Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

NIST SP 800-68 on Windows XP and the Microsoft Windows Vista Security Guide both delineate baseline configuration settings for environments including the Enterprise and Specialized Security-Limited Functionality (SSLF) environments. Which should I use?

0
Posted

NIST SP 800-68 on Windows XP and the Microsoft Windows Vista Security Guide both delineate baseline configuration settings for environments including the Enterprise and Specialized Security-Limited Functionality (SSLF) environments. Which should I use?

0

Federal civilian agencies and other organizations should start with the Enterprise version for most of their managed desktop machines. The Enterprise baseline, as described in NIST SP 800-70, reflects the typical federal civilian operational environment, while the SSLF baseline tracks closely with the DoD operational environment. NIST recommends that federal civilian agencies start with the Enterprise baseline, customize it to reflect their local operational requirements and security policy (e.g., appropriate logon banner, access control mechanisms) and test it with their enterprise applications before pushing these settings out to their managed systems. They should document all changes that were made to the baseline as part of their configuration change control process. SSLF settings may be necessary when the system operates in a high impact environment, or when the agency determines this level is necessary to adequately secure government information.

Related Questions