Talk With an Expert

System Certifications: An Administrative Makeover

System Certifications: An Administrative Makeover (PDF, 2.13MB)Published: 02 May, 2004
Created by:
John Modransky

Described in this paper are the administrative controls that were implemented to certify and accredit UNIX (herein referred to as UN*X) and Microsoft Windows (herein referred to as Windows) based computer systems for a financial institution (The Firm). This InfoSec consultant was assigned the following tasks: 1) perform the UN*X and Windows system certifications 2) develop, document, and publish a standardized methodology document containing the step-by-step actions, both administrative and technical, to perform UN*X or Windows system certifications 3) create a standardized accreditation statement certifying that UN*X and Windows systems conform to a standard configuration and pass a certification process When initially given the project, there did not exist a formal, documented certification methodology or procedure within The Firm's Information Security (InfoSec) department. When a system certification was requested by other departments within The Firm, the current process was ad-hoc; verbal or email messages were used to request an certification, usually when the system administrator remembered.