19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0310 Synch\Maint Application Account Dedication<br />

STIG ID \ V-Key DS05.0310 \ V0011794<br />

Severity Cat II<br />

Short Name Synch\Maint Application Account Dedication<br />

IA Controls ECLP-1<br />

MAC /Conf 1-CSP, 2-CSP, 3-CSP<br />

References AD STIG 2.3.3.6<br />

Long Name: An account used for a directory synchronization or maintenance application is not<br />

dedicated for that function.<br />

Checks:<br />

• Refer to the list of application accounts obtained in check DS05.0300.<br />

• For *each* application account:<br />

- Examine the Full Name information to determine if the account may be assigned<br />

as a user account (instead of an application account).<br />

- If the information is ambiguous, ask the SA to confirm whether the account is<br />

assigned as a user or application account.<br />

• If any synchronization or maintenance application account is assigned as a user<br />

account, then this is a finding.<br />

UNCLASSIFIED<br />

5-42

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!