Ensure that access to the server parameter file is restricted to the owner of the Oracle software set and the DBA group
This is basic WinDoze security stuff, if you do not know anything about this, you may want to post a question in some WinDoze forum.

Good Luck!