NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
NIST SP 800-69 (draft) Guidance for Securing Microsoft Windows XP Home Edition
A NIST Security Configuration Checklist
on Monday 14 August 2006 print the content item {PDF=create pdf file of the content item^plugin:content.58}
in NIST.gov Publications > Special Publications - SP 800 series

SP 800-69 should be considered essential reading for all Windows XP Home Edition users. It does a very good job of summarizing the various threats facing home computer users and lists simple ways for users to mitigate them without having to be technically proficient.

You can download the NIST Special Publication 800-69 from NIST.gov

This document should be considered essential reading for all Windows XP Home Edition users. But that is asking a lot, the SP 800-69 document is 169 pages. However it does a very good job of summarizing the various threats facing home computer users and lists simple ways for users to mitigate them without having to be technically proficient. Surprisingly the document also goes out on a limb in a few places such as listing services that users can disable. It won't make anyone a security expert but it will give the average computer user a much better understanding of the threats they face every time they use their computer online. It even covers wireless networking, re-installation of the operating system, backups, and step-by-step instructions on how configure many of the security features that are built-in to Windows XP Home Edition.


(The below is a short description of SP 800-69 from NIST.gov, edited)

The draft SP 800-69 provides a checklist and guidance to home users, such as telecommuting Federal employees, on improving the security of their home computers that run Windows XP Home Edition. These computers face many threats from people wanting to cause mischief and disruption, commit fraud, and perform identity theft. The publication explains the need to use a combination of security protections to achieve a defense in depth. Thee protections include such as: antivirus software, antispyware software, a personal firewall, limited user accounts, and automatic software updates, to secure a computer against threats and maintain its security. It also emphasizes the importance of performing regular backups to ensure that user data is available after an adverse event such as an attack against the computer, a hardware failure, or human error. The publication contains a detailed step-by-step directions for securing Windows XP Home Edition computers that can be performed by experienced Windows XP Home Edition users.

Users of Windows XP Home Edition need to be aware of the threats that their computers face and the security protections available to protect their computers so that they can operate their computers more securely. Security protections are measures used to thwart threats.

Summary:

One of the most important parts of securing a Windows XP Home Edition computer is eliminating known weaknesses, because attackers could attempt to take advantage of them. Five categories of methods for eliminating weaknesses are as follows:
  • Limiting access to the computer through separate password-protected user accounts for each person, with different accounts for administrative and daily tasks (a limited user account)
  • Applying software updates to the computer on a regular basis, including Windows XP Home Edition and software applications
  • Limiting network access by disabling unneeded networking features, limiting the use of remote access utilities and Internet Connection Sharing, and configuring wireless networking securely
  • Modifying default file associations and the display of default file extensions
  • Disabling services that are not needed.


The five most important protections that should be used for Windows XP Home Edition computers connecting to the Internet are as follows:
  • Using a personal firewall that is configured to restrict incoming network activity to only that which is required
  • Using a limited user account for typical daily use of the computer
  • Running up-to-date antivirus software and antispyware software that is configured to monitor the computer and applications often used to spread malware (e.g., e-mail, Web) and to quarantine or delete any identified malware
  • Applying updates to the operating system and major applications (e.g., e-mail clients, Web browsers) regularly, preferably through automated means that check for updates frequently
  • Performing regular backups so that data can be restored in case an adverse event occurs.


---
The SP 800-69 document was created by the National Institute of Standards and Technology and is public domain (not subject to copyright).


NIST Special Publication # 800-69


Translate to: {GOOGLETRANS}
Google Ads




Headlines

»CVE-2014-3672 (libvirt, xen)
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denia ...
»CVE-2015-7360 (fortisandbox_firmware)
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet Fo ...
»CVE-2015-8558 (qemu)
The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to c ...
»CVE-2015-8853 (fedora, perl)
The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80."
»CVE-2016-0264 (desktop_supplementary, enterprise_linux_desktop_supplementary, enterprise_linux_hpc_node_supplementary, enterprise_linux_server_supplementary, enterprise_linux_server_supplementary_eus, enterprise_linux_workstation_supplementary, java_sdk, linux_enterprise_server, linux_enterprise_software_development_kit, manager, manager_proxy, openstack, supplementary)
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 ...
»CVE-2016-0718 (debian_linux, expat, ubuntu_linux)
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute ar ...
»CVE-2016-1380 (web_security_appliance)
Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers t ...
»CVE-2016-1381 (web_security_appliance)
Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) device ...
»CVE-2016-1382 (web_security_appliance_(wsa))
Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandle ...
»CVE-2016-1383 (web_security_appliance_(wsa))
Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attac ...
»CVE-2016-1385
The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authe ...
»CVE-2016-1400 (telepresence_video_communication_server)
Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to c ...
»CVE-2016-1406 (evolved_programmable_network_manager, prime_infrastructure)
The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Networ ...
»CVE-2016-1407 (ios_xr)
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) mishandles flow-base en ...
»CVE-2016-1886 (freebsd)
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 befo ...


Date published: 2016-05-27T04:50:00Z
Details

»Google Releases Security Update for Chrome
Original release date: May 26, 2016 Google has released Chrome version 51.0.2704.63 to addres ...
»Adobe Releases Security Update for Adobe Connect
Original release date: May 23, 2016 Adobe has released a security update to address a vulnera ...
»VMware Releases Security Updates
Original release date: May 18, 2016 VMware has released security updates to address vulnerabi ...
»Cisco Releases Security Updates
Original release date: May 18, 2016 Cisco has released security updates to address vulnerabil ...
»Symantec Releases Security Update
Original release date: May 16, 2016 Symantec has released Anti-Virus Engine 20151.1.1.4 to ad ...
»Apple Releases Multiple Security Updates
Original release date: May 16, 2016 Apple has released security updates for tvOS, iOS, watchO ...
»Adobe Releases Security Updates for Flash Player
Original release date: May 12, 2016 Adobe has released security updates to address vulnerabil ...
»Google Releases Security Update for Chrome
Original release date: May 11, 2016 Google has released Chrome version 50.0.2661.102 to addre ...
»Adobe Releases Security Updates
Original release date: May 10, 2016 | Last revised: May 11, 2016 Adobe has released security ...
»Microsoft Releases May 2016 Security Bulletin
Original release date: May 10, 2016 Microsoft has released 16 updates to address vulnerabilit ...


Date published: not known
Details

»Virus Bulletin's job site for recruiters and job seekers
Virus Bulletin has relaunched its security job vacancy service and ...
»Throwback Thursday: One_Half: The Lieutenant Commander?
In October 1994, a new multi-partite virus appeared, using some of ...
»Advertisements on Blogspot sites lead to support scam
Support scam pop-ups presented through malicious advertisements sho ...
»To make Tor work better on the web, we need to be honest about it
Many websites put barriers in front of visitors who use the Tor net ...
»Paper: How It Works: Steganography Hides Malware in Image Files
A new paper by CYREN researcher Lordian Mosuela takes a close look ...
»Paying a malware ransom is bad, but telling people to never do it is unhelpful advice
The current ransomware plague is one of the worst threats the Inter ...
»VB2015 paper: VolatilityBot: Malicious Code Extraction Made by and for Security Researchers
In his VB2015 paper, Martin Korman presented his 'VolatilyBot' tool ...
»VB2016 programme announced, registration opened
We have announced 37 papers (and four reserve papers) that will be ...
»New tool helps ransomware victims indentify the malware family
The people behind the MalwareHunterTeam have released a tool that h ...


Date published: not known
Details
Main Menu
· Home
Current Security News
 
US-CERT Current Activity

» Google Releases Security Update for Chrome
[26 May 2016 11:15am]

» Adobe Releases Security Update for Adobe Connect
[23 May 2016 01:44pm]

» VMware Releases Security Updates
[18 May 2016 03:20pm]

» Cisco Releases Security Updates
[18 May 2016 12:30pm]

» Symantec Releases Security Update
[16 May 2016 09:37pm]

» Apple Releases Multiple Security Updates
[16 May 2016 04:32pm]

» Adobe Releases Security Updates for Flash Player
[12 May 2016 11:39am]

» Google Releases Security Update for Chrome
[11 May 2016 03:59pm]

» Adobe Releases Security Updates
[10 May 2016 01:10pm]

» Microsoft Releases May 2016 Security Bulletin
[10 May 2016 01:07pm]

***
US-CERT Alerts

» TA16-144A: WPAD Name Collision Vulnerability
[23 May 2016 05:38am]

» TA16-132A: Exploitation of SAP Business Applications
[11 May 2016 05:31am]

» TA16-105A: Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced
[14 Apr 2016 01:48pm]

» TA16-091A: Ransomware and Recent Variants
[31 Mar 2016 04:00pm]

» TA15-337A: Dorkbot
[03 Dec 2015 04:40pm]

» TA15-314A: Compromised Web Servers and Web Shells - Threat Awareness and Guidance
[10 Nov 2015 06:12pm]

» TA15-286A: Dridex P2P Malware
[13 Oct 2015 05:23am]

» TA15-240A: Controlling Outbound DNS Access
[28 Aug 2015 11:31am]

» TA15-213A: Recent Email Phishing Campaigns – Mitigation and Response Recommendations
[01 Aug 2015 04:01pm]

» TA15-195A: Adobe Flash and Microsoft Windows Vulnerabilities
[14 Jul 2015 05:13pm]

***
Computerworld Security

» New JavaScript spam wave distributes Locky ransomware
[27 May 2016 08:19am]

» What is MAREA? Only an epic shift that changes everything
[27 May 2016 05:18am]

» Up to a dozen banks are reportedly investigating potential SWIFT breaches
[26 May 2016 02:14pm]

» Senators want warrant protections for U.S. email stored overseas
[26 May 2016 11:57am]

» Celebrity hacker Guccifer's confession gives us all a lesson in security
[26 May 2016 11:14am]

» IoT security is getting its own crash tests
[26 May 2016 05:09am]

» IDG Contributor Network: Are you buried under your security data?
[25 May 2016 01:00pm]

» Faception can allegedly tell if you're a terrorist just by analyzing your face
[25 May 2016 09:56am]

» Top-level domain expansion is a security risk for business computers
[25 May 2016 08:32am]

» Apple hires mobile encryption pioneer amid encryption debate
[25 May 2016 04:49am]

» Do we need vendor allies in the malware arms race?
[24 May 2016 12:35pm]

» State officials worry about their ability to fight cyberattacks
[24 May 2016 10:32am]

» New DMA Locker ransomware is ramping up for widespread attacks
[24 May 2016 09:22am]

» 'Delayed' MacBook Pro 2016 to be thinner (says bored analyst)
[24 May 2016 05:30am]

» How data virtualization delivers on the DevOps promise
[23 May 2016 09:41am]

***
Microsoft Security Advisories

» 2880823 - Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[18 May 2016 11:00am]

» 3155527 - Update to Cipher Suites for FalseStart - Version: 1.0
[10 May 2016 11:00am]

» 3152550 - Update to Improve Wireless Mouse Input Filtering - Version: 1.1
[22 Apr 2016 11:00am]

» 3137909 - Vulnerabilities in ASP.NET Templates Could Allow Tampering - Version: 1.1
[10 Feb 2016 11:00am]

» 2871997 - Update to Improve Credentials Protection and Management - Version: 5.0
[09 Feb 2016 11:00am]

» 3109853 - Update to Improve TLS Session Resumption Interoperability - Version: 1.0
[12 Jan 2016 11:00am]

» 3123479 - Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 1.0
[12 Jan 2016 11:00am]

» 3118753 - Updates for ActiveX Kill Bits 3118753 - Version: 1.0
[12 Jan 2016 11:00am]

» 2755801 - Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge - Version: 53.0
[05 Jan 2016 11:00am]

» 3123040 - Inadvertently Disclosed Digital Certificate Could Allow Spoofing - Version: 1.0
[08 Dec 2015 11:00am]

» 3057154 - Update to Harden Use of DES Encryption - Version: 1.1
[08 Dec 2015 11:00am]

» 3119884 - Inadvertently Disclosed Digital Certificates Could Allow Spoofing - Version: 1.0
[30 Nov 2015 11:00am]

» 3108638 - Update for Windows Hyper-V to Address CPU Weakness - Version: 1.0
[10 Nov 2015 11:00am]

» 3042058 - Update to Default Cipher Suite Priority Order - Version: 1.1
[13 Oct 2015 11:00am]

» 2960358 - Update for Disabling RC4 in .NET TLS - Version: 2.0
[13 Oct 2015 11:00am]

***
WIRED

» This Map Tracks Where Governments Hack Activists and Reporters
[26 May 2016 05:00am]

» A Car’s Computer Can ‘Fingerprint’ You in Minutes Based on How You Drive
[25 May 2016 10:24am]

» Security News This Week: Russia’s FindFace Face-Recognition App Is a Privacy Nightmare
[21 May 2016 05:00am]

» Gay Dating Apps Promise Privacy, But Leak Your Exact Location
[20 May 2016 05:00am]

» Chelsea Manning’s Appeal Took Three Years to File. Here’s Why
[19 May 2016 05:49pm]

» New Surveillance System May Let Cops Use All of the Cameras
[19 May 2016 05:00am]

» With Allo and Duo, Google Finally Encrypts Conversations End-to-End
[18 May 2016 01:23pm]

» That Insane, $81M Bangladesh Bank Heist? Here’s What We Know
[17 May 2016 05:00am]

» Everything We Know About How the FBI Hacks People
[15 May 2016 05:00am]

» Security News This Week: It’s Tech Versus the Government, Yet Again
[14 May 2016 05:00am]

***
Network World Security

» Senate proposal to require encryption workarounds may be dead
[27 May 2016 08:37am]

» New JavaScript spam wave distributes Locky ransomware
[27 May 2016 07:46am]

» DARPA wants to find the vital limitations of machine learning
[26 May 2016 08:22pm]

» Up to a dozen banks are reportedly investigating potential SWIFT breaches
[26 May 2016 02:00pm]

» SIEM review: Splunk, ArcSight, LogRhythm and QRadar
[09 May 2016 02:00pm]

» What users love (and hate) about 4 leading firewall solutions
[25 Apr 2016 01:48pm]

» 10 no-cost home security mobile apps worth a download
[01 Apr 2016 06:39am]

» 7 VPN services for hotspot protection
[14 Mar 2016 04:00am]

» Review: Consider VPN services for hotspot protection
[14 Mar 2016 04:00am]

» Review: 5 application security testing tools compared
[01 Mar 2016 01:29pm]

» Skyport eases the pain of deploying and securing remote servers
[29 Feb 2016 04:00am]

» Review: 8 password managers for Windows, Mac OS X, iOS, and Android
[24 Feb 2016 05:58am]

» What users love (and hate) about 4 leading identity management tools
[22 Feb 2016 06:52am]

» New JavaScript spam wave distributes Locky ransomware
[27 May 2016 07:46am]

» Up to a dozen banks are reportedly investigating potential SWIFT breaches
[26 May 2016 02:00pm]

***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}