...
- Create policies to automatically inventory software packages or systems and add authorized applications to a whitelist. See Whitelisting Software Packages and /wiki/spaces/ACS75DOC/pages/1151082.
- Implement the principle of least privilege to enhance the protection of data and functionality from malicious behavior. See Restrict an Application's Process Rights.
Noteinfo title Note The principle of least privilege requires that each subject in a system is granted the most restrictive set of privileges (or lowest clearance) that is needed for the performance of authorized tasks. The application of this principle limits the damage that can result from accident, error, or unauthorized use.
- Apply security ratings to withstand future attacks by reducing the number of applications that are available to exploitation. See Security Rating.
- Isolate an application to protect against file system and registry corruption or misuse. You can achieve this goal by integrating with Altiris® Software Virtualization SolutionTM software. See Run an Application in an SVS Layer.
- Protect against data theft. You can automate the encryption of documents because Application Control Solution has seamless integration with Windows Encrypted File System. For information, see http://www.microsoft.com/resources/documentation/ windows/xp/all/proddocs/en-us/encrypt_overview.mspx?mfr=true. search Microsoft for EFS Encryption. Using Application Control Solution, you can automatically encrypt documents on a notebook and prevent theft. See See Automate Document Encryption.
- Control an application's ability to read or write to specific network locations. See Prevent Read and Write to File Types or Network Locations.
- Prevent potentially malicious applications, such as keyloggers, from installing Windows API hooks. See Manage Applications.
- Protect against viruses and spyware. See Quarantine Files.
...