19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0340 Synch\Maint Aggregate Transport Encryption<br />

STIG ID \ V-Key DS05.0340 \ V0011771<br />

Severity Cat II<br />

Short Name Synch\Maint Aggregate Transport Encryption<br />

IA Controls ECCT-1, ECCT-2, ECNK-1, ECNK-2<br />

MAC /Conf 1-CS, 2-CS, 3-CS<br />

References AD STIG 2.3.3.8<br />

Long Name: A synch\maint implementation that transfers a substantial aggregate of the<br />

directory data for an entire geographic command does not use FIPS 140-2validated<br />

encryption to protect the network traffic.<br />

Checks:<br />

• Interview the Application SA.<br />

• Determine if data transmitted by the synch\maint implementation contains<br />

directory information for an *entire* geographic command such as DISA<br />

CONUS, DISA EUROPE, or DISA PACIFIC or for *all* members of a Service<br />

or other Component.<br />

- An examination of the application documentation or directory query strings can<br />

be used to establish this.<br />

• If the data transmitted by the synch\maint implementation does *not* contain<br />

substantial aggregates, then this check is Not Applicable.<br />

• If the data transmitted by the synch\maint implementation *does* contain a<br />

substantial aggregate, review the application documentation and site network<br />

diagram(s) to determine if FIPS 140-2-validated encryption is used to protect the<br />

network traffic.<br />

- This includes encryption of the data on the host before transmission, the use of<br />

LDAPS or HTTPS protocol, or the use of network components (such as a VPN)<br />

to perform encryption.<br />

• If the data transmitted by the synch\maint implementation contains a substantial<br />

aggregate and it is not encrypted, then this is a Finding.<br />

UNCLASSIFIED<br />

3-23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!