Setup guide

UNCLASSIFIED
UNCLASSIFIED
2
Chapter 1 –
Scope of Guidance
user. This method is labor-intensive for the system administrator, so the most
appropriate method of password control for the operational site should be chosen.
The guidance is also written such that a system secured using this guide should be
easily transitioned into being a managed client in a Client-Server environment. If
the system being secured will eventually reside in a Client-Server environment, the
ability for a user to change his password should not be disabled.
Finally, it is EXTREMELY important on portable systems that very strong user
passwords be used. FileVault uses the user’s login password as a key for the
FileVault encryption. FileVault encryption is used to encrypt the user’s entire home
directory to give some protection against files being viewed by unauthorized users.
All encryption methods mentioned in this guide are the default encryption routines
that come standard on Mac OS X. Following this guide does not provide an
exception to the encryption policies implemented by the site where the system will
reside.