Is our security team right



Hi,

We are currently moving our clients systems to a new environment which
will require us to rebuild their environments from scratch onto new
hardware. The original servers were not built with any hardening
(Windows 2000) but we are going to correct this in the new environment.


Unfortunately someone in the security team has decided (presumably
cause it is easier for them) to build the standard OS and then harden
the machine. Only then are we going to be allowed to install our
applications on the servers!

Now excuse my ignorance but should it not be the other way around -
install OS, install Apps, confirm they are working, make (hardening)
security change, test app ........... if it still works continue, if it
does not then roll back hardening step and identify why it has broken
the app ????

Am I missing something? Can anyone point me to supporting documentation
which will allow me to stop this happening (and me spending weeks
trying to work out what is wrong)?

Thanks,

EddieT

.



Relevant Pages

  • Re: Problems with 2006 rollup QFE for 5.0
    ... not least of which any QFE can overwrite your changes. ... If you install the private source with PB, ... "It usually turns out to be a stale build environment ... mverhagen at embeddedfusion dot com ...
    (microsoft.public.windowsce.platbuilder)
  • Re: Cannot connect to network now...
    ... > Brian Coiley wrote: ... >>command prompt. ... install to pick up anything that may have bombed out first time around. ... > environment, that's probably not a big deal, but with 10,000 machines, ...
    (Debian-User)
  • Re: install_driver(Oracle) failed: wrong ELF class: DynaLoader.pm
    ... i set the environment in my skript, the libs are installed correctly - or the script won't run interactively. ... LOGNAME -> oracle ... Install 32-bit Perl or 64-bit client libraries. ...
    (perl.dbi.users)
  • Re: Lost dev environment
    ... I figured out what's causing my development environment to go south, ... VFP and it recreated the resource files. ... I don't know how it could have gotten deleted, unless Install Shield ... When you copied your exes to the setup directory did you ...
    (microsoft.public.fox.programmer.exchange)
  • Re: Running more than one service on one box
    ... environment to create and maintain a security posture. ... especially apparent while hardening a host. ... Maintaining a security posture in this monolithic environment adds ...
    (Security-Basics)