01. AppLocker
It Specify what software is allowed to run on a user’s PCs through centrally managed but flexible Group Policies. AppLocker is very similar to Software Restriction Policies (SRP). In fact, you may ask yourselves what the difference is. Well, AppLocker has a friendlier user interface, the ability to set restrictions based on application version number or publisher, and is easier to work with for less knowledgeable users.
Now, if you’re still wondering what AppLocker is, it’s a tool that allows you to restrict the execution of programs, installers and scripts on a machine with Windows 7 installed. Rather than using third-party security tools, Windows 7 has a built-in mechanism that allows tight, per-application execution control. The tool can be used to allow or deny certain programs or files to run, which can be used to make your system very secure against damage, accidents, misuse, or attacks.
Accessing AppLocker is not straightforward, which is why I’ve kept this software for the second article. You will need to invoke the Group Policy Editor, by running:
cmd > gpedit.msc
This is no different than Group Policies on Windows XP. and also it explains how to use Software Restriction Policies. AppLocker is a natural extension of this strategy, so if you’ve used the former, you’ll be instantly very comfortable with the new feature in Windows 7.
AppLocker can be found in the Computer Configuration tree, under Security Settings, Application Control Policies.
Your first step would be to configure rule enforcement. You can either have the rules in place or just audit for changes in the system without actually preventing or allowing them.
Then, you should create rules. In the right pane, right-click anywhere. Beginners or less experienced users should start with auto-generated rules. Manual rules can be created later, if needed.
Creating rules is very simple. You just follow a wizard. You create rules based on software groups. For example, you can have a rule for Program Files, a rule for Windows directory, a rule for Users directories, etc.
You can decide how to catalog your files, by digital signature (publisher), hash or path. It is recommended not to use path rules for Users directories, because the location of files can easily change, circumventing your security.
Once your directories are scanned, you’ll get the list of rules. You will be able to review the list and individually remove select items, if needed.
Once this is done, you will be asked to create a default set of rules. If you’re not really sure how AppLocker works, you should do this, to prevent potentially crippling the functionality of your system.
And this is what the Group Policy Editor shows now:
Manual rules
As said before, you can also fine-tune your security and create manual rules. Again, right-click and choose Create New Rule. In my case, I will create some rules for downloaded installed files that sit in the Downloads folder. These will include benign items like CuteWriter, Foxit Reader and IrfanView, just for the sake of the demonstration.
Working with AppLocker is not easy, but it’s definitely worth the investment. Combined with the proper use of the firewall and User Account Control (UAC), you can make your operating system well secured without bleeding the resources one bit.
BitLocker is an encryption software, which lets you encrypt your drive and your files, thus preventing the compromise of data integrity in case your computers get stolen. A similar feature did exist in Windows XP, but it is now easier to use and implement.
You can find BitLocker in the Control Panel:
I will merely inform you that this option exists and that you should explore it, if you like. That said, I do not recommend it, and here’s why:
Proprietary format
Encryption should never be closed-source. Always use open-source, proven, well tested solutions, like TrueCrypt, which offers the same capabilities, and then some, including cross-platform compatibility.
Hardware requirements
BitLocker has some rather curious requirements. One is that you have installed Windows 7 on a computer that supports Trusted Platform Module (TPM), which allows BitLocker to store its keys in a special microchip. Failing that, you will need an external USB key on to which you will store the encryption keys.
Moreover, BitLocker requires that you have at least two partitions on the system, both formatted with NTFS.
Personally, I find the requirements to be too much, especially considering the fact free, open-source alternatives like PGP and TrueCrypt require no such thing. Furthermore, both these solutions are proven workhorses of the encryption world, whereas BitLocker is a closed-source tool that you cannot use with other operating systems.
While encryption can potentially add to your security, which is why it’s listed as an item in this article, BitLocker itself does not have merits that warrant using. In this particular case, knowing which security features not to use is the part of the overall security scheme that I’m trying to teach.
03. Parental Control
In Windows 7 you can set limits on your kids’ computer use—and help them be safer online—without constantly peeking over their shoulders.
Parental Controls helps you limit how much computer time children have, as well as which programs and games they can use (and perhaps more importantly, when). With the Parental Controls in Windows Media Center, you can also block access to objectionable TV shows and movies.
To help keep your children safer online, download Windows Live Family Safety. This free program helps you manage which websites your children see and who they can talk to online. It also provides helpful, easy-to-read reports of their online activity.
What can I control with Parental Controls?
- Set specific time limits on your children’s computer use. You can set time limits to control when children are allowed to log on to the computer. Time limits prevent children from logging on during specified hours. You can set different logon hours for every day of the week. If they’re logged on when their allotted time ends, they’ll be automatically logged off.Prevent your children from playing games you don’t want them to play. Control access to games, choose an age-rating level, choose the types of content you want to block, and decide whether you want to allow or block specific games.Keep your children from running specific programs. Prevent children from running programs that you don’t want them to run.
To turn on parental control you should have standard user rights.
Open Parental Controls by clicking the Start button , clicking Control Panel, and then, under User Accounts and Family Safety, clicking Set up parental controls for any user. If you’re prompted for an administrator password or confirmation, type the password or provide confirmation.
No comments:
Post a Comment