{"id":6551,"date":"2009-10-09T10:04:23","date_gmt":"2009-10-09T14:04:23","guid":{"rendered":"https:\/\/www.bu.edu\/tech\/?page_id=6551"},"modified":"2015-02-03T09:18:38","modified_gmt":"2015-02-03T14:18:38","slug":"windows","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/tech\/about\/security-resources\/bestpractice\/windows\/","title":{"rendered":"Securing Windows Systems"},"content":{"rendered":"<p>Microsoft Windows is one of the most widely used Operating Systems ever.\u00a0 The great popularity of the feature-rich operating system has come at a price: With millions of lines of code in Windows, the Operating System has required hundreds of patches to ensure that it can be securely used on the Internet.<\/p>\n<p>Unsecured computers that are directly connected to the Internet pose a threat to all users of the network.\u00a0 By compromising a single computer on a network, it may be possible an intruder to gain access to files, gather personal information, and disrupt the normal operations of the network.\u00a0 It is therefore imperative that we take precautions when connecting any computer to the campus network and Internet.<\/p>\n<p>There are several steps one should take to ensure to secure a Windows computer when connecting it to the campus network:<\/p>\n<ol>\n<li><a href=\"\/tech\/services\/infrastructure\/security\/firewall\/\" target=\"_blank\">Activate the Windows Firewall<\/a> <strong>before<\/strong> connecting the computer to the network.\u00a0 Attacks can happen very quickly once a computer is connected, often with in minutes or even seconds.\u00a0 You may not have time after plugging in the network cord to activate the firewall before your computer is compromised.<\/li>\n<li>Apply all current patches via <a href=\"http:\/\/windowsupdate.microsoft.com\/\" target=\"_blank\">Windows Update<\/a>.\u00a0 It may be necessary to reboot the computer several times during this process.\u00a0 You should repeat this step as needed until there are no more critical or recommended patches that need to be applied.<\/li>\n<li><a href=\"\/tech\/services\/infrastructure\/security\/autoupdate\/\" target=\"_blank\">Turn on Automatic Updates<\/a> so that your computer will continue to receive patches as they are released.<\/li>\n<li>Make sure all local accounts including the built-in local administrator or owner account have strong passwords.\u00a0 A strong password will be 6 or more characters in length, contain both numbers and letters as well as special characters, and not be found in a dictionary.\u00a0 Microsoft has advice on <a href=\"http:\/\/www.microsoft.com\/protect\/fraud\/passwords\/create.aspx\" target=\"_blank\">how to create strong passwords<\/a>.<\/li>\n<li>Install and use <a href=\"\/tech\/services\/infrastructure\/security\/software\/\" target=\"_blank\">virus protection software<\/a>.<\/li>\n<li>Install and use <a href=\"\/tech\/services\/infrastructure\/security\/spyware\/\" target=\"_blank\">spyware removal software<\/a>.<\/li>\n<\/ol>\n<h3>Keep Current!<\/h3>\n<p>It is important to realize that the methods used to compromise computer security are constantly changing. Minimizing your computer&#8217;s risk of compromise is therefore not a one-time task. It is instead a process that must be repeated and reviewed to ensure your computer remains secure.<\/p>\n<p>Learn about <a href=\"https:\/\/www.bu.edu\/tech\/services\/security\/advisories\/internal\/email\/\" target=\"_blank\">IS&amp;T&#8217;s mailing lists for computer administrators<\/a> and join those that are appropriate for you.\u00a0 Also subscribe to your vendor&#8217;s security notification service. In addition to <a href=\"http:\/\/technet.microsoft.com\/en-us\/security\/dd252948.aspx\" target=\"_blank\">Microsoft Technical Security Notifications<\/a>, most software and hardware vendors have some sort of means of notifying their customers when security patches and or upgrades become available. Make sure you and your IT staff are on the list to receive relevant notifications.<\/p>\n<p>Keep your software current. Many vendors, Microsoft included, only make security patches available for the most current releases of software. Be sure to know your vendor&#8217;s policies and plan accordingly.<\/p>\n<h3>Keep Clean!<\/h3>\n<p>Every piece of software installed on a computer adds to the risk of compromise.\u00a0 Some software will install unexpected extras that may include viruses, spyware, or just unseen components that may be compromised later to gain access to your system.\u00a0 Unneeded software will often be neglected and left without updates, eventually leading to a compromise through neglect.\u00a0 Therefore we encourage you to install only the applications you need and only from trusted sources.\u00a0 When installing new software, be sure you have a backup of your system and do not install unknown software on critical servers.<\/p>\n<p>Web browers and instant messenger clients are a common source of malware.\u00a0 While these products are often inextricable from a desktop system, their use on a server system should be carefully avoided.\u00a0 Many unpatched vulnerabilities exist for today&#8217;s browsers and websites with malicious code hidden within exist just waiting to trick unsuspecting users into accessing them.\u00a0 When using a web browser as a user with administrator privileges be sure to only browse known websites such as www.microsoft.com.<\/p>\n<h3>Protect University Data!<\/h3>\n<p>University data, including student data, financial records, and health information require special protections and handling.\u00a0 <a href=\"\/tech\/support\/accounts\/by-request\/mainframe\/dsa\/\" target=\"_blank\">Contact your Data Security Administrator <\/a>for advice on safe handling of university data.<\/p>\n<p>Do not install any unnecessary applications or free\/share ware on any system you care about or can not easily restore from scratch.<\/p>\n<p>Many modern viruses are taking advantage of all versions of instant messaging applications such as IRC, MSN, and AOL to install trojan and spyware software on systems without your knowledge. Applications of this nature have no business on a workstation<strong> <\/strong>housing university data. Use caution when using any application of this type and be sure to read the product documentation indicating how to secure the application on workstations determined to benefit (if any) from this type of application.<\/p>\n<p>Refrain from browsing the web from a<strong> <\/strong>&#8220;critical&#8221; workstation. Use caution when browsing any untrusted websites.<\/p>\n<h3>Promote Awareness about Computer Security<\/h3>\n<p>Many of our incidents originate from end-user actions whether they have installed new software, answered a phishing email, or disabled antivirus software.\u00a0 Computer administrators cannot hope to keep computer secure unless we make computer users more aware about the importance of computer security.<\/p>\n<h3>Resources<\/h3>\n<ul>\n<li><a href=\"\/tech\/services\/infrastructure\/security\/safe\/\" target=\"_blank\">IS&amp;T&#8217;s Stay Safe advice for computer owners<\/a><\/li>\n<li>The SANS Institute&#8217;s <a href=\"http:\/\/www.sans.org\/reading_room\/whitepapers\/windows\/windows_vista_first_steps_1298?show=1298.php&amp;cat=windows\" target=\"_blank\">Windows Vista: First Steps<\/a> Guide<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Windows is one of the most widely used Operating Systems ever.\u00a0 The great popularity of the feature-rich operating system has come at a price: With millions of lines of code in Windows, the Operating System has required hundreds of patches to ensure that it can be securely used on the Internet. Unsecured computers that&#8230;<\/p>\n","protected":false},"author":2127,"featured_media":0,"parent":6549,"menu_order":2,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6551"}],"collection":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/users\/2127"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/comments?post=6551"}],"version-history":[{"count":17,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6551\/revisions"}],"predecessor-version":[{"id":85675,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6551\/revisions\/85675"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6549"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/media?parent=6551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}