19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS10.0130 AD Data File Locations<br />

STIG ID \ V-Key DS10.0130 \ V0008317<br />

Severity Cat II<br />

Short Name AD Data File Locations<br />

IA Controls DCSP-1<br />

MAC /Conf 1-CSP, 2-CSP<br />

References AD STIG 2.3.1.5<br />

Long Name: The AD data files are located on the same logical partition as directories and files<br />

owned by users.<br />

Checks:<br />

• Refer to the AD database, log, and work file information obtained in check<br />

DS00.0120. Note the logical drive (e.g., “C:”) on which the files are located.<br />

• At a command line prompt enter “net share”.<br />

• Record the logical drive(s) for any site-created shares. [Ignore all system<br />

(NETLOGON, SYSVOL, and administrative (ending in $)) shares.]<br />

• If any site-created shares are located on the same logical drive as the AD<br />

database, log, or work files, then this is a Finding.<br />

UNCLASSIFIED<br />

5-4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!