NIST SP800-68r1:Windows XP安全配置指南

需积分: 9 0 下载量 191 浏览量 更新于2024-07-16 收藏 1.37MB PDF 举报
"NIST SP800-68r1.pdf" 是一份由美国国家标准与技术研究所(NIST)发布的指南,旨在帮助IT专业人员在不同环境下安全配置Windows XP工作站、移动计算机和远程办公计算机。这份指南专门针对运行Service Pack 2 (SP2)或Service Pack 3 (SP3)的Windows XP Professional系统。它提供了Windows XP的安全特性详解,流行应用程序的安全配置指南,以及Windows XP操作系统本身的配置指南。 该文档的主要目标是推荐并解释经过测试的安全设置,以简化在小型办公室/家庭办公室(SOHO)、企业、特殊安全有限功能(SSLF)、遗留和联邦桌面核心配置(FDCC)五种环境下的Windows XP系统安全提升的管理负担。所提出的控制措施与NIST SP 800-53中表示的IT系统的最低安全控制一致。此指南及其关联模板是为了支持NIST的国家检查表计划而创建的。 NIST SP800系列标准是美国政府对信息技术系统安全的权威指导,其中SP800-68r1聚焦于Windows XP的安全配置,为IT专业人士提供了实施每项推荐安全设置的方法。作者包括Karen Scarfone、Murugiah Souppaya和Paul M. Johnson,他们都是在计算机安全领域有着深厚经验的专家。 该文档详细阐述了如何根据NIST的建议来保护Windows XP系统,包括但不限于设置防火墙、更新和补丁管理、用户权限管理、数据加密、审计日志记录等方面。此外,它还讨论了如何在SOHO环境中确保家庭办公室设备的安全,以及在企业环境中如何实现更高级别的安全策略。对于SSLF环境,它提出了更为严格的安全限制,以减少攻击面。对于遗留系统,指南提供了解决方案以应对旧版软件和硬件的安全挑战。最后,FDCC是联邦机构的标准配置,旨在标准化联邦政府的桌面安全。 NIST SP800-68r1是IT专业人员维护和增强Windows XP系统安全的重要参考文献,提供了实用的步骤和建议,有助于确保这些系统在不断演变的威胁环境中保持安全。
2020-02-21 上传
The information security concern regarding information disposal and media sanitization resides not in the media but in the recorded information. The issue of media disposal and sanitization is driven by the information placed intentionally or unintentionally on the media. Electronic media used on a system should be assumed to contain information commensurate with the security categorization of the system’s confidentiality. If not handled properly, release of these media could lead to an occurrence of unauthorized disclosure of information. Categorization of an information technology (IT) system in accordance with Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems1, is the critical first step in understanding and managing system information and media. Based on the results of categorization, the system owner should refer to NIST Special Publication (SP) 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations2, which specifies that “the organization sanitizes information system digital media using approved equipment, techniques, and procedures. The organization tracks, documents, and verifies media sanitization and destruction actions and periodically tests sanitization equipment/procedures to ensure correct performance. The organization sanitizes or destroys information system digital media before its disposal or release for reuse outside the organization, to prevent unauthorized individuals from gaining access to and using the information contained on the media.” This document will assist organizations in implementing a media sanitization program with proper and applicable techniques and controls for sanitization and disposal decisions, considering the security categorization of the associated system’s confidentiality. The objective of this special publication is to assist with decision making when media require disposal, reuse, or will be leaving the effective control of an organization. Organizations should develop and use local policies and procedures in conjunction with this guide to make effective, risk-based decisions on the ultimate sanitization and/or disposition of media and information. The information in this guide is best applied in the context of current technology and applications. It also provides guidance for information disposition, sanitization, and control decisions to be made throughout the system life cycle. Forms of media exist that are not addressed by this guide, and media are yet to be developed and deployed that are not covered by this guide. In those cases, the intent of this guide outlined in the procedures section applies to all forms of media based on the evaluated security categorization of the system’s confidentiality according to FIPS 199.
2020-02-21 上传
The information security concern regarding information disposal and media sanitization resides not in the media but in the recorded information. The issue of media disposal and sanitization is driven by the information placed intentionally or unintentionally on the media. With the advanced features of today’s operating systems, electronic media used on a system should be assumed to contain information commensurate with the security categorization of the system’s confidentiality. If not handled properly, release of these media could lead to an occurrence of unauthorized disclosure of information. Categorization of an information technology (IT) system in accordance with Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, is the critical first step in understanding and managing system information and media. Based on the results of categorization, the system owner should refer to NIST Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems, which specifies that, “the organization sanitizes information system digital media using approved equipment, techniques, and procedures. The organization tracks, documents, and verifies media sanitization and destruction actions and periodically tests sanitization equipment/procedures to ensure correct performance. The organization sanitizes or destroys information system digital media before its disposal or release for reuse outside the organization, to prevent unauthorized individuals from gaining access to and using the information contained on the media.”