19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

3.3 Active Directory Domain<br />

Notes: The checks in this section apply to Active Directory Domain assets and are performed<br />

only once per AD domain, on any one domain controller.<br />

DS10.0260 AD Object Ownership Delegation<br />

STIG ID \ V-Key DS10.0260 \ V0008521<br />

Severity Cat II<br />

Short Name AD Object Ownership Delegation<br />

IA Controls ECLP-1, ECPA-1<br />

MAC /Conf 1-CSP, 2-CSP, 3-CSP<br />

References AD STIG 2.3.3.6<br />

Long Name: The number of accounts is excessive or documentation does not exist for the<br />

accounts that have been delegated AD object ownership or update permissions<br />

and are *not* members of Windows built-in administrative groups.<br />

Checks:<br />

• Interview the IAM.<br />

• Obtain the list of accounts that have been delegated AD object ownership or<br />

update permissions and that are *not* members of Windows built-in<br />

administrative groups.<br />

[This includes accounts for help desk or support personnel who are not<br />

Administrators, but have authority in AD to maintain user accounts or printers.]<br />

• If accounts with delegated authority are defined and there is no list, then this is a<br />

Finding.<br />

• Count the number of accounts on the list.<br />

• If the number of accounts with delegated authority is greater than ten (10), review<br />

the site documentation that justifies this number.<br />

- The object is to validate that the IAM explicitly acknowledges the need to have<br />

a high number of privileged users.<br />

• If the number of accounts with delegated authority is greater than ten (10) and<br />

there is no statement in the documentation that justifies the number, then this is a<br />

Finding.<br />

UNCLASSIFIED<br />

3-5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!