Principles Of System Maintenance Security; Guidelines For Password Security Maintenance; Log Maintenance Suggestions - Huawei TE20 Administrator's Manual

Videoconferencing endpoint
Hide thumbs Also See for TE20:
Table of Contents

Advertisement

TE20 Videoconferencing Endpoint
Administrator Guide

10.5.1 Principles of System Maintenance Security

It is recommended that you comply with account management, permission management, and
auditing principles to ensure system maintenance security.
Account Management
Permission Management
Auditing Principles

10.5.2 Guidelines for Password Security Maintenance

User identities must be authenticated before users can log in to application systems. The
complexity and validity periods of accounts and passwords can be configured according to
system security requirements.
Guidelines for password security maintenance are as follows:

10.5.3 Log Maintenance Suggestions

It is recommended that you take log maintenance suggestions and utilize logs to help find
errors.
The system must record the operations, such as system parameter settings and conference
calls in the logs. Reinforce the system to protect the logs.
Checking Logs Regularly
Check the system logs, applications logs, and security logs regularly and report to the
department of a higher level once abnormal logs are found. Ask the local representative office
for help if the issues cannot be located or resolved.
Issue 01 (2016-09-01)
Manage the accounts strictly.
Control the permissions of accounts of different levels. Only users of higher levels can
change the passwords for users of lower levels.
Minimize permissions to the system service and permissions of accounts.
Strictly control the operation authorization on the web interface.
Use logs and other feasible methods to monitor operations on the endpoint.
Audit the failed access to the system's important resources.
Audit the successful access to the system's important resources.
Audit the failed and successful access control strategy modification.
Change the password periodically to prevent risks.
Designate specialist personnel to manage the administrator account and password.
Encrypt passwords during data transmission.
Remind users to change their passwords after system deployment.
Change passwords periodically. Do not use the default passwords or old passwords used
last five times.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
10 Security Maintenance
99

Advertisement

Table of Contents
loading

Table of Contents