Support of Virus Protection Software for Server Applications Version: 1.20 Date: 2010-12-23 OpenScale Baseline Security Office Siemens Enterprise Communications Group Communication for the open minded Siemens Enterprise Communications www.siemens-enterprise.com
1 Overview and Scope This security policy covers application servers where software applications provided by Siemens Enterprise Communications Group (hereinafter referred to as SEN) are installed. It describes the use of virus protection software on those servers and how it affects support and service for the SEN products. Products of SEN, where the operating system is provided as integral part of the product delivery (for example VoIP phones, gateways, or software appliances like the OpenScape Voice server) are not affected by this policy. Customers of SEN usually define their own security policies and standards, where the installation and operation of virus protection software on all application servers in the network is a mandatory requirement. The software is an essential component to protect the server from being exploited by viruses, worms or other malicious attacks, as well as to clean an infected server. SEN explicitly recommends implementing best-practice security measures in the customer's network. This also includes the operation of virus protection software. Note however, that Often the customer's policy dictates the use of a virus protection software from a specific vendor. It may differ from the virus protection software selected for use in SEN test laboratories. The installation of any 3 rd -party software on the application server could detrimentally affect the operation and performance of the application provided by SEN. This document describes how SEN addresses the oppositional requirements and how SEN can continue to provide support and service for their products. Version 1.20, 2010-12-23 Page 2
1.1 History of Change Date Version What 2009-05-29 1.00 Initial release 2010-03-31 1.10 Update of Applicability Matrix 2010-12-23 1.20 Update of Applicability Matrix 1.2 Contents 1 Overview and Scope 2 1.1 History of Change 3 1.2 Contents 3 1.3 Applicability Matrix 4 2 Virus Protection Software on Application Servers 5 Version 1.20, 2010-12-23 Page 3
1.3 Applicability Matrix In the current version, this policy applies to the following SEN server application products (hereinafter referred to as 'product'): SEN Product Name Major Server Operating System Version Microsoft SuSE other Windows Linux 1 HiPath 5000 RSM V7, V8 X HiPath 4000 Manager V4, V5, V6 X HiPath 4000 SoftGate V5, V6 X HiPath Accounting Management V2.0 X HiPath CAP V3.0 X HiPath DAKS V2.1, V3.0 X HiPath Display Telephone Book V9.0 X HiPath Fault Management V4 X X 2 HiPath License Management (HLM) V1 X X X 3 HiPath ProCenter Agile/Standard V6.5 X HiPath QoS Management V1.0 X HiPath User Management V2.0, V3 X HiPath Trading V3 X OpenScape Accounting V1 X OpenScape Alarm Response Economy V1 X OpenScape Alarm Response Professional V3 X OpenScape ComAssistant V2.0 X OpenScape Contact Center Agile/Enterprise V7.0, V8 X OpenScape Contact Center Campaign Director V6 X OpenScape Contact Center Extensions V1 X (includes OpenScape Concierge) OpenScape Deployment Service V2.0, V3 X X OpenScape ILA (Identity Lifecycle Assistant) V1 X OpenScape Media Server V3, V4 X OpenScape Office HX V2 X OpenScape UC Application V3, V4 X OpenScape Voice Assistant (incl. Common V3, V4, V5 X Management Portal, RG8700 Assistant, DLS) OpenScape Voice Survival Authority (if deployed V3, V4, V5 X standalone) OpenScape Voice Trace Manager V1, V2 X OpenScape Web Collaboration V1 X OpenScape Xpressions V5, V6 X OpenScape Xpert V4 X SESAP V1 X 1 Novell SuSE Linux Enterprise Server or opensuse Linux 2 When installed on HiPath 4000 Manager 3 openwrt, Solaris Version 1.20, 2010-12-23 Page 4
2 Virus Protection Software on Application Servers SEN does not provide, recommend or certify any specific virus protection software for use with the application servers. Nevertheless, as part of the System-, Release- and Regression-Tests, SEN may install and operate a current version of virus protection software with a broad market acceptance (e.g. Trend Micro, F-Secure, or McAfee). The used software is listed in the SEN product's administration manual or release notes. Installation and configuration of virus protection software on the application servers (if required by the customer) is the sole responsibility of the customer and is accomplished at the customer s own risk. The customer assumes all liability for installation and correction should the virus protection software interfere with proper operation of the application software provided by SEN. SEN recognizes, however, that installation of virus protection software may be required by the customer's security or system management policies. Installation of such software will thus not void the warranty or maintenance agreement provided by SEN. SEN may ask the customer to remove the software in order to restore proper operation of the system if diagnosis of a problem is not possible in the SEN laboratories. That is, if the problem cannot be recreated and diagnosed with reasonable effort in the SEN laboratories, SEN will assume that the problem is caused by the virus protection software and will request that the software be removed before additional investigation is conducted. Customers desiring to install virus protection software on the application servers can do so, with the following notes: 1. If the installation or operation of the software causes the system to malfunction, then the customer should: a. Remove or disable the software to restore proper system operation. The customer can, of course, choose to leave the software installed if, in their opinion, the risk of operating without it is higher than the cost of the malfunction. b. Report the problem to SEN using the normal product support process. c. Re-install or enable the software after investigation and advice from SEN. 2. The detection and cleaning process of virus protection software can be highly CPU intensive. If full disk scans are scheduled to run during high system usage, the scanning will slow down system performance and may affect the operation of the product. We recommend that disk scans be scheduled to run during periods when the traffic and system load are low. The disk scans should also be scheduled such that they do not coincide with any maintenance windows. 3. Enabling active virus checking (i.e. the virus protection software checks for viruses on all disk write operations) will also affect the product's performance for those features that are I/O intensive. This includes for example the writing of statistics, creation and updating of configuration information and the writing of diagnostic information. Version 1.20, 2010-12-23 Page 5
About Siemens Enterprise Communications Group (SEN Group) The SEN Group is a premier provider of enterprise communications solutions. More than 14,000 employees in 80 countries carry on the tradition of voice and data excellence started more than 160 years ago with Werner von Siemens and the invention of the pointer telegraph. Today the company leads the market with its "Open Communications" approach that enables teams working within any IT infrastructure to improve productivity through a unified collaboration experience. SEN Group is a joint venture between the private equity firm, The Gores Group, and Siemens AG and incorporates Siemens Enterprise Communications, Enterasys Networks, SER Solutions, Cycos and isec. For more information about Siemens Enterprise Communications, please visit www.siemens-enterprise.com Communication for the open minded Siemens Enterprise Communications www.siemens-enterprise.com Siemens Enterprise Communications GmbH & Co. KG Siemens Enterprise Communications GmbH & Co. KG is a Trademark Licensee of Siemens AG Status 03/2009 The information provided in this brochure contains merely general descriptions or characteristics of performance which in case of actual use do not always apply as described or which may change as a result of further development of the products. An obligation to provide the respective characteristics shall only exist if expressly agreed in the terms of contract. Availability and technical specifications are subject to change without notice. OpenScape, OpenStage and HiPath are registered trademarks of Siemens Enterprise Communications GmbH & Co. KG. All other company, brand, product and service names are trademarks or registered trademarks of their respective holders. Printed in Germany.