19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS05.0420 Synch\Maint Server Physical Access<br />

STIG ID \ V-Key DS05.0420 \ V0011778<br />

Severity Cat II<br />

Short Name Synch\Maint Server Physical Access<br />

IA Controls PECF-1, PECF-2<br />

MAC /Conf 1-CS, 2-CS, 3-CS<br />

References AD STIG 2.3.5<br />

Long Name: Physical access to a host used in routine, scheduled synch\maint operations is not<br />

restricted to authorized personnel.<br />

Checks:<br />

• Interview the Application SA.<br />

• Verify that physical access to hosts used in routine, scheduled synch\maint<br />

operations is restricted to authorized personnel.<br />

- This includes the Windows host(s) holding any synch\maint databases and<br />

synch\maint application executables.<br />

• If physical access to a host used in routine, scheduled synch\maint operations is<br />

not restricted, then this is a Finding.<br />

DS05.0430 Synch\Maint Data Backup<br />

STIG ID \ V-Key DS05.0430 \ V0011779<br />

Severity Cat II<br />

Short Name Synch\Maint Data Backup<br />

IA Controls CODB-1, CODB-2, CODB-3<br />

MAC /Conf 1-CSP, 2-CSP, 3-CSP<br />

References AD STIG 2.3.6<br />

Long Name: Production data from routine, scheduled synch\maint operations is not backed up<br />

periodically.<br />

Checks:<br />

• Interview the Application SA.<br />

• Obtain a copy of the site’s SOP for backups.<br />

• Check the SOP for the frequency at which data used in routine, scheduled<br />

synch\maint operations is backed up.<br />

- Alternatively, physically verify that backups are being taken.<br />

• If the synch\maint data for a MAC III system is not backed up weekly or at least<br />

after each execution, then this is a Finding.<br />

• If the synch\maint data for a MAC I or II system is not backed up daily or at least<br />

after each execution, then this is a Finding.<br />

UNCLASSIFIED<br />

3-30

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!