Locking Down Windows Clients

For Windows clients, always follow the fundamental lockdown principles explained earlier. MBSA helps by detecting whether any service packs, security patches, or hot fixes need to be installed. It will also check local passwords for certain known weaknesses, such as blank passwords.

Format Disk Drives Using NTFS

All disk drives should be formatted using NTFS. NTFS can be used to ensure that only authenticated and authorized users can read or change files and folders. In addition, files and folders can be secured so that only members of certain security groups can access them. For example, Chapter 1 discussed how to store a private key in a file. The file can be secured by restricting its access to only certain Windows ...

