Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.


Share this Page URL
Help

Server OS hardening > Enabling and disabling services and protocols - Pg. 23

OS Hardening CHAPTER 2 23 contain user account information as well as directory services for the organiza- tion as a whole. The normal workstation may only need to have the compatws template applied as the end workstations will only be used by the regular users. The Web servers as well as the DNS servers will most likely have tight security requirements as they could be placed outside the corporate firewall in a DMZ that is accessible from the Internet. It is important to remember that the generic security templates provided by Microsoft or used in such hardening tools as Bastille UNIX will need to be further customized by an organization in order to meet their specific security requirements. MICROSOFT BASELINE SECURITY ANALYZER The Microsoft Baseline Security Analyzer (MBSA) is a free tool for small and medium-sized businesses that can be used to analyze the security state of a Windows network relative to Microsoft's own security recommendations. In addition to identifying security issues, the tool offers specific remediation guidance. MBSA will detect common security misconfigurations and missing security updates on Windows systems. The MBSA is an excellent tool that will