Está en la página 1de 7

Government of Newfoundland and Labrador

Office of the Chief Information Officer


Solution Delivery Branch
SERVER BUILD BOOK
Purpose: The Server Build Book documentation is intended to rovide Oerations with an accurate account of
all confi!urations modifications to !et the server to its roduction state includin! any confi!uration modifications
made as a result of vulnerability assessments and other security hardenin! efforts" #elated relevant information
ertainin! to alications and databases hosted on these environments can be found in the comanion
$lication Build Book"
Server Name
Server Environment %roduction Sta!in! Test Develoment
Server Location && Indicate current location 'build( transition or other)( final location
determined by Data Centre staff **
Server Purpose && Indicate the server urose and environment( e+amle, Database(
%roduction **
Project Name
Project Number && DTC Number **
Appication Number && $lication Number **
Project Description && %rovide a short descrition of the ro-ect" **
I!POR"AN" NO"ES #OR $O!PLE"IN% "&IS DO$U!EN"
.ach section of the Server Build Book must be comleted in full" If a articular section is not alicable to this
ro-ect( then you must write Not Applicable and rovide a reason"
Important Note, No sections are to be deleted from this document"
Te+t contained within && ** rovides information on how to comlete or more detailed descrition of what
needs to be catured in that section and can be deleted once the section has been comleted"
Server Build Book &Server name* %a!e / of 0
Temlate 1ersion Oerations 2( 34/25425/2 6i!h Sensitivity
Government of Newfoundland and Labrador
Office of the Chief Information Officer
"ABLE O# $ON"EN"S
Net'or( Arc)itecture Dia*ram++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ,
SERVER SPE$I#I$A"IONS++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ,
Server 7odel and Serial Number"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" 2
OPERA"IN% S-S"E! INS"ALLA"ION+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ,
NE".ORK SE""IN%S++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ,
#IRE.ALL $ON#I%URA"ION /LO$AL SERVER0++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1
SO#".ARE INS"ALLED++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1
SE$URI"- &ARDENIN%+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1
SSL $ER"I#I$A"ES++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 2
A$$ESS+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 2
$dministrator $ccount Information"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" 8
9ser : Service $ccounts"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" 8
Sudoers Confi!uration"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" 8
;ile System""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" 8
S$&EDULED "ASKS++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 3
SERVER !ONI"ORIN%+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 3
S-DI REPOR" #OR .INDO.S+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 3
$#%4&"!L #OR AI56UNI56LINU5++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 3
I!POR"AN" NO"ES+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 3
PREPARED B-++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 3
REVIE.ED B-++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 7
APPROVED B-+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 7
Server Build Book &Server name* %a!e 3 of 0
Temlate 1ersion Oerations 2"/( 34/25//5/2 6i!h Sensitivity
Government of Newfoundland and Labrador
Office of the Chief Information Officer
NETWORK ARCHITECTURE DIAGRAM
Description && %rovide a detailed descrition of the technical architecture 'infrastructure)
includin! how each iece fits in to the overall solution" **
"ec)nica Arc)itecture Dia*ram
&& insert dia!ram's) **
&& $n annotated Network $rchitecture Dia!ram is re<uired to show the relationshi between servers" $t a
minimum( the network dia!ram shall include,
5 Server Names=
5 I% $ddresses=
5 ;irewall intersections= and
5 The communications between Servers and Clients"
$ more comrehensive dia!ram can be included describin! the additional comonents such as the direction
and tye of communication with other systems( tye of Oeratin! System( and the orts used" **
SERVER SPECIFICATIONS
SERVER MODEL AND SERIAL NUMBER
Server Name !o8e Number "9pe Seria Number
OPERATING SYSTEM INSTALLATION
I: t)is Server is not part o:
t)e Active Director9 8omain;
attac) Ops approva e<mai+
$ttached
A88itiona Notes
NETWORK SETTINGS
IP A88ress
Subnet !as(
De:aut %ate'a9
Server Build Book &Server name* %a!e 2 of 0
Temlate 1ersion Oerations 2"/( 34/25//5/2 6i!h Sensitivity
Government of Newfoundland and Labrador
Office of the Chief Information Officer
Primar9 DNS Server
Secon8ar9 DNS Server
DNS Entr9 && %rovide DNS .ntry and:or any ;>DN : $liases associated with Server **
FIREWALL CONFIGURATION (LOCAL SERVER)
Loca #ire'a $on:i*uration
Detais
&& List the firewall information to be recorded for this server" Get the detailed
host firewall rules for local firewall( such as 7icrosoft 9$G **
SOFTWARE INSTALLED 'Non5Business $lication)
Description && This section will include all software installed and confi!ured on this server
that is re<uired to run the business alication"
Important Note: This section is NOT for the business alication runnin! on
the server" **
Non<Stan8ar8 or a88itiona
so:t'are
Other /
Other 3
So:t'are Instaation 6
$on:i*uration
&& %rovide details stes to install software and confi!uration for each**
SECURITY HARDENING
User Ri*)ts Poic9
/.in8o's0
&& %rovide details on non5standard 9ser #i!hts security hardenin!
confi!uration" **
Securit9 Ri*)ts Poic9
/.in8o's0
&& %rovide details on non5standard Security #i!hts security hardenin!
confi!uration" **
Re*istr9 A88itions6$)an*es
/.in8o's0
&& %rovide details any non5standard #e!istry security hardenin!
confi!urations made" **
#ie S9stem Securit9 && %rovide details on non5standard ;ile System security hardenin!" **
Pass'or8 6 Account Poic9 && %rovide details on non5standard %assword and $ccount security
hardenin!" **
Event Lo* Poic9 /.in8o's0 && %rovide details on non5standard .vent Lo! security hardenin! chan!es"
**
A88itiona Securit9 && %rovide details on additional security hardenin! confi!urations made such
e+amles are DCO7 ort chan!es( I% Stack( sysctl"conf 'Linu+) et cetera **
Services at Server Start<up && %rovide a list of services that should be runnin! on start5u" If there is
secial inte!ration or reliance of the alication on native oeratin! system
Server Build Book &Server name* %a!e ? of 0
Temlate 1ersion Oerations 2"/( 34/25//5/2 6i!h Sensitivity
Government of Newfoundland and Labrador
Office of the Chief Information Officer
services 'such as IIS or any service altered from the normal settin!) they
should be clearly described in this section" **
SSL CERTIFICATES
$erti:icate cassi:ication;
8escription or i8enti:ication
&& %rovide details on how the SSL Certificates are used" **
@eb server to alication
$lication to database
$erti:icate e=pir9 && %rovide details on SSL Certificate e+iry" **
ACCESS
ADMINISTRATOR ACCOUNT INFORMATION
Description && Identify all administrators created for this server= ensure to include 9serID(
Name and $ccess Level" **
UserID $ontact name Access Leve
USER / SERVICE ACCOUNTS
Description && Identify all other System 9sers created for this server= ensure to include
9serID( Name and $ccess Level" **
UserID $ontact Name Access Leve
SUDOERS CONFIGURATION 'Linu+ and $IA only)
FILE SYSTEM
Description && Identify all chan!es made to file system ermissions for this server=
ensure to include 9serID : !rou( folder : share and ermission !iven" This
need to include ermissions !iven and ermissions taken away" **
S)are 6 #o8er 6 #ie names UserID 6 %roup Permission
Server Build Book &Server name* %a!e 8 of 0
Temlate 1ersion Oerations 2"/( 34/25//5/2 6i!h Sensitivity
Government of Newfoundland and Labrador
Office of the Chief Information Officer
SCHEDULED TASKS
$rontab Entries && %rovide a list of crontab entries" **
.in8o's Sc)e8ue8 "as(s && %rovide a list of @indows Scheduled Tasks" **
SERVER MONITORING
Services to be monitore8
be9on8 norma monitorin*
sc)eme
&& %rovide a list of additional or secial services to be monitored" Include the
services above the basic OS services re<uired for this serverBs urose" ;or
e+amle a web server would have the service re<uired to ensure the web
server is functionin! correctly $ache or IIS" **
SYDI REPORT FOR WINDOWS
S-DI Report "e=t && %aste the SCDI reort te+t here" Contact Oerations if you re<uire hel
runnin! the SCDI scrit" **
CFG2HTML FOR AIX/UNIX/LINUX
$#%4&"!L Report "e=t && %aste the cf!3html reort te+t here" Contact Oerations if you re<uire hel
runnin! the scrit" **
IMPORTANT NOTES
A88itiona In:ormation &&#ecord additional information here( includin!( but not limited to
confi!uration information about server services( and secialiDed hardware
inte!ral to the workin!s of the service:alication( modems( sensors( etc"
.+amle, information about how IIS is confi!ured to suort the web site" **
PREPARED BY
>> "ite ??
'%rint name) 'si!nature) 'date)
REVIEWED BY
>> "ite ??
'%rint name) 'si!nature) 'date)
Server Build Book &Server name* %a!e E of 0
Temlate 1ersion Oerations 2"/( 34/25//5/2 6i!h Sensitivity
Government of Newfoundland and Labrador
Office of the Chief Information Officer
APPROVED BY
!ana*er o: Operations @
Server 6 Stora*e
'%rint name) 'si!nature) 'date)
Server Build Book &Server name* %a!e 0 of 0
Temlate 1ersion Oerations 2"/( 34/25//5/2 6i!h Sensitivity

También podría gustarte