19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0140 Synch\Maint Inter-Enclave LDAPS\HTTPS Usage<br />

STIG ID \ V-Key DS05.0140 \ V0011761<br />

Severity Cat II<br />

Short Name Synch\Maint Inter-Enclave LDAPS\HTTPS Usage<br />

IA Controls DCPP-1<br />

MAC /Conf 1-CSP, 2-CSP, 3-CSP<br />

References AD STIG 2.3.1.3<br />

DODI 8551.1<br />

Long Name: A synch\maint implementation that spans enclave boundaries and uses LDAPS or<br />

HTTPS protocol does not use a DODI 8551.1-compliant solution to protect the<br />

network traffic.<br />

Checks:<br />

• Interview the Application SA.<br />

• If the response to check DS05.0130 indicates that directory data *is* transferred<br />

across enclave boundaries, review the application documentation to determine if<br />

the synch\maint implementation uses the LDAPS or HTTPS protocol.<br />

• If directory data is *not* transferred across enclave boundaries or does *not* use<br />

LDAPS or HTTPS, then this check is Not Applicable.<br />

• If the synch\maint implementation transfers data using LDAPS or HTTPS, review<br />

the site network diagram(s) with the assistance of the SA, NSO, or network<br />

reviewer as required, to determine if a DODI 855.1-compliant network<br />

configuration is in use.<br />

- This generally means that the traffic must flow through a DMZ to comply with<br />

the PPSM requirements for LDAPS and HTTPS.<br />

• If the LDAPS or HTTPS traffic does not flow through a compliant network<br />

configuration, then this is a Finding.<br />

UNCLASSIFIED<br />

3-13

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!