Educause Security Discussion mailing list archives

Re: Secure Server Procedure


From: "Casas, Victoriano (ISO)" <vcasas () AUSTIN UTEXAS EDU>
Date: Tue, 27 Feb 2007 11:56:35 -0600

Charlie,
We used the CIS docs as a basis to our Hardening Checklist:
http://security.utexas.edu/admin/

G'luck,
Victoriano Casas III, MPA, CISSP
Information Security Office
The University of Texas at Austin
security.utexas.edu
v 512.232.9371 

-----Original Message-----
From: Brian Smith-Sweeney [mailto:bsmithsweeney () NYU EDU] 
Sent: Tuesday, February 27, 2007 10:42 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Secure Server Procedure

I would suggest checking out http://www.cisecurity.com/ for 
these types of standards.  You can either adopt a standards 
doc whole-hog, or pick-and-choose what you think is 
appropriate for your purposes.

Cheers,
Brian

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Brian Smith-Sweeney      Sr. Network Security Analyst
ITS Technology Security Services, New York University 
bsmithsweeney () nyu edu http://www.nyu.edu/its/security 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Charlie D. Kutil wrote:
We are defining some new servers that we wish to classify as Secure 
Servers.  We have a policy in place for server hardening, 
however we 
do not have a step based procedure or checklist. Is anyone 
willing to 
share their procedure for developing a Secure Server?

Thank you,
Charlie Kutil

Charlie Kutil, M.P.H., CISSP
Information Policy & Security Officer
Office of Information Technology (OIT) Texas A&M Health 
Science Center 
Coastal Bend Health Education Center
(O) 361-825-2805
(C) 361-876-3781
  


Current thread: