<?xml version="1.0" encoding="UTF-8" standalone="no"?><!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook V4.1//EN" "http://www.oasis-open.org/docbook/xml/4.1/docbookx.dtd">
<book>
<bookinfo>
<title>NT4 Server Security Standard</title>
<titleabbrev>LCZ-NT4-S</titleabbrev>
<edition>1.1</edition>
<pubdate>16 May 2009</pubdate>
<abstract>
<para>This document specifies technical security policy for implementations of <trademark>Microsoft</trademark> <trademark>Windows</trademark> NT4.0, and applies to domain controller implementations of NT4.0.
</para>
<para>This standard contains 12 baseline controls, and 0 above baseline controls, for a total of 12 controls.</para></abstract>
<revhistory>
<revision>
<revnumber>1.1</revnumber>
<date>16 May 2009</date>
<authorinitials>FOD</authorinitials>
<revremark>Revised for re-release</revremark>
</revision>
<revision>
<revnumber>1.0</revnumber>
<date>05 February 2003</date>
<authorinitials>LCZ</authorinitials>
<revremark>Initial Version for public release</revremark>
</revision>
</revhistory>
<copyright>
<year>2001</year><year>2002</year><year>2003</year><year>2009</year>
<holder>Frank O'Dwyer</holder>
</copyright>
<legalnotice><important><para>All of these Security Standards and Security Policies are copyrighted. THEY ARE NOT IN THE
PUBLIC DOMAIN. They are however distributed under a liberal open-source license, 
see <link linkend="publishing">Publishing these Security Standards and Policies</link>.</para></important></legalnotice><publisher><publishername>Frank O'Dwyer</publishername></publisher></bookinfo>
<chapter><title>Introduction</title>
<section><title>Objectives</title><para>The objectives of this document are:</para><itemizedlist>
<listitem><para>To specify a baseline configuration for implementations of &lt;trademark&gt;Microsoft&lt;/trademark&gt; &lt;trademark&gt;Windows&lt;/trademark&gt; NT4.0 server. 
</para></listitem>
<listitem><para>To provide guidance to administators, developers and security personnel in securely implementing &lt;trademark&gt;Microsoft&lt;/trademark&gt; &lt;trademark&gt;Windows&lt;/trademark&gt; NT4.0 server. 
</para></listitem>
</itemizedlist></section>
<section><title>Scope</title>
<para>Controls specified in this document apply to server implementations of NT4.0.
</para>
<para>All of the organisation's NT4.0  server systems
will be subject to the policies specified within
this security standard. The policies will
be applied to new and existing installations.
</para>
</section>
<section><title>Not In Scope</title>
<para>Compliance with this standard will not provide <quote>in depth</quote> security architecture or intelligent security design guidance
to projects. As a consequence, for high impact or safety-critical business applications, additional guidance will still need to be 
sought from your Information Security team consultancy function.  
</para>
<para>This is a specific standard for NT4.0 servers. Controls specific to workstation, domain controller, and generic controls common to all are not specified in this document and are the subject of separate standards.
</para>
<para>Compliance with this standard does not negate the need for an overall security review 
of a proposed application. Contact the Information Security team if you are in doubt.
</para>
</section>
<section><title>Giving Feedback</title><para>Your feedback to improve this document is welcome. Please let me know of your experiences in applying the controls and 
	guidance in this standard. Are the controls effective, easy to implement, too onerous, clear, unclear, something missing? Does an exceptional case 
need to be covered? Let me know. Please 
send your comments to frankodwyer AT netscape.net. Your comments will be 
used to produce better free security standards for the IT community.</para><para>I also request that you give feedback where you think the controls and guidance is 
correct. This will let us gauge whether or not specific controls are controversial or 
broadly acceptable to the community, and will help us to resolve cases where we have 
conflicting feedback on particular content.</para></section><section id="publishing"><title>Publishing these Security Standards and Policies</title><para>This document may be reproduced and distributed in whole or in part, free of charge, subject to the following conditions:</para><itemizedlist><listitem><para>All copyright and trademark notices, and this permission notice must be preserved complete on all complete or partial copies.</para></listitem><listitem><para>Any translation or derivative work of this document must be approved by Frank O'Dwyer in writing before distribution.</para></listitem><listitem><para>If you distribute this guide in part, instructions for obtaining the complete version of this manual must be included, and a means for obtaining a complete version provided.</para></listitem><listitem><para>Small portions may be reproduced as illustrations for reviews or quotes in other works without this permission notice if proper citation is given.</para></listitem><listitem><para>Neither Frank O'Dwyer's name nor the names of any contributors may be used to endorse or promote products derived from this document without specific prior written permission.</para></listitem></itemizedlist><para>THIS DOCUMENT IS PROVIDED BY FRANK O'DWYER AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY 
AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL FRANK O'DWYER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF 
LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.</para><para>I would like to be informed of any plans to publish or distribute these documents, just so I know how they're being used and where they are becoming available. 
	If you are publishing or distributing or planning to publish or distribute any of these documents, please send mail to frankodwyer AT netscape.net</para></section>
<section><title>Related Documents</title><para>This document should be read and applied in conjunction with the technology specific security standards that are available from the frankodwyer.com  
web site. Please note that some of the documents below are currently under development and as such may not as yet be available. Check back frequently for updates
to this document and those documents listed below.</para><section><title>Generic Security Standards</title><para><emphasis>Generic Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para><para><emphasis>Data Protection European Union Security Standard</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para><para><emphasis>Application Service Provider Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para></section><section><title>Operating System Security Standards</title><para><emphasis>Generic Unix Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Generic Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Workstation Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Server Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Domain Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para></section><section><title>Database Security Standards</title><para><emphasis>Oracle Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#db">http://www.frankodwyer.com/standards/index.html#db</ulink></para></section></section>
<section><title>Definitions</title>

<para>An <quote>Information Asset</quote> equates to any computerised information system 
or component thereof and thus includes an application, an item of off the shelf software, hardware, media, 
a data item, a data item repository and associated communications networks.</para>
<para>The specification of 
the Information Asset in question will usually be given so that this document is unambiguous, except
where a control relates to any <quote>Information Asset</quote>. </para>


<para>The use of <quote>must</quote> or <quote>will</quote> indicates what the author considers to be a mandatory control.</para>
<para>However, whether the controls listed here are mandatory for your organisation is entirely at your organisation's discretion and
thus they should be interpreted as representing the strongest recommendation of the author.</para>


<para>The use of <quote>should</quote> or <quote>recommended</quote> or <quote>ought</quote> indicates
that the author believe that the controls in question are worthwhile and should be implemented unless such
an implementation is impossible, onerous or impractical. Again, the implementation of controls so recommended
in this document is entirely at your organisation's discretion.</para>

</section>
</chapter>




<chapter><title>User Configuration</title>



<section><title>Privileges</title>
<section><title>The advanced user right to increase quotas must be held by administrators only</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-PRIV-6</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to increase quotas must be held by administrators only</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that the administrators group holds this right</para></listitem>
<listitem><para>Ensure that only administrator staff are members of the administrators group</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and services may be subject to a loss of availability</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to lock pages in memory must be held by no one.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-PRIV-7</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to lock pages in memory must be held by no one.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that no one holds this right</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and services may be subject to a loss of availability</para></listitem>
</itemizedlist></section></section>
<section><title>The user right to backup files and directories must only be held by Backup Operators</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-PRIV-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The user right to backup files and directories must only be held by Backup Operators</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that only operators are in the backup operators group</para></listitem>
<listitem><para>Ensure that the backup operators group hold the backup files and directories user right</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information may be subject to unauthorised disclosure</para></listitem>
<listitem><para>Business information may be subject to a loss of availability</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to log on as a batch job must be held by no one.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-PRIV-8</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to log on as a batch job must be held by no one.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that no one holds this right</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and services may be subject to a loss of availability</para></listitem>
</itemizedlist></section></section>
</section>

</chapter>


<chapter><title>Network Security Configuration</title>
<section><title>Network Interface Considerations</title>
<section><title>Remote Acess Server must be enabled only if required</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-NETW-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Remote Acess Server must be enabled only if required</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Disable remote access server if it is not required</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Remote access server allows users potentially to gain unauthorised remote access</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>

</chapter>




<chapter><title>Configuration</title>
<section><title>Files and File Permissions</title>
<section><title>File and directory permissions must be restricted on the basis of least privilege</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-ACCESS-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>File and directory permissions must be restricted on the basis of least privilege</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that the access permitted for each file and directory permits the minimum access permissions </para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
<section><title>Administration</title>
<section><title>Replication must be implemented only at the administrator level</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-ADMIN-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Replication must be implemented only at the administrator level</para></section><section><title>Detailed Steps</title><itemizedlist>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>

</chapter>


<chapter><title>Auditing and Monitoring</title>


<section><title>Events to be audited</title>
<section><title>Auditing should be enabled for RAS for failed authentication and authentication timeout</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-AUDIT-4</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Auditing should be enabled for RAS for failed authentication and authentication timeout</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up auditing to audit for failed authentication and authentication timeout</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
<listitem><para>Business information may be disclosed</para></listitem>
<listitem><para>Business information may be maliciously altered</para></listitem>
</itemizedlist></section></section>
<section><title>Failed attempts to delete documents in a print queue should be audited</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-AUDIT-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Failed attempts to delete documents in a print queue should be audited</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up auditing to audit for failed attempts to delete documents in a print queue</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Failed attempts to take ownership of documents should be audited</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-AUDIT-3</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Failed attempts to take ownership of documents should be audited</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up auditing to audit for failed attempts to take ownership of documents in a print queue</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
<listitem><para>Business information may be disclosed</para></listitem>
<listitem><para>Business information may be maliciously altered</para></listitem>
</itemizedlist></section></section>
<section><title>Failed attempts to change permissions on a print queue should be audited</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>copy of NT4S-AUDIT-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Failed attempts to change permissions on a print queue should be audited</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up auditing to audit for failed attempts to delete documents in a print queue</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
</chapter>
<chapter><title>Other</title>
<section><title>RAS should be set up to encrypt logon information by any remote client before sending across the network</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4S-NETW-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>RAS should be set up to encrypt logon information by any remote client before sending across the network</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>RAS should be configured to encrypt logon information by any remote client before sending across the network</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Account logon details may be compromised</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</chapter>
<chapter><title>Checklist</title><informaltable><tgroup cols="3" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="5*" colname="c2"/><colspec colwidth="1*" colname="c3"/><spanspec align="left" nameend="c3" namest="c1" spanname="hspan"/><tbody><row><entry align="center" spanname="hspan"><para><emphasis>User Configuration</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Privileges</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4S-PRIV-6</entry><entry>Is the advanced user right to increase quotas must be held by administrators only</entry><entry><para/></entry></row><row><entry>NT4S-PRIV-7</entry><entry>Is the advanced user right to lock pages in memory held by no one?</entry><entry><para/></entry></row><row><entry>NT4S-PRIV-2</entry><entry>Is the user right to backup files and directories only held by Backup Operators?</entry><entry><para/></entry></row><row><entry>NT4S-PRIV-8</entry><entry>Is the advanced user right to log on as a batch job held by any user?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Network Security Configuration</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Network Interface Considerations</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4S-NETW-1</entry><entry>If Remote Acess Server is enabled is it required?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Configuration</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Files and File Permissions</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4S-ACCESS-1</entry><entry>Are file and directory permissions restricted on the basis of least privilege?</entry><entry><para/></entry></row><row><entry spanname="hspan"><para><emphasis>Administration</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4S-ADMIN-1</entry><entry>Is replicationimplemented only at the administrator level?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Auditing and Monitoring</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Events to be audited</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4S-AUDIT-4</entry><entry>Is auditing enabled for RAS for failed authentication and authentication timeout?</entry><entry><para/></entry></row><row><entry>NT4S-AUDIT-1</entry><entry>Are failed attempts to delete documents in a print queue audited?</entry><entry><para/></entry></row><row><entry>NT4S-AUDIT-3</entry><entry>Are failed attempts to take ownership of documents audited?</entry><entry><para/></entry></row><row><entry>copy of NT4S-AUDIT-2</entry><entry>Are failed attempts to change permissions on a print queue audited?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Other</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4S-NETW-2</entry><entry>Is RAS set up to encrypt logon information by any remote client before sending across the network?</entry><entry><para/></entry></row></tbody></tgroup></informaltable></chapter></book>
