149
described below within this chapter should achieve an NIAP Evaluation Assurance Level (EAL) 4
augmented with ALC_FLR.3 and a TOE minimum function strength of SOF-medium.
3.1
Security Policy Modifications
Administrators can configure their network and HP NAS server systems to meet the
US Government's
Trusted Computer Security Evaluation Criteria (TCSEC)
C2 security requirements or the National Information
Assurance Partnership (NIAP) Common Criteria Evaluation and Validation Scheme (CCEVS) security
requirements, a.k.a Common Criteria (CC)v2.1 (ISO/ IEC15408) security requirements, by applying
all of the NSA security modifications listed within Chapter 2, “NSA Security Compliancy”, and the
following additional modifications to their HP NAS server system:
System Power-On Password
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Enabled Enabled Enabled
It is recommended that administrators created a system Power-On password within the HP NAS server
system to prevent rogue administrators and users from turning on the computer system for all three
environment configurations.
BIOS Setup Password
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Enabled Enabled Enabled
It is recommended that administrators created a BIOS setup password to prevent rogue administrators
and users from accessing the system BIOS and changing its settings for all three environment
configurations.
Physical Removal of Floppy and DVD-ROM drive
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Floppy and DVD-ROM
installed
Floppy and DVD-ROM
installed
Floppy and DVD-ROM
installed
Remove Floppy and
DVD-ROM
It is recommended that the floppy and DVD-ROM drives remain installed within all HP NAS server
systems in Legacy Client and Enterprise Client environments. However, both devices should be
removed within High Security Client environments to prevent rogue administrators and users from
booting other operating systems on to the box and accessing data.
IMPORTANT:
Within High Security Client environments, administrators must re-install the DVD-ROM
drive to use the HP NAS QuickRestore DVD to re-image of the HP NAS operating system.
Audit Privilege Use
Member Server Default
Legacy Client
Enterprise Client
High Security Client
No Auditing
Success Failure
Success Failure
Success Failure
This Audit policy value can be configured in the Domain Group Policy section of Windows Server
2003 at the following location:
Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy
The
Audit privilege use
setting determines whether to audit each instance of a user exercising a user
right. Configuring this value to
Success
generates an audit entry each time that a user right is