Lock down administrative workstations

This excerpt from Chapter 1 of Roberta Bragg's "Hardening Windows systems" explains why you need to designate and harden administrative workstations.

This excerpt from Chapter 1 of Roberta Bragg's "Hardening Windows systems" explains why you need to designate and harden administrative workstations.

Designate certain workstations as administrative workstations, computers that will be used to administer the network. Harden them. How much? Just as hard as you can. Start by putting them in a secured area and reinstalling the operating system and adding the latest service pack and security patches. Do this off the network. Use IPSec or a personal firewall to control ingress (what comes in) and egress (what goes out) and use software restriction policies to prevent the use of nonapproved software. Use the workstations only for administration -- no playing of games, no e-mail.

