Ethical administration

From: Manish Jain (manishj@eapglobal.com)
Date: 09/22/02


From: "Manish Jain" <manishj@eapglobal.com>
Date: Sun, 22 Sep 2002 08:02:37 -0700


Hi Mark,
You can enable complex password policy in windows 2000
security policies to ensure that all the users have a
complex combination of password. For auditing purpose, if
your company is willing to spend some money you can buy
ISS System Scanner for your DC and run the tool on the
server. It will give you the exact picture of your domain
passwords along with the other security related weakness.

Thanks & Regards,
___________________________
Manish Jain
Information Security Consultant
EAP Global
270/1, Lloyds Road, Royapettah,
Chennai, TN. 6000014. INDIA
T +91 44 8130001
M +91 98402 95210
F +91 44 8130815
http://www.eapglobal.com
manishj@eapglobal.com

>-----Original Message-----
>following on from my previous post about password
auditing, are there any
>guidelines to doing this ethically? I realise I
shouldn't include senior
>managers and the like but is there anything else I
should consider?
>
>cheers
>
>Mark
>
>
>.
>



Relevant Pages

  • Audit GP settings, strange situation
    ... setted some domain security policies that are functioning ... (likw account settings), but when I set an auditing ... policy + (folder auditing settings)+ ... Security policies are propagated with warning. ...
    (microsoft.public.win2000.group_policy)
  • RE: Auditing Log On not working-Win2kPro
    ... Auditing Log On not working-Win2kPro ... Are they audited for failure and success or only one of them? ... yes, Dave, I'll give it a shot. ... Mark Sargent. ...
    (Security-Basics)
  • Re: Minimum Password Length HPUX 10.2
    ... I guess you need to turn on TCB. ... sam choose auditing and security then security policies. ...
    (comp.sys.hp.hpux)