19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0390 Synch\Maint Remote Access Session Logs<br />

STIG ID \ V-Key DS05.0390 \ V0011775<br />

Severity Cat II<br />

Short Name Synch\Maint Remote Access Session Logs<br />

IA Controls EBRP-1<br />

MAC /Conf 1-CS, 2-CS, 3-CS<br />

References AD STIG 2.3.4<br />

Long Name: Sessions for privileged remote access to a synch\maint implementation are not<br />

logged or the logs are not reviewed at least weekly.<br />

Checks:<br />

• Interview the Application SA.<br />

• If the information obtained in check DS05.0380 indicates the synch\maint<br />

implementation does *not* support and utilize privileged remote access, then this<br />

check is Not Applicable.<br />

• Obtain a copy of the site’s policy that addresses privileged remote access.<br />

• Check that the policy addresses the requirements to capture session logs and to<br />

review them at least weekly.<br />

Alternatively review the logs or other evidence that indicates session capture and<br />

review.<br />

• If session logs are not captured or the logs are not reviewed at least weekly, then<br />

this is a Finding.<br />

UNCLASSIFIED<br />

3-27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!