19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

SUMMARY OF CHANGES<br />

Version 1 R1.2 – 22 September 2006<br />

General - Updated version to V1R1.2 and date to 22 September 2006.<br />

Section 1 - 1.2 - Updated description of Appendix B.<br />

- 1.4 - Renamed section to “Review Methodology” and added<br />

paragraph to reference new “Pre-Trip Information Gathering” section.<br />

Section 2 - 2.4 - Revised section to map appropriately to the specific review<br />

items.<br />

Section 3 - 3.1 - Added paragraph to note the value of gathering information in<br />

advance and reference new “Pre-Trip Information Gathering” section.<br />

Added paragraph to reference FSMO information gathering<br />

procedures in Appendix D.<br />

- DS10.0260 - Updated text to clarify that list is required only if<br />

privileged accounts exist.<br />

- Updated (VMS Fixes) text to add example justification<br />

statement.<br />

- DS10.0350 - Added text to note that pre-requisite check (DS10.0100)<br />

is a manual check in section 5.<br />

- DS05.0170 - Added text to note that pre-requisite check (DS05.0160)<br />

is a manual check in section 5.<br />

Section 5 - 5.1 - Added paragraph to note the value of gathering information in<br />

advance and reference new “Pre-Trip Information Gathering” section.<br />

Added paragraph to reference FSMO information gathering<br />

procedures in Appendix D.<br />

- DS00.0120 - Corrected STIG reference to 2.3.3.3.<br />

- DS10.0140 - Added “ADAM_instance” as an additional example.<br />

- Added note that MS Windows-based DNS is an<br />

acceptable application.<br />

- DS10.0170 - Added text to clarify that the objective is to verify that a<br />

*current* need for each trust exists.<br />

- DS10.0180 - Added text to clarify that check applies only to trusts<br />

between DoD organizations.<br />

- DS10.0240 - Updated (VMS Fixes) text to add example justification<br />

statement.<br />

- DS10.0250 - Added text to show the format of an account from an<br />

outside domain.<br />

- DS10.0295 - Updated header text to indicate that check applies only<br />

to the forest root PDC Emulator DC.<br />

Appendix A - A.1.1 - Added explanation of accounts marked with an asterisk.<br />

Appendix B - Renamed to “Documentation”.<br />

- Inserted section B.1, “Pre-Trip Information Gathering”.<br />

- B.2.1.1 - Corrected the “N\A” value to “No” in the Transitive column<br />

for the Realm trust example.<br />

UNCLASSIFIED<br />

v

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!