Appendix A Understanding CiscoWorks Security
General Security
A-2
User Guide for CiscoWorks Common Services
78-16571-01
General Security
The CiscoWorks Server provides an environment that allows the deployment of
web-based network management applications.
Web access provides an easy-to-use and easy-to-access computing model that is
more difficult to secure than the standard computing model that only requires a
system login to execute applications.
The CiscoWorks Server also provides security mechanisms (authentication and
authorization) used to prevent unauthenticated access to the CiscoWorks Server
and unauthorized access to CiscoWorks applications and data.
However, CiscoWorks applications can change the behavior and security of your
network devices. Therefore, it is critical to limit access to applications and servers
as follows:
•
Limit access to personnel who need access to applications or the data that the
applications provide.
•
Limit CiscoWorks Server logins to just the systems administrator.
•
Limit connectivity access to the CiscoWorks Server by putting it behind a
firewall.
Server Security
The CiscoWorks Server uses the basic security mechanisms of the operating
system to protect the code and data files that reside on the server.
The
following
CiscoWorks Server security control elements apply:
•
Server–Imposed Security
•
System Administrator-Imposed Security
Server–Imposed Security
The CiscoWorks Server has many dimensions, such as:
•
Files, File Ownership, and Permissions
•
Runtime