| SECURITY (SERVERS) |
- Install latest Security Updates.
- Set password policies and expirations.
- Turn on and monitor security auditing. Check for failed
admin log-ins and other signs of attempted security breaches.
- Limit exposure to Internet for all servers.
- Convert all Windows server FAT partitions to NTFS.
|
- Disable any unused services and TCP ports.
- Restrict anonymous access to server recources.
- Disable guest accounts and unneeded administrative accounts.
- Harden permissions on certain Windows files and directories.
- Check permissions on all shared directories.
- Set permissions on registry keys.
|
| MAINTENANCE (SERVERS) |
- Monitor disk space & clean up temp files.
- Check print spooler status & clean up old jobs.
- Install latest O/S patches and hot fixes.
- Examine and clean out O/S event logs.
|
- Make backup copy of Windows system registry.
- Create current Windows ERD (Emergency Repair Disk)
- Disable running processes that are not being used.
|
| ANTI-VIRUS |
- Establish an Anti-Virus "server" PC to receive
daily virus updates.
- Verify daily updates are being performed.
- Spot-check PC's to verify they are getting updates from
the Anti-Virus server.
|
- Check server Anti-Virus status & verify program is
working properly and updates are current.
- Check Anti-Virus log files for evidence of problems and
viruses found.
- Set-up and check weekly server Anti-Virus scan.
|
| RECOVERY & BACKUP |
- Formalize a backup plan, if one doesn't exist.
- Check configuration of scheduled backup jobs.
- Check backup logs to verify status of backups and adherance
to the backup plan.
|
- Perform a test restore from Nightly Backups.
- Create and keep up-to-date server boot/recovery disks.
- Clean tape drive.
|
|
TESTING & MONITORING
|
- Check server resources(RAM, paging, etc) and assess effect
on performance.
- Check system logs for potential problems, such as mis-configured
s/w, driver issues, printer problems, networking problems,
etc.
- Perform a test backup and restore.
|
- Run Baseline Security Analyzer on servers.
- Perform Security Vulnerability Scans on netowork, firewalls,
etc.
- Run port scans to identify open ports on servers and critical
PC's.
- Test Internet connection performance.
|
To fill out the S.M.A.R.T.
questionaire mentioned earlier, click HERE.
|