Guide to general server security

Karen A. Scarfone, W Jansen, M C Tracy · 2008

The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation's measurement and standards infrastructure.ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology.ITL's responsibilities include the development of technical, physical, administrative, and management standards and guidelines for the cost-effective security and privacy of sensitive unclassified information in Federal computer systems.This Special Publication 800-series reports on ITL's research, guidance, and outreach efforts in computer security and its collaborative activities with industry, government, and academic organizations.Certain commercial entities, equipment, or materials may be identified in this document in order to describe an experimental procedure or concept adequately.Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose. National Institute of Standards and Technology Special Publication 800-123Natl.Inst.Stand.Technol.Spec.Publ.800-123, 53 pages (Jul.2008)Organizations should implement appropriate security management practices and controls when maintaining and operating a secure server.Appropriate management practices are essential to operating and maintaining a secure server.Security practices entail the identification of an organization's information system assets and the development, documentation, and implementation of policies, standards, procedures, and guidelines that help to ensure the confidentiality, integrity, and availability of information system resources.To ensure the security of a server and the supporting network infrastructure, the following practices should be implemented: Organization-wide information system security policy Configuration/change control and management Risk assessment and management Standardized software configurations that satisfy the information system security policy Security awareness and training Contingency planning, continuity of operations, and disaster recovery planning Certification and accreditation.Organizations should ensure that the server operating system is deployed, configured, and managed to meet the security requirements of the organization.The first step in securing a server is securing the underlying operating system.Most commonly available servers operate on a general-purpose operating system.Many security issues can be avoided if the operating systems underlying servers are configured appropriately.Default hardware and software configurations are typically set by manufacturers to emphasize features, functions, and ease of use, at the expense of security.Because manufacturers are not aware of each organization's security needs, each server administrator must configure new servers to reflect their organization's security requirements and reconfigure them as those requirements change.Using security configuration guides or checklists can assist administrators in securing servers consistently and efficiently.Securing an operating system initially would generally include the following steps:Patch and upgrade the operating system Remove or disable unnecessary services, applications, and network protocols Configure operating system user authentication ES-2 GUIDE TO GENERAL SERVER SECURITY Configure resource controls Install and configure additional security controls, if needed Perform security testing of the operating system.Organizations should ensure that the server application is deployed, configured, and managed to meet the security requirements of the organization.In many respects, the secure installation and configuration of the server application will mirror the operating system process discussed above.The overarching principle is to install the minimal amount of services required and eliminate any known vulnerabilities through patches or upgrades.If the installation program installs any unnecessary applications, services, or scripts, they should be removed immediately after the installation process concludes.Securing the server application would generally include the following steps:Patch and upgrade the server application Remove or disable unnecessary services, applications, and sample content Configure server user authentication and access controls Configure server resource controls Test the security of the server application (and server content, if applicable).Many servers also use authentication and encryption technologies to restrict who can access the server and to protect information transmitted between the server and its clients.Organizations should periodically examine the services and information accessible on the server and determine the necessary security requirements.Organizations should also be prepared to migrate their servers to stronger cryptographic technologies as weaknesses are identified in the servers' existing cryptographic technologies.For example, NIST has recommended that use of the Secure Hash Algorithm 1 (SHA-1) be phased out by 2010 in favor of SHA-224, SHA-256, and other larger, stronger hash functions.Organizations should stay aware of cryptographic requirements and plan to update their servers accordingly.Organizations should commit to the ongoing process of maintaining the security of servers to ensure continued security.Maintaining a secure server requires constant effort, resources, and vigilance from an organization.Securely administering a server on a daily basis is an essential aspect of server security.Maintaining the security of a server will usually involve the following actions:Configuring, protecting, and analyzing log files on an ongoing and frequent basis Backing up critical information frequentlyEstablishing and following procedures for recovering from compromise Testing and applying patches in a timely manner Testing security periodically.

Read the paper · More papers on PaperTik