Sms And Operating System Hardening Guidelines - Alcatel-Lucent Security Management Server (SMS) Installation Manual

Release 9.4
Table of Contents

Advertisement

SMS Hardening Guidelines

SMS and Operating System Hardening Guidelines

.........................................................................................................................................................................................
General SMS hardening recommendations
For maximum security, Alcatel-Lucent recommends that the management platform (SMS)
be placed on its own server in a secure zone protected by an Alcatel-Lucent VPN Firewall
®
Brick
Security Appliance. The administrator would then utilize the Alcatel-Lucent SMS
platform to configure the administrativezone using the pre-defined rulesets (refer to the
Pre-Configured VPN Firewall Brick® Device Zone Rulesets appendix in the SMS Policy
Guide for additional information.
In addition to the above recommendation, the underlying operating system on which the
SMS is installed should be hardened. This will provide an additional layer of security from
internal attacks as well as an added layer of security for networking environments, where
the customer is not in a position to deploy a Brick device with an administrativezone.
Operating system hardening recommendations
The following are recommendations for hardening the underlying operating system for
platforms that are running the Alcatel-Lucent SMS or Remote Navigator applications:
Ensure that you are running the latest patches from the operating system vendor.
Implement the hardening guidelines recommended by your operation system platform
vendor.
Ensure that only the required services are running on the platform.
If additional applications are running on the system being used for the Alcatel-Lucent
SMS and/or Remote Navigator products, ensure that the latest patches and any specific
hardening guidelines for those other applications are implemented.
Implement higher security passwords for system login, application login, and remote
management capabilities.
Recommended patches
As vulnerabilities may get published frequently, it is recommended that you regularly
review the Sun
ensure that new patch updates are downloaded and installed whenever necessary.
...................................................................
112
®
®
®
Solaris
, Microsoft
®
Windows
, and Microsoft
®
®
Vista
support facilities to

Advertisement

Table of Contents
loading

This manual is also suitable for:

Security management server 9.4

Table of Contents