I have about 30 computers for which used a Linux based boot disk to hack into the user database to change the Administrator password. Now, to truly secure my workstations on a Windows based network, I would take the following steps. Can you help me think of things that I’m missing?
1. Prevent physical access to the chassis.
2. Remove floppy drive.
3. Password protect bios.
4. Disable Optical booting
5. Implement Group Policy
6. Re-direct user folders and delte roaming Cache at logoff.
7. Physically secure workstation.
If it’s as easy as booting to a linux disk to change the admin password, then the system is not secure IMHO.
Should I do anything else to secure my workstations? Have I gone overboard?
What other risks will I encounter?