HostedDB - Dedicated UNIX Servers

-->
ITBPM S 4.107 Use of vendor resources

S 4.107 Use of vendor resources

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Administrator

All vendors of IT systems or IT components offer various forms of support and information for purchasers of their products. These include, for example, assistance in dealing with problems (support, hotline, updates, patches etc.) and access to information on security solutions (www sites, news groups, mailing lists etc.). Some of these are free of charge, others are not.

Already when purchasing IT systems or products, consideration should be given to the question of which forms of support provided by the vendor should be taken up, especially when these incur ongoing costs.

Steps should be taken to ensure that for all IT systems and products used regular checks are made as to whether new information regarding security problems and possible solutions is available from the vendor. This is especially important for all server operating systems as a security weakness on the server can cause significantly more damage than one which affects only a single IT system.

Security-specific updates, when these are not supplied directly from the vendor on CD-ROM, should only be obtained from trustworthy sources, e.g. from CERTs (see also S 2.35 Obtaining information on security weaknesses of the system). Updates should be checked to ensure they are intact using cryptographic methods (e.g. MD5, PGP) if they are offered appropriately encrypted and digitally signed.

To ensure that security-relevant advice from the vendor can be accessed at any time, a summary should be maintained for all operating systems and all major IT products used. This should show clearly the www addresses where security-specific updates and patches and information provided by the operating system vendor can be found.

A table like the one set out below, which provides a summary of the relevant links to known server operating systems, can be used for this purpose. The lines marked with U contain the URLs for (security-specific) updates and patches for the vendor concerned, while the lines marked with I contain the addresses from where security-specific information can be obtained.

Berkeley Software Design, Inc. - BSD/OS

U ftp://ftp.bsdi.com/bsdi/patches/
I http://www.bsdi.com/services/support/

Caldera OpenLinux

U ftp://ftp.caldera.com/pub/openlinux/updates/
I http://www.calderasystems.com/support/security/

Deban Linux

U http://cgi.debian.org/www-master/debian.org/security/ (German)
http://cgi.debian.org/www-master/debian.org/security/index.en.html (English)
I http://www.debian.org/security
http://www.debian.org/security/index.en.html

Digital Equipment Corporation - DEC

U http://www.service.digital.com/patches/
I http://www.unix.digital.com/

The FreeBSD Project - FreeBSD

U ftp://ftp.FreeBSD.org/pub/FreeBSD/
I http://www.freebsd.org/security/security.html

Hewlett Packard - HP

U http://europe-support.external.hp.com/
http://us-support.external.hp.com/
ftp://ftp.hp.com/pub/security/patches/
I http://europe-support.external.hp.com/
http://us-support.external.hp.com/

IBM

U http://service.software.ibm.com/aixsupport/
I http://www.ers.ibm.com/tech-info/index.html

The Open BSD Project - OpenBSD

U http://www.openbsd.org/errata.html
I http://www.openbsd.org/security.html

RedHat Linux

U ftp://www.redhat.com/pub/updates/
http://www.redhat.com/download/mirror.html
http://www.redhat.com/corp/support/errata/index.html
I http://www.redhat.com/LinuxIndex/Administration/Security/

S.u.S.E. Linux

U ftp.suse.de/pub/suse_update/
I http://www.suse.de/de/support/security/index.html (English also)

Santa Cruz Operation - SCO

U ftp://ftp.sco.com/SSE/
I http://www.sco.com/security/

Silicon Graphic Inc. - SGI

U ftp://sgigate.sgi.com/patches/
I http://www.sgi.com/Support/security/security.html

Sun MicroSystems Inc. - Sun

U http://sunsolve.sun.de/pub-cgi/us/pubpatchpage.pl
http://sunsolve.sun.com/pub-cgi/us/pubpatchpage.pl (depending on address of the local SunSolve server)
I http://sunsolve.sun.de/sunsolve/securitypub.html
http://sunsolve.sun.com/sunsolve/securitypub.html (depending on address of the local SunSolve server)

Windows NT

U http://www.microsoft.com/security/
I http://www.microsoft.com/security/

Novell

U http://support.novell.de/
http://support.novell.com
I http://www.novell.com/corp/security/
Unfortunately, experience indicates that links frequently change so it is important to check the list regularly to ensure that it is correct and, if necessary, to update it. For this reason no responsibility can be accepted for the material to be found on the links listed above, which has been provided for illustrative purposes.

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
Januar 2000
home