|
The following policies must be followed for all computers connected to the Harvard University data networks to minimize the chance that the computers could be compromised, or if they are compromised, minimize the chance that they could be used to attack other computers at Harvard or elsewhere on the Internet. Specific best practices for computers that might be targets of special interest to hackers or terrorists are noted under the heading "target computers."
Policies for Computer Operation
Principle: ensure that the software on computers is secure and the machines are operated in a way to minimize the chance of a security breach.
1: The software on any computer connected to the Internet or an internal network must be kept up to date with regard to security patches; default account passwords must be changed and all other normal good computer security practices must be followed. The computer manager should do a weekly review of security alerts or subscribe to appropriate security mailing lists.
2: Only people with a specific need to use a particular computer should have accounts on it.
|