STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide (STIG) Version: 2 Release: 13 Benchmark Date: 26 Apr 2019:

If a VPN is used in the AD implementation, the traffic must be inspected by the network Intrusion detection system (IDS).

DISA Rule

SV-30994r3_rule

Vulnerability Number

V-8523

Group Title

IDS Visibility of Directory VPN Data Transport

Rule Version

DS00.4140_AD

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Replace the VPN solution or reconfigure it so that directory data is inspected by a network or host-based IDS.

Check Contents

1. Interview the site representative. Ask about the location of the domain controllers.

2. If domain controllers are not located in multiple enclaves, then this check is not applicable.

3. If domain controllers are located in multiple enclaves and a VPN is not used, then this check is not applicable.

4. If domain controllers are located in multiple enclaves and a VPN is used, review the site network diagram(s) with the SA, NSO, or network reviewer as required to determine if the AD network traffic is visible to a network or host IDS.

5. If the AD network traffic is not visible to a network or host IDS, then this is a finding.

Vulnerability Number

V-8523

Documentable

False

Rule Version

DS00.4140_AD

Severity Override Guidance

1. Interview the site representative. Ask about the location of the domain controllers.

2. If domain controllers are not located in multiple enclaves, then this check is not applicable.

3. If domain controllers are located in multiple enclaves and a VPN is not used, then this check is not applicable.

4. If domain controllers are located in multiple enclaves and a VPN is used, review the site network diagram(s) with the SA, NSO, or network reviewer as required to determine if the AD network traffic is visible to a network or host IDS.

5. If the AD network traffic is not visible to a network or host IDS, then this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

870

Comments