Home > Midmarket CIO Tips > Security for the midmarket > Checklist: Harden access control settings
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Checklist: Harden access control settings


SearchWindowsSecurity.com
07.21.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip originally appeared on SearchWindowsSecurity.com, a sister site of SearchSMB.com.


Whether you're protecting sensitive data from malicious outsiders or preventing internal users from accessing systems not assigned to them, you have your work cut out for you when it comes to access control. This collection of checklists written by Roberta Bragg will help you along your way. She details specific steps to take in locking down default Windows access control settings and offers access control best practices.


  • Three security mandates for any Windows environment
    Find out what you must do to lock down standalone computers, workgroup computers and Active Directory domains using Security Options

  • Block anonymous access
    You can change Windows account names to obscure them from attackers, but account SIDs can still be obtained using anonymous access. Foil intruders with this checklist.

  • Seven steps to properly set account lockout
    Is it riskier to set account lockout or not? Weigh the pros and cons of using account lockout at all, and then get seven steps for making these settings work to your advantage in this checklist by Roberta Bragg.

  • Restrict access to prevent insider hacks
    Internal security threats often prove to be more malicious than all the people on the Internet. Get help protecting Windows from fellow coworkers and employees in this checklist.

  • Set account options to limit systems access
    Granting access to Windows systems is a privilege -- not a right. Limit access wherever possible by hardening account options, starting with the settings in this checklist.

  • Tighten default settings to prevent unauthorized access
    One of the simplest ways to avoid common attacks is to modify Windows system default settings for network connections. Site expert Roberta Bragg identifies four important settings to disable right away.


    About the author: Roberta Bragg is author of "Hardening Windows systems." She is an MCSE, CISSP and Microsoft MVP, and a well-known information systems security consultant, columnist and speaker.


    More information from SearchWindowsSecurity.com

  • Learning Guide: Access control
  • Ask the Experts Archives: Tips for controlling access to the server
  • Checklists: Click for the complete collection of Roberta Bragg's Windows Security Checklists


  • Rate this Tip
    To rate tips, you must be a member of SearchCIO-Midmarket.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Information security management for the midmarket
    Mobile device management: From business apps to device security
    Test your knowledge: IT quizzes for midmarket CIOs
    Droid does, but will IT support it?
    Information security program revamp adds outsourcer oversight and more
    From data breaches to risk management frameworks: Test your knowledge
    The challenge of managing risk when IT budgets tighten
    Why cybersecurity awareness is everyone's responsibility
    Information technology management e-book downloads for midmarket CIOs
    10 must-have steps for an effective SMB information security program
    Your IT security budget: How to get more bang for the buck

    Risk management for the midmarket
    CIO resources: Top five technology topics of 2009
    Information security program revamp adds outsourcer oversight and more
    From data breaches to risk management frameworks: Test your knowledge
    Adopting a beta tool: Risks vs. rewards for a midsized enterprise
    The challenge of managing risk when IT budgets tighten
    Why cybersecurity awareness is everyone's responsibility
    How to decide if changing technology vendors is worth the time, risk
    A guide to managing the risk assessment process
    Free risk management tools and resources for the enterprise
    CIOs taking risk of cutting vendor maintenance contracts to save money

    Security tools for the midmarket
    Why CIOs need to get real about identity and access management in 2010
    Free risk management tools and resources for the enterprise
    IT security spending a bright spot in '09, with more growth predicted
    Security and risk management in the midmarket
    Identity and access management planning guide for the midmarket
    A CIO's advice for implementing single sign-on solutions
    Options for outsourcing security grow, offer IT budget savings
    Network access control: Pointers for getting the knack of NAC
    Unified communications: Securing access to OCS
    Unified communications security: How safe is it?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    risk assessment framework (RAF)  (SearchCIO-Midmarket.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts