Re: Is our security team right




<eddieturbo@xxxxx> wrote in message
news:1148382797.776230.322330@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Unfortunately someone in the security team has decided (presumably
cause it is easier for them) to build the standard OS and then harden
the machine. Only then are we going to be allowed to install our
applications on the servers!

Now excuse my ignorance but should it not be the other way around -
install OS, install Apps, confirm they are working, make (hardening)
security change, test app ........... if it still works continue, if it
does not then roll back hardening step and identify why it has broken
the app ????

Am I missing something? Can anyone point me to supporting documentation
which will allow me to stop this happening (and me spending weeks
trying to work out what is wrong)?

Sorry, I don't see any problem with the way they are planning to do it. I'm
also not sure how it will harm you if it is done this way. You're going to
have to research what the problem is no matter what way it is done. They're
not going to make one change, then let you test, then make another change.
They're going to apply them all at once. MS has some tools that can make
this process easier, especially for Windows 2003 and XP, and filemon and
regmon from www.sysinternals.com may help too. A good migration plan such
as keeping the old servers online until the new servers are validated as
working may also help prevent pain. But either way, migrating can mean some
unavoidable pain.



.



Relevant Pages

  • Re: book recommendation to install AND harden/secure LAMP (linux, apache, mysql, php)?
    ... > I've been programming php for a while and now need to learn to install & ... > harden a LAMP server. ... > and walks them step-by-step through installing and hardening LAMP. ... try to find a local linux user group and attend: ...
    (alt.computer.security)
  • Re: Linux Hardening
    ... > Anyone know where I can find step-by-step documentation ... > on Hardening RH Linux boxes? ... to remove the rpm-version and install them from source (that way you have ...
    (Focus-Linux)
  • Re: Linux Hardening
    ... > Anyone know where I can find step-by-step documentation ... > on Hardening RH Linux boxes? ... to remove the rpm-version and install them from source (that way you have ...
    (Security-Basics)
  • Re: Update says key is invalid, I KNOW its not!
    ... Maybe you should defer the hardening until /after/ you install all of the ... > update had to validate this version of windows, ... > product key error. ...
    (microsoft.public.win2000.windows_update)
  • Update says key is invalid, I KNOW its not!
    ... I did a complete wipe/fresh install of Win2K Pro, ... I thought maybe this was due to steps in the hardening, ... and it still says I have an invalid product key. ... I realize I can get the fixes by using Automatic Update instead of doing it ...
    (microsoft.public.win2000.windows_update)