Powered by Bitpipe Oracle Research Library

 RESEARCH LIBRARY HOME   WHITE PAPERS   PRODUCTS   MULTIMEDIA 
SEARCH the Research Library: HELP   |  WHAT'S POPULAR
sponsored by Lumension
Posted:  18 Jun 2009
Published:  28 May 2009
Format:  PDF
Length:  12   Page(s)
Type:  White Paper
Language:  English


ABSTRACT:
The Federal Desktop Core Configuration (FDCC) is an Office of Management and Budget (OMB) mandated security configuration set applicable within United States Federal Government agencies. Private enterprises may also choose to utilize this established framework as a foundation for their own security configuration baselines. These FDCC guidelines were developed at the United States National Institute of Standards and Technology (NIST), based on collaborative work with the Department of Homeland Security (DHS), Defense Information Security Agency (DISA), National Security Agency (NSA), United States Air Force (USAF) and Microsoft.

The FDCC XML checklists detail security concerns identified by Common Vulnerability Enumeration (CVE), which may be resolved by patching, and those specified by Common Configuration Enumeration (CCE), which may be resolved by configuration setting. The FDCC specific configuration requirements are generally based on the "Principle of Least Privilege" restricting user and machine rights. In addition to the operating system coverage, the FDCC configuration standards extend to Windows Internet Explorer, Windows Firewall and Windows Defender. These specific applications, however, are not explicitly required. If these applications are not utilized, the guidance is that the FDCC settings be leveraged and equivalently extended to the alternative applications.

The FDCC v1.2.1.0 configuration guidance may be grouped into several categories, each addressing a different area of security. This whitepaper highlights these high level categories and a representative set of configuration items.





BROWSE RELATED RESOURCES
Compliance (Systems Operations) | Compliance Best Practices | Governance, Risk, Compliance (GRC) | Government Agencies (U.S.) | Government Information Security | Security Best Practices | Security Management | Security Policies | Vulnerability Assessments

View All Resources sponsored by Lumension

Library Home |  White Papers |  Products |  Multimedia |  Partner with Us
 

Bitpipe Definitions: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z Other
What's Popular at Bitpipe? Daily Top 50 Reports | Daily Top 100 Topics | Popular Report Topics | Popular Product Topics
Oracle Research Library Copyright © 1998-2009 Bitpipe, Inc. All Rights Reserved.
Designated trademarks and brands are the property of their respective owners.
Use of this web site constitutes acceptance of the Bitpipe Terms and Conditions and Privacy Policy.
webmaster@techtarget.com