19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS10.0110 AD Inter-Enclave VPN Usage<br />

STIG ID \ V-Key DS10.0110 \ V0008522<br />

Severity Cat II<br />

Short Name AD Inter-Enclave VPN Usage<br />

IA Controls DCPP-1<br />

MAC /Conf 1-CSP, 2-CSP, 3-CSP<br />

References AD STIG 2.3.1.3<br />

DODI 8551.1<br />

Long Name: An AD implementation (domains or forest) that spans enclave boundaries does<br />

not use a VPN to protect AD network traffic.<br />

Checks:<br />

• Interview the IAM.<br />

• With the assistance of the SA, NSO, or network reviewer as required, review the<br />

site network diagram(s) to determine if domain controllers for the AD forest are<br />

located in multiple enclaves.<br />

- The object is to determine if AD network traffic is traversing enclave network<br />

boundaries.<br />

• If domain controllers are *not* located in multiple enclaves, then this check is<br />

Not Applicable.<br />

• If domain controllers are located in multiple enclaves, verify that a VPN is used to<br />

transport the AD network traffic (replication, user logon, AD queries, etc.).<br />

[Retain this location and VPN information for use in a subsequent check.]<br />

• If a VPN solution is not used to transport AD network traffic across enclave<br />

boundaries, then this is a Finding.<br />

Note: This check and the associated requirement are based on DoD ports and<br />

protocols restrictions stated in DoD Instruction 8551.1 and linked documents.<br />

UNCLASSIFIED<br />

3-6

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!