Workstation security: Lock down that Mac
Computerworld - Security should always be on the mind of a systems administrator. It should be part of how you build workstation images, how you configure servers, the access you grant to users and the choices you make in building your physical network.
Security, however, doesn't end once everything is rolled out; sysadmins need to remain proactive by being aware of what's going on in their networks and responding quickly to potential intrusions. Equally important, you need keep all servers, workstations and other devices updated against newly discovered security threats, viruses and attacks. And you need to keep your understanding of security techniques and risks current.
With security as an ongoing concern, you can do much of the necessary work as your network is rolled out or upgraded. If things are secure from the start, the number of threats you'll need to worry about right away will be reduced, and even new threats will be easier to deal with.
In this series on Macintosh infrastructure security, I've opted to include as many ways to secure a network as possible. Some of them can be applied to every network; others may have more limited uses. As with backup strategies, security is often a balancing act between protecting your users and allowing them the access they need.
I'm going to talk initially about workstation security for two reasons. First, workstations are where a large number of security breaches are likely to be attempted (particularly in a shared-workstation situation such as a computer lab). Second, many of the security approaches you can take with Mac OS X workstations work for Mac OS X servers, too, while the reverse is rarely true. In other words, server-specific security procedures often aren't relevant to workstations.
Workstation security takes several forms. First there is physical security, which includes protecting computers against vandalism or theft -- either of the entire workstation or of individual components. Physical security is tied to security of data because if someone manages to steal the workstation, they get all of the data contained on it as well.
Next to physical security is firmware security. Apple gives you the power to password-protect access to a workstation or modification of its boot process using the firmware code on the motherboard. This allows you to enforce file permissions on the data stored on the hard drive, which could otherwise be bypassed by users booting to a disk other than the internal hard drive or specified NetBoot disk. Firmware security relies on physical security because access to the internal



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Forrester: Economic Impact of Switching to Google Apps
- Content provided by Google
Read this Forrester report on the "total economic impact" of Google Apps, and learn how switching to Google Apps creates... - Intelligent Systems: Unlocking Hidden Business Value with Data
- An intelligent system enables data to flow across an enterprise infrastructure, spanning the devices where valuable data is gathered from employees and customers,...
- Concepts of NonStop SQL/MX
- For DBAs and developers who are familiar with Oracle solutions and want to learn about NonStop SQL/MX, this whitepaper provides an overview of...
- HP Advanced Information Services for SAP In-Memory Appliance (SAP HANA)
- Organizations are eager to connect the vast amounts of data available within and outside their businesses to compete more effectively and make better... All BI and Analytics White Papers
- Quantifying the Business Value of VMware View - Webcast
- Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price...
- Good to Great - How to Take Business Analytics to the Next Level
- By attending this webcast you will learn how you can implement an effective BA strategy that will deliver maximum strategic value to your...
- Supporting Mobile Productivity With A Limited IT Budget
- Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
- User Experience Monitoring
- In this webinar, you will learn hints & tips for improving end-user response times from Forrester Research analyst, Jean-Pierre Garbani.
- Hints & Tips Cisco
- Overwhelmed by tracking your Vblock, Flexpod or Cisco UCS performance? Spend one hour with Nimsoft to learn how you can eliminate the overhead... All BI and Analytics Webcasts