Re: Best Practice for Screen Savers

From: Chris Berry (compjma@hotmail.com)
Date: 09/11/02


From: "Chris Berry" <compjma@hotmail.com>
To: security-basics@securityfocus.com
Date: Wed, 11 Sep 2002 13:36:16 -0700


    Don't take personal offense to this, perhaps your security requirements
are different than ours.
<flame>
    I have to ask, "ARE YOU INSANE?", you can't just recommend something
without enforcing it. Try that and you'll have people running around with
every port in the box wide open, passwords that are blank or sticky noted to
the screen, unlocked workstations, kazaa running rampant through your
system, rains of fire from the sky, dogs and cats living together, its the
end of the world, run for your lives.
</flame>
    Seriously though, while you should do your best to co-operate with the
deparment heads and such, no enforcement means no security as far as I can
see.

>From: Gene Yoo <gyoo@attbi.com>
>To: Chris Hylen <chris.hylen@unigard.com>
>CC: security-basics@securityfocus.com
>Subject: Re: Best Practice for Screen Savers
>Date: Tue, 10 Sep 2002 20:17:19 -0700
>
>IMHO - Rather than being Draconian about mandating certain aspects of user
>preference, I think suggesting to user that "best practice" is XYZ.
>Something like "IT recommends that best practice for screen saver password
>between 10-15 minutes..." Perhaps having a little lunch and learn with
>each department on a monthly basis to do a lunch and learn about how they
>could utilize and secure their PC's more effectively, etc...
>Chris Hylen wrote:
>
>>Security Pro's-
>>
>> I am looking for any best practice info or case studies on what to
>>set my companies screen saver password timeout to. It is currently 10
>>minutes and I want to know if this is reasonable or if it is to stringent.
>>Any comments welcome.
>>
>>Thanks,
>>
>>-Chris
>>

Chris Berry
compjma@hotmail.com
Systems Administrator
JM Associates

"Ask me for the impossible and I'll do it immediately, miracles take a
little longer."

_________________________________________________________________
Chat with friends online, try MSN Messenger: http://messenger.msn.com