control ID 06060]
• Configure the Trusted Platform Module (TPM) startup options properly. [UCF Control ID 06061]
Authority documents complied with:
AICPA Suitable Trust Services Principles and Criteria, ¶ .17 § 3.8, ¶ .20 § 3.11, ¶ .24 § 3.12, ¶ .29 § 3.11; Payment Card Industry (PCI) Data Security Standard, Requirements and Security Assessment Procedures, Version 1.2.1, § 2.2.3; IRS Publication 1075: TAX INFORMATION SECURITY GUIDELINES FOR FEDERAL, STATE AND LOCAL AGENCIES AND ENTITIES; Safeguards for Protecting Federal Tax Returns and Return Information, Exhibit 8 Control 13; Defense Information Systems Agency UNISYS Security Technical Implementation Guide Version 7 Release 2, 28 August 2006, § 2.1, § 5.6, § 5.6.4; DISA Secure Remote Computing Security Technical Implementation Guide, Version 1, Release 2, § 3.2; ISO/IEC 15408-2 Common Criteria for Information Technology Security Evaluation Part 2, 2008, § 15.10, § J.10; Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance All other Merchants and all SAQ-Eligible Service Providers, Version 1.2, § 2.2.3; DISA Wireless STIG Motorola Good Mobile Wireless Email System Security Checklist, Version 5 Release 2.3, § 2.2 (WIR3250), § 3.15.2, App B.2 Row “Site Access/URL Substitutions”; Recommended Security Controls for Federal Information Systems, NIST SP 800-53, Revision 3, App F § AC-18(4); ISO/IEC 13335-5 Information technology — Guidelines for the management of IT Security — Part 5: Management guidance on network security, 2001, ¶ 13.6
Payment Card Guidance
The organization must ensure all system security parameters are configured to prevent misuse.
Examine the configuration files and standards to verify the the security parameters are included in the system configuration standards.
Interview System Administrators and/or security managers to ensure they know the common security settings for the operating systems, servers, and other components of the network. [§ 2.2.3, Payment Card Industry (PCI) Data Security Standard, Requirements and Security Assessment Procedures, Version 1.2.1]
The organization must ensure all system security parameters are configured to prevent misuse. [§ 2.2.3, Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance All other Merchants and all SAQ-Eligible Service Providers, Version 1.2]
US Internal Revenue Guidance
The system boot settings or initialization files must be password-protected. [Exhibit 8 Control 13, IRS Publication 1075: TAX INFORMATION SECURITY GUIDELINES FOR FEDERAL, STATE AND LOCAL AGENCIES AND ENTITIES; Safeguards for Protecting Federal Tax Returns and Return Information]
NIST Guidance
The organization should ensure only authorized personnel are allowed to configure wireless networking capabilities. [App F § AC-18(4), Recommended Security Controls for Federal Information Systems, NIST SP 800-53, Revision 3]
System Configuration Guidance
The Information Assurance Officer should regularly scan the security posture of the system to identify potential security weaknesses. Waiting for security violations to occur and reacting to them is not adequate. ACLs can be used to grant or deny access to objects based on security groups (users, user groups, or program groups). The Security Officer or the Site Management Complex (SIMAN) Administrator should be the only users allowed to grant or deny access permissions to objects. [§ 2.1, § 5.6, § 5.6.4, Defense Information Systems Agency UNISYS Security Technical Implementation Guide Version 7 Release 2, 28 August 2006]
Other Configuration Guidance
The System Administrator must ensure security measures have been implemented to prevent security incidents from occurring. [§ 3.2, DISA Secure Remote Computing Security Technical Implementation Guide, Version 1, Release 2]
§ 2.2 (WIR3250) Configure a filter on the GMI server to block the download of prohibited file types. Ensure that all required wireless email servers and device configuration settings are implemented.
§ 3.15.2 Prohibited file types must be blocked from being downloaded on to the smartphone, including .cab, .exe, and .zip.
App B.2 Row “Site Access/URL Substitutions” under Site Access Tab, click ‘Yes’ and change from ‘local host’ to ‘www.google.com’. Localhost is blocked so that users cannot access data on the GMI host server. [§ 2.2 (WIR3250), § 3.15.2, App B.2 Row “Site Access/URL Substitutions”, DISA Wireless STIG Motorola Good Mobile Wireless Email System Security Checklist, Version 5 Release 2.3]
ISO Guidance
The system should ensure that security policy enforcement functions succeed before functions are allowed to proceed. [§ 15.10, § J.10, ISO/IEC 15408-2 Common Criteria for Information Technology Security Evaluation Part 2, 2008]
Protection Against Malicious Code. Users need to be aware that malicious code may be introduced into their environment through network connections. Malicious code may not be detected before damage is done unless suitable safeguards are implemented. Malicious code may result in compromise of security safeguards (e.g. capture and disclosure of passwords), unintended disclosure of information, unintended changes to information, destruction of information, and/or unauthorized use of system resources.
Some forms of malicious code can be detected and removed by special scanning software. Scanners are available for firewalls, file servers, mail servers, and workstations for some types of malicious code. Further, to enable detection of new malicious code it is very important to ensure that the scanning software is always kept up to date, through at least weekly updates. However, users and administrators should be made aware that scanners cannot be relied upon to detect all malicious code (or even all malicious code of a particular type) because new forms of malicious code are continually arising. Typically, other forms of safeguard are required to augment the protection provided by scanners (where they exist).
Users and administrators of systems with network connections should be made aware that there are greater than normal risks associated with malicious software when dealing with external parties over external links. Guidelines for users and administrators should be developed outlining procedures and practices to minimize the possibility for introducing malicious code.
Users and administrators should take special care to configure systems and applications associated with network connections to disable functions that are not necessary in the circumstances. (For example, PC applications could be configured so that macros are disabled by default, or require user confirmation before execution of macros.) [¶ 13.6, ISO/IEC 13335-5 Information technology — Guidelines for the management of IT Security — Part 5: Management guidance on network security, 2001]
General Guidance
The system security parameters should be configured in accordance with the organization's security policy to ensure only authorized users can gain access to the system. [¶ .17 § 3.8, ¶ .20 § 3.11, ¶ .24 § 3.12, ¶ .29 § 3.11, AICPA Suitable Trust Services Principles and Criteria]
Metrics
The metrics associated with this control are as follows:
- • Report on the percentage of systems for which approved configuration settings have been implemented as required by policy. [UCF Control ID 02097]
• Report on the percentage of systems with configurations that do not deviate from approved standards. [UCF Control ID 02098]
Copyright 2005-2009 Unified Compliance Framework™. All rights reserved.
