Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


August 1997

Windows NT Security Guide


RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

The ins and outs of NT's native security features

Computer security is a hot topic this year, no matter what operating system you use. Your Windows NT system is not immune to security problems, and you may wonder how to secure your system better. Stephen A. Sutton's book, Windows NT Security Guide, will help your NT security endeavors. Sutton is president of Trusted System Services and has a reputation as knowledgeable in the NT security field. His book is a fairly detailed guide to the ins and outs of NT's native security features.

The book covers everything from accounts and domains to recommendations about how to secure installation. The Guide has three basic parts: general information targeted at day-to-day NT users; administration, written for systems administrators; and assessment, designed for people who need to know whether NT is secure enough for their requirements.

Let's quickly peek at each section. In Part 1, "General Use," Sutton discusses user accounts, NT domains, working environment, access control lists, and special situations such as using NT's Remote Access Service (RAS). This part of the book is very useful, especially for those new to NT's security features.

The next section, "Administration," covers planning NT domains, managing groups and accounts, security auditing, the Internet and intranets, trusted computing bases, and NT subsystems such as the Registry. This section finishes with a chapter called "Summary and Checklist." A would-be administrator will find information that will assist in building a good NT domain model and in managing users, groups, and resources adequately. The administration section is similar to Mark Minasi's Mastering Windows NT Server, except that Sutton writes from an acute security perspective, offering detailed information about each security dialog item. The closing "Summary and Checklist" chapter is a handy quick reference list to the complete administration section.

Part 3, "Assessment," consists of one chapter devoted to NT security. This section discusses the Trusted Computer System Evaluation Criteria (TCSEC--better known as the Orange Book--a government gauge for security) as it pertains to NT; networking using TCSEC; and a broad brush of NT security, feature by feature.

The Guide also contains an appendix on secure installations of NT. I found this section the most useful one of the book. The eight pages provide excellent how-to information for almost anyone who is installing an NT system. This appendix covers Registry settings, file systems access control lists (ACLs), user rights policies, and a few miscellaneous items such as disabling booting from floppy disks and limiting access to system-shutdown features.

Overall, Sutton's Guide is useful because it describes each of NT's internal security features. However, the book focuses almost exclusively on teaching the reader about the security features of NT, without much regard to building a secure network or connecting to untrusted networks. You will not learn much from this book about firewalls, proxy servers, virtual private networking, or other functions that you may need to build your NT network environment. Although the book contains a chapter entitled "The Internet and Intranets," half of the chapter very generally describes the types of attacks your network may experience, and the other half quickly discusses some of Microsoft's Internet Information Server (IIS) security concerns.

If you're new to NT security, Sutton's Windows NT Security Guide will help you get started. The book definitely provides valuable information about a hands-on approach to NT security administration, but you'll probably find yourself wanting to learn much more about building a secure computing environment--especially if you're connecting to the Internet or to a business partner's network.

Windows NT Security Guide
Author: Stephen A Sutton
Publisher: Addison-Wesley Developers Press, Reading, Mass, 1997, ISBN 0-201-4196-9
Price: $29.95, 373 pages

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Microsoft Kills OneCare, Will Launch Free Security Solution

Microsoft on Tuesday announced that it would retire its $50-a-year security subscription product, Windows Live OneCare, and replace it with a free solution codenamed "Morro." Unlike OneCare, however, Morro will focus only on core anti-malware features and ...

The website is down because someone removed the X-Box

What happens when a manager mistakes a server for a games console. ...

Xbox 360 Overhaul Arrives with New UI, Avatars

Xbox 360 owners who logon to the system's Xbox Live system this morning will receive the most significant functional change yet to the console's user interface, or dashboard. Dubbed the New Xbox Experience, this new front-end features a completely new ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing