19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

B.1.2 Pre-Trip Documentation<br />

The SRR team members must make every attempt to obtain copies of the documents and<br />

procedures listed below prior to arriving on-site. The SRR team members work with the site<br />

POC to capture the required information to the fullest extent possible.<br />

Documents:<br />

a. Network diagram displaying AD architecture (forest hierarchy) including the location of<br />

Flexible Single-Master Operations (FSMO) domain controllers. The location of premise<br />

routers and any Intrusion Detection Systems should also be displayed.<br />

b. Password Policy<br />

c. List of accounts assigned to AD privileged groups including Domain Admins, Enterprise<br />

Admins, Schema Admins, Group Policy Creator Owners, and Incoming Forest Trust<br />

Builders<br />

d. List of accounts that are not members of the AD privileged groups, but do have<br />

(delegated) permission to create or change AD objects<br />

e. List of AD trust relationships, their characteristics, and the access requirement(s) that the<br />

trusts support<br />

f. Trust relationship documentation<br />

Procedures:<br />

a. Standard Operating Procedures (SOP) for data backup<br />

b. Supplemental INFOCON response procedures, including any AD trust-specific actions<br />

c. Configuration management procedures that apply to AD schema updates<br />

d. Disaster recovery procedures, including any AD-specific actions<br />

The SRR team members will obtain copies of all listed documentation and procedures for<br />

examination. The Team Lead or Reviewer should request the documentation from the site's POC<br />

in any one of the following formats, listed in the order of preference:<br />

- CD-ROM<br />

- Diskette<br />

- Signed, encrypted e-mail<br />

- Paper.<br />

UNCLASSIFIED<br />

B-2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!