Re: C2 security standards
From: Alex Noordergraaf (alex.noordergraaf@sun.com)Date: 05/21/02
- Previous message: Gian Fabio Palmerini: "Re: C2 security standards"
- In reply to: Juan Ignacio Trentalance: "C2 security standards"
- Next in thread: Fetter, David (ETW): "RE: C2 security standards"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 21 May 2002 17:15:09 -0400 From: Alex Noordergraaf <alex.noordergraaf@sun.com> To: Juan Ignacio Trentalance <TRENTALANCE@crm.com.ar>
Juan Ignacio Trentalance wrote:
>
> Hi,
>
> Recently, I have been assigned the task of cheking that a group of sun
> solaris machines meet the C2 security standard.
>
> I have searched the focus lists and other security sites for something like
> a "C2 security checklist for solaris" whithout any luck.
And you answer why that is later in your original email. C2 doesn't mean
that systems are secure - nor do Common Criteria evals ;-(.
If you are, in fact, interested in improving the security of your
Solaris servers then you should be determining if your Solaris systems
follow security best practices and your corporate security policies.
Being C2 compliant just doesn't mean much as all the insecure protocols
can still be enabled on the system.
Would suggest you take a look at the security best practices available
from the BluePrint OnLine articles at http://sun.com/security/blueprints
and how they are implemented by the Solaris Security Toolkit (JASS)
available at http://sun.com/security/jass
There are lots of other security docs available from SecurityFocus and
other Internet sites as well...
Now - if this is just to meet some requirement which states that systems
must be C2 compliant ignore and not an attempt to improve the security
of an environment just ignore this email...
Hope this helps.
-Alex
>
> Thanks in advance,
>
> Juan
- Previous message: Gian Fabio Palmerini: "Re: C2 security standards"
- In reply to: Juan Ignacio Trentalance: "C2 security standards"
- Next in thread: Fetter, David (ETW): "RE: C2 security standards"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|