<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="33913" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/hewlettpackard-u4196s" lastchanged="2025-07-29T12:18:23+02:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Securing HPE NonStop Servers using Safeguard</title><productcode>U4196S</productcode><vendorcode>HP</vendorcode><vendorname>HP</vendorname><fullproductcode>HP-U4196S</fullproductcode><version>1.0</version><objective>&lt;h5&gt;At the conclusion of this course, you should be able to:  &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Be familiar with the $CMON interface and TACL considerations&lt;/li&gt;&lt;li&gt;Install and configure Safeguard software&lt;/li&gt;&lt;li&gt;Create and manage user IDs&lt;/li&gt;&lt;li&gt;Apply Access Control Lists (ACLs) on system objects&lt;/li&gt;&lt;li&gt;Describe sources of audit events&lt;/li&gt;&lt;li&gt;Use the Safecom command utility&lt;/li&gt;&lt;li&gt;Use the SAFEART utility to generate audit reports&lt;/li&gt;&lt;li&gt;Apply OSS standard security and OSS ACLs on OSS objects&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;ul&gt;
&lt;li&gt;Concepts and Facilities for HPE NonStop Systems (U4147S)&lt;/li&gt;&lt;li&gt;Knowledge of TACL commands (such as STATUS, FILEINFO, and WHO) for information gathering&lt;/li&gt;&lt;li&gt;Knowledge of Guardian utilities (such as FUP, SCF, and DSAP)&lt;/li&gt;&lt;li&gt;Knowledge of basic OSS commands and utilities&lt;/li&gt;&lt;li&gt;Ability to manage user profiles using the PASSWORD and DEFAULT programs&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;Information security administrators &amp;bull;Electronic Data Processing (EDP) auditors &amp;bull;System operations management personnel in security operations&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;h5&gt;Module 1: NonStop Kernel Security Architecture &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Guardian and OSS application environments&lt;/li&gt;&lt;li&gt;Authentication, authorization, and audit&lt;/li&gt;&lt;li&gt;Goals of NonStop kernel standard security&lt;/li&gt;&lt;li&gt;Components of NonStop kernel security architecture&lt;/li&gt;&lt;li&gt;Memory address isolation and disk file protection&lt;/li&gt;&lt;li&gt;$CMON process&lt;/li&gt;&lt;li&gt;Licensed program files&lt;/li&gt;&lt;li&gt;Setuid setting for OSS programs&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;
&lt;h5&gt;Module 2: Safeguard Features&lt;/h5&gt;
&lt;ul&gt;
&lt;li&gt;Relation of Safeguard to the NonStop kernel&lt;/li&gt;&lt;li&gt;Safeguard extensions to NonStop kernel security system&lt;/li&gt;&lt;li&gt;Safeguard process components and their functions&lt;/li&gt;&lt;li&gt;Safeguard disk file components and global configuration options&lt;/li&gt;&lt;li&gt;Safeguard warning mode and OSS audit options&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3: User Authentication&lt;/h5&gt;
&lt;ul&gt;
&lt;li&gt;Authentication defined&lt;/li&gt;&lt;li&gt;User profile management considerations&lt;/li&gt;&lt;li&gt;Safeguard configuration options for password management and system access control&lt;/li&gt;&lt;li&gt;Guardian user IDs and OSS UID&lt;/li&gt;&lt;li&gt;Administrative and file sharing groups&lt;/li&gt;&lt;li&gt;User profile options for Guardian and OSS&lt;/li&gt;&lt;li&gt;Network users and remote passwords&lt;/li&gt;&lt;li&gt;Create a user ID using Safecom&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4: User Management with Safecom&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Safecom session commands and displays&lt;/li&gt;&lt;li&gt;User IDs and aliases management&lt;/li&gt;&lt;li&gt;File sharing group(s) for OSS usage&lt;/li&gt;&lt;li&gt;User audit attributes&lt;/li&gt;&lt;li&gt;Default protection for users&lt;/li&gt;&lt;li&gt;Safeguard authentication service&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;

&lt;h5&gt;Module 5: Guardian Security &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;System product files and sensitive utilities&lt;/li&gt;&lt;li&gt;TACL specific considerations&lt;/li&gt;&lt;li&gt;Guardian disk file access and ownership control&lt;/li&gt;&lt;li&gt;Process and ownership control&lt;/li&gt;&lt;li&gt;Guardian disk file security&lt;/li&gt;&lt;li&gt;OSS UGO bits, umask, and profile file&lt;/li&gt;&lt;li&gt;OSS sticky bit, SETUID, SETGID&lt;/li&gt;&lt;li&gt;OSS file ownership access and control&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 6: Securing OSS Files &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;OSS file system layout&lt;/li&gt;&lt;li&gt;File security&lt;/li&gt;&lt;li&gt;Permission modes&lt;/li&gt;&lt;li&gt;File and directory permissions&lt;/li&gt;&lt;li&gt;User and group IDs&lt;/li&gt;&lt;li&gt;Setting the sticky bit&lt;/li&gt;&lt;li&gt;OSS file change ownership and group association&lt;/li&gt;&lt;li&gt;OSS Access Control Lists (ACLs)&lt;/li&gt;&lt;li&gt;File and directory ACLs&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 7: Authorization and Object Access Control &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Object types and their management&lt;/li&gt;&lt;li&gt;Safecom to create and manage protection records on objects&lt;/li&gt;&lt;li&gt;Apply ACLs on objects&lt;/li&gt;&lt;li&gt;Object warning mode&lt;/li&gt;&lt;li&gt;ACL persistence&lt;/li&gt;&lt;li&gt;Node names on ACLs&lt;/li&gt;&lt;li&gt;DISKFILE-PATTERN&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;

&lt;h5&gt;Module 8: Safeguard Audit Configuration &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Sources of security event audit information&lt;/li&gt;&lt;li&gt;Create, manage, and activate audit pools&lt;/li&gt;&lt;li&gt;Audit pool recovery modes&lt;/li&gt;&lt;li&gt;OSS API and process audit&lt;/li&gt;&lt;li&gt;Safeguard configuration for OSS audit&lt;/li&gt;&lt;li&gt;AUDITENABLED option for OSS filesets&lt;/li&gt;&lt;li&gt;SAFEART utility&lt;/li&gt;&lt;li&gt;Lab&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 9: Safeguard Administration and Installation &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Safeguard security administration features&lt;/li&gt;&lt;li&gt;Assign control of Safeguard&lt;/li&gt;&lt;li&gt;Safeguard security groups&lt;/li&gt;&lt;li&gt;Safeguard installation options&lt;/li&gt;&lt;li&gt;Undeniable super ID&lt;/li&gt;&lt;li&gt;Security Event Exit Process (SEEP)&lt;/li&gt;&lt;li&gt;Learning check&lt;/li&gt;&lt;/ul&gt;

&lt;h5&gt;Onsite Delivery Equipment Requirements  &lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Workstation with terminal emulator to access lab host system&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>At the conclusion of this course, you should be able to:  


- Be familiar with the $CMON interface and TACL considerations
- Install and configure Safeguard software
- Create and manage user IDs
- Apply Access Control Lists (ACLs) on system objects
- Describe sources of audit events
- Use the Safecom command utility
- Use the SAFEART utility to generate audit reports
- Apply OSS standard security and OSS ACLs on OSS objects</objective_plain><essentials_plain>- Concepts and Facilities for HPE NonStop Systems (U4147S)
- Knowledge of TACL commands (such as STATUS, FILEINFO, and WHO) for information gathering
- Knowledge of Guardian utilities (such as FUP, SCF, and DSAP)
- Knowledge of basic OSS commands and utilities
- Ability to manage user profiles using the PASSWORD and DEFAULT programs</essentials_plain><audience_plain>- Information security administrators •Electronic Data Processing (EDP) auditors •System operations management personnel in security operations</audience_plain><outline_plain>Module 1: NonStop Kernel Security Architecture 


- Guardian and OSS application environments
- Authentication, authorization, and audit
- Goals of NonStop kernel standard security
- Components of NonStop kernel security architecture
- Memory address isolation and disk file protection
- $CMON process
- Licensed program files
- Setuid setting for OSS programs
- Lab

Module 2: Safeguard Features



- Relation of Safeguard to the NonStop kernel
- Safeguard extensions to NonStop kernel security system
- Safeguard process components and their functions
- Safeguard disk file components and global configuration options
- Safeguard warning mode and OSS audit options
- Lab
Module 3: User Authentication



- Authentication defined
- User profile management considerations
- Safeguard configuration options for password management and system access control
- Guardian user IDs and OSS UID
- Administrative and file sharing groups
- User profile options for Guardian and OSS
- Network users and remote passwords
- Create a user ID using Safecom
- Lab
Module 4: User Management with Safecom


- Safecom session commands and displays
- User IDs and aliases management
- File sharing group(s) for OSS usage
- User audit attributes
- Default protection for users
- Safeguard authentication service
- Lab


Module 5: Guardian Security 


- System product files and sensitive utilities
- TACL specific considerations
- Guardian disk file access and ownership control
- Process and ownership control
- Guardian disk file security
- OSS UGO bits, umask, and profile file
- OSS sticky bit, SETUID, SETGID
- OSS file ownership access and control
- Lab
Module 6: Securing OSS Files 


- OSS file system layout
- File security
- Permission modes
- File and directory permissions
- User and group IDs
- Setting the sticky bit
- OSS file change ownership and group association
- OSS Access Control Lists (ACLs)
- File and directory ACLs
- Lab
Module 7: Authorization and Object Access Control 


- Object types and their management
- Safecom to create and manage protection records on objects
- Apply ACLs on objects
- Object warning mode
- ACL persistence
- Node names on ACLs
- DISKFILE-PATTERN
- Lab


Module 8: Safeguard Audit Configuration 


- Sources of security event audit information
- Create, manage, and activate audit pools
- Audit pool recovery modes
- OSS API and process audit
- Safeguard configuration for OSS audit
- AUDITENABLED option for OSS filesets
- SAFEART utility
- Lab
Module 9: Safeguard Administration and Installation 


- Safeguard security administration features
- Assign control of Safeguard
- Safeguard security groups
- Safeguard installation options
- Undeniable super ID
- Security Event Exit Process (SEEP)
- Learning check


Onsite Delivery Equipment Requirements  


- Workstation with terminal emulator to access lab host system</outline_plain><duration unit="d" days="4">4 jours</duration><pricelist><price country="AT" currency="EUR">3000.00</price><price country="CH" currency="CHF">3600.00</price><price country="DE" currency="EUR">3000.00</price></pricelist><miles/></course>