19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

APPENDIX C: VMS PROCESS GUIDANCE<br />

This appendix provides guidance for entering and accessing the asset information in VMS for the<br />

items covered by the Checklist. There are three review subjects covered in the Checklist:<br />

- Active Directory Implementation - This subject covers checks for AD Domain<br />

Controllers, AD Domains, and the AD Forest that make up an implementation of Active<br />

Directory.<br />

- Synchronization\Maintenance Application - This subject covers checks for an individual<br />

installation of an application used to perform synchronization or maintenance on one or<br />

more Active Directory implementations.<br />

- ADAM - This subject covers checks for an individual installation of ADAM as a<br />

directory service.<br />

To understand how to access the VMS data, it is helpful to know how the data is organized. The<br />

following table summarizes this VMS data organization.<br />

Review Subject Items Included VMS<br />

VMS<br />

Asset Data Organization Asset Type<br />

Active Directory AD Domain Controller Windows server OS Asset Posture Computing<br />

Implementation<br />

with Domain Controller Role<br />

AD Domain Active Directory Domain Asset Non-Computing<br />

AD Forest Active Directory Forest Asset Non-Computing<br />

Synch\Maint<br />

Application<br />

Synch\Maint Application Synch\Maint App Asset Posture Computing<br />

ADAM ADAM Instance ADAM Instance Asset Posture Computing<br />

Note: The path used to access asset data in the VMS application depends on the assigned role of<br />

the user:<br />

- System Administrators (SAs) use the Asset Finding Maint. item on the VMS menu,<br />

select the Assets / Findings item, and navigate to assets under the By Location branch.<br />

- Reviewers use the Asset Finding Maint. item on the VMS menu, select the Assets /<br />

Findings item, and navigate to assets under the Visit branch.<br />

Because this is the significant detail in which the procedures vary between SAs and<br />

Reviewers, a single set of procedures is defined here and variations are noted where relevant.<br />

C.1 AD Implementation Data - AD Domain Controller, AD Domain, AD Forest<br />

AD implementation data is expressed in VMS through three categories:<br />

- The AD Domain Controller category is not explicitly defined in VMS. Rather, to take<br />

advantage of the existing VMS data, the asset data for AD Domain Controllers is stored<br />

under assets that are defined with a Windows server OS Asset Posture and the Domain<br />

Controller Role.<br />

- AD Domain asset data is stored though the definition of an “Active Directory Domain”<br />

Non-Computing asset in VMS.<br />

- AD Forest asset data is stored though the definition of an “Active Directory Forest”<br />

Non-Computing asset in VMS.<br />

UNCLASSIFIED<br />

C-1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!