S 2.404 Creating a security concept for directory services

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: IT Security Officer

A security concept must be created for the directory service. The security concept specifies which services, components etc. may (and should) be used and in which manner. The following list provides a rough overview of the areas to be regulated in the concept. The list needs to be adapted, specified in detail, and expanded according to the operational scenarios existing in the organisation. These specific security policies must be in agreement with the organisation's overall security concept.

General information:

Assigning rights:

Administration:

Data communication:

Certificate authority:

File system of the underlying operating system:

LDAP:

Client access to the directory service:

Encryption of attributes:

Remote access to the system monitor and administration:

The aspects described here need to be examined in more detail in a security policy for directory services (see S 2.405 Drawing up a security policy for the use of directory services).

Review questions: