Skip to content

The impact of INFOCON changes on the cross-directory authentication configuration must be considered and procedures documented.

An XCCDF Rule

Description

<VulnDiscussion>When incidents occur that require a change in the INFOCON status, it may be necessary to take action to restrict or disable certain types of access that is based on a directory outside the Component's control. Cross-directory configurations (such as trusts and pass-through authentication) are specifically designed to enable resource access across directories. If conditions indicate that an outside directory is at increased risk of compromise in the immediate or near future, actions to avoid a spread of the effects of the compromise should be taken. A trusted outside directory that is compromised could allow an unauthorized user to access resources in the trusting directory.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-243501r723557_rule
Severity
Low
References
Updated



Remediation - Manual Procedure

Evaluate cross-directory configurations (such as trusts and pass-through authentication) and provide documentation that indicates: 
1. That an evaluation was performed. 
2. The specific AD trust configurations, if any, that should be disabled during changes in INFOCON status because they could represent increased risk.