19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0320 Synch\Maint Local Code Configuration Management<br />

STIG ID \ V-Key DS05.0320 \ V0011767<br />

Severity Cat III<br />

Short Name Synch\Maint Local Code Configuration Management<br />

IA Controls ECSD-1, ECSD-2<br />

MAC /Conf 1-CSP, 2-CSP, 3-CSP<br />

References AD STIG 2.3.3.7<br />

Long Name: There is no policy to ensure that code that is not vendor-provided and is used in a<br />

synch\maint implementation that updates security principal accounts is subject to<br />

a configuration management process.<br />

Checks:<br />

• Interview the Application SA.<br />

• Determine if a synch\maint implementation that updates security principal<br />

accounts includes code not provided by the vendor.<br />

- For MIIS\IIFP, this refers to Management Agents (MAs) not provided from<br />

Microsoft.<br />

[Retain this code information for use in a subsequent check.]<br />

• If the synch\maint implementation does *not* use non-vendor code, then this<br />

check is Not Applicable.<br />

• If the synch\maint implementation *does* use non-vendor code, obtain a copy of<br />

the site’s configuration management procedures documentation.<br />

• Verify that there is a local policy that requires implementation and changes to the<br />

code to be processed through a configuration management process.<br />

• If there is no policy that requires code implementation and changes to be<br />

processed through a configuration management process, then this is a Finding.<br />

UNCLASSIFIED<br />

3-19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!