欢迎来到天天文库
浏览记录
ID:34935687
大小:1.89 MB
页数:131页
时间:2019-03-14
《SecuringPublicKeyInfrastructure(PKI)》由会员上传分享,免费在线阅读,更多相关内容在工程资料-天天文库。
1、SecuringPublicKeyInfrastructure(PKI)MicrosoftITInformationSecurityandRiskManagementPublished:May16.2014Forthelatestinformation,pleaseseehttp://aka.ms/securingpki131SecuringPublicKeyInfrastructure(PKI)131SecuringPublicKeyInfrastructure(PKI)ContentsForeword6Acknowledgeme
2、nts7ExecutiveSummary8Introduction10AboutthisDocument11ContentOriginandOrganization11PKIAssessmentsandConsulting11ContentScope11IntroductiontoPKI11PKIComponents11PKIGovernance12BusinessDriversforPKI12ElementsofaSuccessfulPKI13DeterminingtheLevelofProtectionRequired14Com
3、promisingPKI15HowPKICompromisesOccur15ProtectingaPKIDeployment16PlanningaCAHierarchy17CAHierarchyOptions18Conclusion21PhysicalControlsforSecuringPKI22FunctionalConsiderations22OperationalConsiderations23DesigningPhysicalSecurity23TrackandAuditPhysicalAccessRequests23Co
4、nsiderUsingBiometrics24UseMultiPersonControl24EliminateTailgatingtoSensitiveAreas24UseAlarmSystemsasaDetectiveControl25UseCamerasasaDetectiveControl25GeographicallySeparatePrimaryandBackupSites25UseSecuritybyObscurityCarefully25Conclusion26131SecuringPublicKeyInfrastru
5、cture(PKI)PKIProcessSecurity27PKIPolicy27CertificatePolicy27CertificationPracticeStatement28PKIGovernanceandOversight29RolesandResponsibilities30KeyGenerationCeremonies31Conclusion33TechnicalControlsforSecuringPKI34SecuringtheCAOperatingSystem34CreatingaBaselineConfigu
6、rationforallCAsandRAs34MicrosoftSecurityComplianceManager34MicrosoftSecurityConfigurationWizard34OnlineCAHardeningRecommendations34AdditionalRolesonCertificationAuthorities35AlternateAdministrativeAccounts35UpdatingOnlineCertificationAuthorities35InternetAccessfromCert
7、ificationAuthorities36LocalAdministratorsGroupMembership36ApplicationWhitelisting36SecuringRemoteManagementTasks37Multi-factorAuthenticationforCertificationAuthorityAccess37SecuringOfflineCertificationAuthorities38ProtectCAPrivateKeys38OfflineCAsShouldBeTrulyOffline38M
8、anagingDataTransfer39UpdatingOfflineCertificationAuthorities39AccountManagement39VirtualizingCertificationAuthorities
此文档下载收益归作者所有