| Home | News | Products | Buy online | Solutions | About | |
| Sitemap | Freelancers | Download | Support | Services | Contact us |
| Corporate info |
|
|
Basic MS Windows security This page describes how we set up a basic Windows system with both security and the user in mind. Basic recommendations: Prepare a DVD with the original software you need to install. We use two DVDs, one for the "basic container" (which means the operating system + all required software), and one for the optional software (such as developer or administrative tools). If you have multiple PCs, dedicate one of them for internet access. This PC should only have your webbrowser and email client installed, and any non-public data should be on an encrypted volume. The remaining PCs should not be connected to the network. Use a (possible encrypted) USB memory stick if you need to transfer data. Tip: an encrypted volume of 4300 Mb fits on a DVD as well (for backup). If you have Norton Ghost, take a new image on the PC after major changes and monthly update(s). Your basic container could consists of Microsoft Windows 2000 and the software listed here. Steps to prepare the PC: 1. Make sure the PC is clean, and you data and basic container is on a CD-ROM or DVD ready for import/installation. 2. Disconnect the network cable. 3. Boot on your Windows CD-ROM and begin the installation. Format the drive(s) and divide it into proper partitions. We recommend a 10 Gb C: drive for Windows and your software, and the rest on a D: and E: drive for data (D: = Public junk, E: encrypted data). Also go through all the settings for the various applications and Microsoft Windows, and adjust them as needed. 4. When the Windows installation is complete, install the rest of the basic container. The following applications are highly recommended: ZoneAlarm, AdAware, Spybot Search & Destroy, Microsoft Baseline Security Advisor, and Grisoft antivirus. Reboot and make sure everything runs. 5. Install CryptoEx or a similar package, and create encrypted volumes for your data. Then restore your data from the CDR/DVD to the encrypted volume(s). 6. Open the Local Security Policy (Administrative Tools) and secure your PC. 7. You can now configure your network connection and reconnect the cable. 8. Go through the following applications and make sure they are up to date and that the AutoUpdate scheduling feature is enabled: Microsoft Windows Automatic Updates (in control panel); ZoneAlarm ; AdAware ; SpyBot ; Grisoft antivirus. |