Security Basics mailing list archives

Re: Security Standards


From: John Morrison <john.morrison101 () googlemail com>
Date: Thu, 7 Jan 2010 19:27:28 +0000

It looks like you are the leader in this field. Not even MS has any
information about this. You could start with the Windows Server 2003
and Windows Vista guides and create your own check lists to
distribute. It seems that nobody else with a business that relies on
card transactions is as brave as you and has not got to the point of
deploying these new technologies.

2010/1/7 Youngquist, Jason R. <jryoungquist () ccis edu>:
I've looked at both the NSA and Center for Internet Security sites and they don't have any checklists for Windows 
Server 2008 and Windows 7.  Thoughts on where to find checklists for these two operating systems?

Thanks.
Jason Youngquist


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Boyd, Chad
Sent: Wednesday, January 06, 2010 3:30 PM
To: s0h0us () yahoo com; security-basics () securityfocus com
Subject: RE: Security Standards

The baseline that we used were the NSA Security Configuration Guides:
http://www.nsa.gov/ia/guidance/security_configuration_guides/operating_systems.shtml

They do a great job of telling you what settings to change for various scenarios. These, of course, should be 
modified to your environment, but these are a great jumping-off point.


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of s0h0us () yahoo com
Sent: Wednesday, January 06, 2010 1:30 PM
To: security-basics () securityfocus com
Subject: Security Standards

Hi,
As part of a PCI-DSS risk assessment I need to come up with security standards for all of our critical network 
devices, including windows servers. I've been directed to NIST publications and others but I'm finding that they are 
general documents rather than specific ones regarding what settings need to be configured, i guess like a checklist. 
can you recommend a site that might have them? i continue to search as i submit this posting...thanks! any 
information is appreciated. happy new year!!!


sOhO

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: