Setup guide

UNCLASSIFIED
UNCLASSIFIED
25
Chapter 4-
Configuring System Settings
Figure 4: Active Screen Corners Panel
7. Use the pull-down menu corresponding to the corner chosen as the screen
saver hot corner, and select Start Screen Saver in the menu.
8. Click the OK button.
Security Settings
The Security option is found in the Personal row in System Preferences. Unlike
most panels, the Security panel’s lock only applies to part of the panel, the bottom
section for All Accounts on this Computer. The other settings in the panel are
not affected by the lock and apply only to the account currretly logged in. Turning
on encryption for the user’s directory (FileVault), however, requires an
administrator ID and password. This means FileVault must be set up by an
administrator while logged into the user account. Configuring FileVault for
individual users is addressed in the section on configuring user accounts in
Chapter 5.
FileVault
Mac OS X’s FileVault feature for encrypting home folders is strongly
recommended for systems whose physical security cannot always be
guaranteed, such as portables like the iBook and PowerBook. FileVault
encryption should be enabled for the system and for all user accounts. When
FileVault is enabled for a user account, files in the user’s home folder files are
encrypted, and thereby protected from casual viewing if the system is
compromised. However, FileVault may adversely affect disk-intensive tasks
such as video editing. If delays in disk-intensive tasks interfere with
operational needs, use of FileVault may not be practical.
FileVault cannot guarantee the confidentiality of a file that existed before
FileVault was activated because the file itself or an application’s working copy
of the file may have been deleted. Deleted data still exist on the drive, unless
removed with the Secure Empty Trash feature, which applications do not
typically use. Consider files protected by FileVault only if they have been
received or created after FileVault was activated. Running a commercial tool
to sanitize all unused space on the drive (where deleted files may exist) is
another means of addressing the problem of unencrypted data that users wish
protected by FileVault.