Skip to content

Each cross-directory authentication configuration must be documented.

An XCCDF Rule

Description

Active Directory (AD) external, forest, and realm trust configurations are designed to extend resource access to a wider range of users (those in other directories). If specific baseline documentation of authorized AD external, forest, and realm trust configurations is not maintained, it is impossible to determine if the configurations are consistent with the intended security policy.

ID
SV-243494r959010_rule
Version
DS00.1120_AD
Severity
Low
References
Updated

Remediation Templates

A Manual Procedure

Develop documentation for each AD external, forest, and realm trust configuration. At a minimum this must include:
Type (external, forest, or realm)
Name of the other party
Confidentiality, Availability, and Integrity categorization
Classification level of the other party
Trust direction (inbound and/or outbound)