S 4.105 Initial measures after a Unix standard installation

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator

For most Unix systems, a default installation does not meet the requirements for secure operation of the system. Here, the manufacturers often enable too many security-critical services and configurations and/or grant them rights that are too wide-ranging.

The following overview is intended to generically demonstrate how a default installation can be protected:

All changes made should be documented carefully, and a change should only be made after all system administrators agree to the change. This documentation can be in paper form or stored in a file on the corresponding system. It should be possible, though, to read and update the documentation at any time (see also S 2.34 Documentation on changes made to an existing IT system).

Review questions: