Workstation Security Best Practices Flashcards

1
Q

Password expiration and recovery - Workstation Security Best Practices

A
  • All passwords should expire (30 days, 60 days, 90 days, etc.)
  • Critical systems might change more frequently
  • Some organizations have a very formal recovery process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Desktop security - Workstation Security Best Practices

A
  • Require a screensaver password, lock after a timeout
  • Disable autorun through the registry
    • autorun.inf in Vista, no Autorun in Windows 7 or 8/8.1 • Consider changing AutoPlay
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Password best practices - Workstation Security Best Practices

A
  • Changing default usernames/passwords
  • Supervisor/Administrator BIOS password: Prevent BIOS changes
  • User BIOS password: Prevent booting
  • Always require passwords - No blank passwords, no automated logins
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Restricting user permissions - Workstation Security Best Practices

A
  • Everyone isn’t an Administrator
  • Assign proper rights and permissions
  • Assign rights based on groups - Difficult to manage per-user rights
  • Login time restrictions - Only login during working hours
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Disabling unnecessary accounts - Workstation Security Best Practices

A
  • Not all accounts are necessary - disable/remove the unnecessary
  • Disable interactive logins - Not all accounts need to login
  • Change the default usernames - Helps with brute-force attacks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Account lockout and disablement - Workstation Security Best Practices

A
  • Too many bad passwords will cause a lockout

* Disable user accounts - You don’t want to delete accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data encryption - Workstation Security Best Practices

A
  • Full-disk encryption - Encrypt the entire drive
  • Filesystem encryption - Individual files and folders
  • Removable media - Protect those USB flash drives
  • Key backups are critical - You always need to have a copy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Patch and update management - Workstation Security Best Practices

A
  • Keep OS and applications updated for security and stability
  • Deployment may be managed internally
  • Many applications include their own updater
How well did you know this?
1
Not at all
2
3
4
5
Perfectly