Safe Computing Practices

Document number: 69065

 

This is a problem prevention document. If you are already having a problem see the following documents

Safe Computing Practices

  1. Make sure you have installed all mandatory and recommended updates.  See Eureka! documents 19007 — Software Update Service and Systems Management Server and Software Patch Management

  2. Make sure you have the most current Service Pack installed. See Eureka! document 69035 — How to find out what Windows Service Pack is loaded.

  3. Do not use Outlook or Outlook Express. Lotus Notes is the only email program authorized for use on PeopleSoft machines.

  4. Use your Anti-virus software, and keep it up to date. See Eureka! document 15262 — FAQs about Norton AntiVirus.

  5. Back up regularly. For more information see Connected Network Backup

  6. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.

  7. Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If you have Windows 2000 and you don't need to use IIS (webserver) go to the Software Library page Microsoft IIS 5.0 and uninstall it. The page also has a button you can use to find out if you have IIS installed in the first place. (It is installed by default on some builds, but not on others). At the least make sure IIS is disabled. See Eureka! document 19021 — How to disable IIS.

  8. Anti-virus programs aren't very good at detecting Trojan horse programs, so be extremely careful about opening binary files and Word/Excel documents even from known sources. Any file that can run a program or script is suspect. That means .xls and .doc, .vbs, .exe, .bat, .pif and more. Newer viruses are even taking advantage of javascript and can spread by viewing infected web pages.

  9. Do not to open attachments unless you are expecting them. That they are from someone you know is not sufficient. Even if you know the sender, if you are not expecting an attachment contact the sender before opening an attachment.  Many viruses use the victim's address book as a method of distribution.  Viruses will fake their "from" information by using addresses culled from an infected machine. So getting an infected email "from" someone does not mean that it actually came from the person or their machine.

  10. Do not allow anyone to use PeopleSoft assets, including family members. Do not share your password with anyone. If you are getting help with something be present and type in the password yourself.

  11. Be careful about accessing disks for which you do not know the source. Scan all files (not just the program files) for viruses before opening anything on the disk. This should also be done for every piece of store bought or shrink-wrapped software, on both floppies and CD-ROMs.

  12. Check your security setting in Internet Explorer. See 19013 — How to check your security settings in Internet Explorer.

  13. Do not run, save, or download a program from a source that you do not trust. Be especially careful to read and understand messages before answering. Some messages are worded so that if you select "No" you have accepted the download, e.g. "Do you want to abort this download?" For more information see document 19038 — Control of pop-up windows.

 

 

 

 

 

Created by the PeopleSoft Knowledge Management Team.
Copyright © 2003. 2004 All rights reserved.
Created: db 01/02/2004