19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0210 Synch\Maint Password Protection<br />

STIG ID \ V-Key DS05.0210 \ V0011764<br />

Severity Cat I<br />

Short Name Synch\Maint Password Protection<br />

IA Controls IAIA-1, IAIA-2<br />

MAC /Conf 1-CS, 2-CS, 3-CS<br />

References AD STIG 2.3.2<br />

Long Name: A password used in the execution of a synch\maint implementation is embedded<br />

in a script or stored in an unencrypted file.<br />

Checks:<br />

• Interview the Application SA.<br />

• Verify whether the execution of the synch\maint implementation uses a script in<br />

which a password is embedded or uses any unencrypted file that contains a<br />

password.<br />

- Verification can involve review of the operating documentation or observation<br />

of the execution of a synch\maint cycle.<br />

• If execution of the synch\maint implementation uses a script in which a password<br />

is embedded or uses any unencrypted file that contains a password, then this is a<br />

Finding.<br />

UNCLASSIFIED<br />

3-16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!