HP EliteBook 8470p HP ProtectTools Getting Started - Page 19

Additional security elements, Assigning security roles, Managing HP ProtectTools passwords, CAUTION

Page 19 highlights

Additional security elements Assigning security roles In managing computer security (particularly for large organizations), one important practice is to divide responsibilities and rights among various types of administrators and users. NOTE: In a small organization or for individual use, these roles may all be held by the same person. For HP ProtectTools, the security duties and privileges can be divided into the following roles: ● Security officer-Defines the security level for the company or network and determines the security features to deploy, such as Drive Encryption or Embedded Security. NOTE: Many of the features in HP ProtectTools can be customized by the security officer in cooperation with HP. For more information, go to http://www.hp.com. ● IT administrator-Applies and manages the security features defined by the security officer. Can also enable and disable some features. For example, if the security officer has decided to deploy smart cards, the IT administrator can enable both password and smart card mode. ● User-Uses the security features. For example, if the security officer and IT administrator have enabled smart cards for the system, the user can set the smart card PIN and use the card for authentication. CAUTION: Administrators are encouraged to follow "best practices" in restricting end-user privileges and restricting user access. Unauthorized users should not be granted administrative privileges. Managing HP ProtectTools passwords Most of the HP ProtectTools Security Manager features are secured by passwords. The following table lists the commonly used passwords, the software module where the password is set, and the password function. The passwords that are set and used by IT administrators only are indicated in this table as well. All other passwords may be set by regular users or administrators. HP ProtectTools password Windows Logon password Security Manager Backup and Recovery password Smart card PIN Set in the following module Function Windows® Control Panel or Can be used for manual logon and for HP ProtectTools Security authentication to access various Security Manager Manager features. Security Manager, by individual user Protects access to the Security Manager Backup and Recovery file. Credential Manager Can be used as multifactor authentication. Can be used as Windows authentication. Authenticates users of Drive Encryption, if the smart card is selected. Additional security elements 9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138

Additional security elements
Assigning security roles
In managing computer security (particularly for large organizations), one important practice is to
divide responsibilities and rights among various types of administrators and users.
NOTE:
In a small organization or for individual use, these roles may all be held by the same person.
For HP ProtectTools, the security duties and privileges can be divided into the following roles:
Security officer—Defines the security level for the company or network and determines the
security features to deploy, such as Drive Encryption or Embedded Security.
NOTE:
Many of the features in HP ProtectTools can be customized by the security officer in
cooperation with HP. For more information, go to
.
IT administrator—Applies and manages the security features defined by the security officer. Can
also enable and disable some features. For example, if the security officer has decided to deploy
smart cards, the IT administrator can enable both password and smart card mode.
User—Uses the security features. For example, if the security officer and IT administrator have
enabled smart cards for the system, the user can set the smart card PIN and use the card for
authentication.
CAUTION:
Administrators are encouraged to follow “best practices” in restricting end-user
privileges and restricting user access.
Unauthorized users should not be granted administrative privileges.
Managing HP ProtectTools passwords
Most of the HP ProtectTools Security Manager features are secured by passwords. The following
table lists the commonly used passwords, the software module where the password is set, and the
password function.
The passwords that are set and used by IT administrators only are indicated in this table as well. All
other passwords may be set by regular users or administrators.
HP ProtectTools password
Set in the following
module
Function
Windows Logon password
Windows® Control Panel or
HP ProtectTools Security
Manager
Can be used for manual logon and for
authentication to access various Security
Manager features.
Security Manager Backup and
Recovery password
Security Manager, by
individual user
Protects access to the Security Manager
Backup and Recovery file.
Smart card PIN
Credential Manager
Can be used as multifactor authentication.
Can be used as Windows authentication.
Authenticates users of Drive Encryption, if
the smart card is selected.
Additional security elements
9