19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0330 Synch\Maint Data Transport Encryption<br />

STIG ID \ V-Key DS05.0330 \ V0011769<br />

Severity Cat II<br />

Short Name Synch\Maint Data Transport Encryption<br />

IA Controls ECCT-1, ECCT-2, ECNK-1, ECNK-2<br />

MAC /Conf 1-CS, 2-CS, 3-CS<br />

References AD STIG 2.3.3.8<br />

Long Name: A synch\maint implementation that transfers data over wireless or non-DoD<br />

networks does not use FIPS 140-2-validated encryption to protect the network<br />

traffic.<br />

Checks:<br />

• Interview the Application SA.<br />

• With the assistance of the SA, NSO, or network reviewer as required, review the<br />

site network diagram(s) and application documentation to determine if the<br />

synch\maint implementation transfers data over wireless or non-DoD networks.<br />

• If data is *not* transferred over wireless or non-DoD networks, then this check is<br />

Not Applicable.<br />

• If data *is* transferred over wireless or non-DoD networks, review the site<br />

network diagram(s) and application documentation to determine if FIPS 140-2validated<br />

encryption is used to protect the network traffic.<br />

- This includes encryption of the data on the host before transmission, the use of<br />

LDAPS or HTTPS protocol, or the use of network components (such as a VPN)<br />

to perform encryption.<br />

• If data *is* transferred over wireless or non-DoD networks and acceptable<br />

encryption is not used, then this is a Finding.<br />

UNCLASSIFIED<br />

3-21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!