Skip to main content
CUI

Scan: _Reviewed/MONT-DC-003/Checklist/MONT-DC-003_ADForest_V3R2_20251023-171845.ckl

Scan Information

Hull Number
T-ESD-1
Scan Date
2026-01-14
Source File
MONT-DC-003 ADForest 20251023-171845
Source Tool
Evaluate-STIG
Imported
2026-01-14 17:57
Hostname (from CKL asset — override if blank or incorrect)
STIG Benchmark

Active Directory Forest Security Technical Implementation Guide

Version

V3R2

Score

66.7%

Total

7

Open

2

OCA Technology Area

Assign this checklist to an OCA assessment area for scoring

Hostname
MONT-DC-003
STIG Benchmark
Active Directory Forest Security Technical Implementation Guide
Current Area: Domain Name System

STIG Rule Mapping

7
Mapped to STIG
0
Unmapped
7
Total Findings
All findings mapped to STIG rules.

Checklist Scoring

Severity Not a Finding Not Applicable Open Not Reviewed Total
CAT I 3 0 0 0 3
CAT II 1 0 2 0 3
CAT III 0 0 0 1 1
Total 4 0 2 1 7
Filter:

Vuln IDs (7)

V-243502 Membership to the Schema Admins group must be limi...
V-243503 Anonymous Access to AD forest data above the rootD...
V-243504 The Windows Time Service on the forest root PDC Em...
V-243505 Changes to the AD schema must be subject to a docu...
V-243506 Update access to the directory schema must be rest...
V-269098 Windows Server hosting Active Directory Certificat...
V-269099 Windows Server running Active Directory Certificat...

Vulnerability Details

Click a Vuln ID on the left to view details.

Status & Comments

Select a finding to edit.

CUI