Commentary

Alexander Wolfe
 

Spy Agency Posts Windows, OS X Security Guides

Who should know more about security than the National Security Agency? (Hey, it's their middle name!) No one, presumably. Which is why you might want to check out a series of security configuration guides the NSA has posted for Windows XP, 2000, Mac OS X, and Sun Solaris.

Who should know more about security than the National Security Agency? (Hey, it's their middle name!) No one, presumably. Which is why you might want to check out a series of security configuration guides the NSA has posted for Windows XP, 2000, Mac OS X, and Sun Solaris.Before you get all excited--and I was, when I first read about this on Digg--be aware that there's probably less here than meets the eye.

Specifically, I was disappointed when I finally downloaded (the site was slow going, probably due to the Digg-driven traffic) the Windows XP security guide, to find out that it was a document prepared by Microsoft. That's not to say it's bad; there are 200 pages worth of detailed information for admins interesting in configuring a secure set-up. It's just that there was no spy agency value-add.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

That's not the case for the 69-page Mac OS X security guide, which has the NSA logo emblazoned on the title page, and a big red "Unclassified" stamp on each page, too.

I loved the warning near the beginning: "Do not attempt to implement any of the settings in this guide without first testing in a non-operational environment.

A closer examination indicates that there's no intelligence-community mystery behind the NSA's OS X security advice. It's common-sense things like maintaining good user-account controls, auditing your log files, keeping track of network services, and managing security certificates.

If I learned anything from my time spent on the NSA site today, it's that there's probably nothing about implementing a decent security policy that you don't already know. The hard parts are a) implementing it throughout your IT structure and b) (even tougher) getting people to comply with the stuff that's under their control. Don't get me started on people connecting their thumb drives to their PCs, or bringing in unauthorized CDs.

Finally, as this post tilts ever further away from its original intent, did you know that the NSA has a kids' page? Neither did I. It's entitled "America's Cryptokids: Future Codemakers and Codebreakers."


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links