![]() |
Networks - Minimum Desktop Requirements |
|
Summary of minimum requirements for desktop connectivity. 1. Automatic Software Patch Updates*2. Anti-virus software* 3. Host-based firewall* 4. Passwords 5. No unencrypted authentication 6. No unauthenticated email relays 7. Network connectivitiy 8. Physical security 9. Unnecessary services 10. Remote session encryption 11. Deploy computers with standard burn 12. Non-Compliance * Done in standard load Detail of minimum requirements for desktop connectivity. *1. Automatic Software Patch UpdatesAll machines must be up to date with security patches. Windows campus networked devices must be configured to use the CWU Patch Server to maintain patching. Macintosh patching will be available from a local OS/X server in 2005. *2. Anti-virus softwareAnti-virus software must be installed, running and kept up to date. 3. Host-based firewallHost-based firewalls must be at a minimum:
4. PasswordsAccess to CWU hosts, networks and computing must require password authentication. Passwords must meet minimum complexity standards. Remove or disable default accounts. Required password authentication after being idle for more than 20 minutes. (Screen saver password.) All default passwords must be changed. 5. No unencrypted authenticationHistorically insecure services such as Telnet, FTP, SNMP, POP, and IMAP must be replaced by their encrypted equivalents. 6. No unauthenticated email relaysUnauthenticated email relays can cause problematic bandwidth usage and inappropriate email appearing to come from campus. Relays may be exploited to allow use of devices for other unauthorized activities, in a manner similar to virus attacks. System administrators should migrate to user-authenticated SMTP services. Campus devices must not provide an active SMTP service that allows unauthorized third parties to relay e-mail messages. 7. Network connectivitiyDevices which extend the network such as but not limited to hubs, switches, bridges, routers and access points or computers functioning as such may only be connected by the Networks and Operations department within Information Technology Services only. Users (students, faculty and staff) may connect computers and printers to the network. 8. Physical securityUnauthorized physical access to an unattended device can result in potentially dangerous situations. In light of this, where possible and appropriate, devices must be configured to "lock" and require a user to re-authenticate if left unattended for more than 20 minutes. Mission-critical systems must be located in a secure location accessible only to authorized personnel. 9. Unnecessary servicesIf a service is not necessary for the intended purpose or operation of the device, that service shall not be running. (SNMP, Universal Plug & Play, WWW, FTP) 10. Remote session encryptionUsers accessing trusted or privileged connections to resources must use strong encryption, such as a VPN. 12. Deploy computers with standard burnStandard burns for PC's are here and standard burns for MAC's are here. Machines burned with a standard load are consistent, easier to manage security and to predict or identify use outside the norm.11. Non-ComplianceCompromised network devices will be disconnected from the network. Action may be taken to restrict or remove network access to devices not found to be in compliance with the minimum requirements. |
||
| Contact Information
ITS - Networks 400 E. University Way Ellensburg, WA 98926 Phone (509) 963-2924 Email: networks@cwu.edu |
| Central Washington University | 400 E. University Way, Ellensburg WA 98926 | This Site Optimized For Newer Browsers. |