V-243501
CAT IIIThe impact of CPCON changes on the cross-directory authentication configuration must be considered and procedures documented.
- Ships Affected
- 1
- Total Findings
- 1
- Open
- 0
- Closed
- 0
Check Text
1. Refer to the list of actual manual AD trusts (cross-directory configurations) collected from the site representative.
2. If there are no manual AD trusts (cross-directory configurations) defined, this check is not applicable.
For AD, this includes external, forest, or realm trust relationship types.
3. Obtain a copy of the site's supplemental CPCON procedures as required by Strategic Command Directive (SD) 527-1.
4. Verify that it has been determined by the IAM whether CPCON response actions need to include procedures to disable manual AD trusts (cross-directory configurations). The objective is to determine if the need has been explicitly evaluated.
5. If it has been determined that actions to disable manual AD trusts (cross-directory configurations) are not necessary, then this check is not applicable.
6. If it has been determined that actions to disable manual AD trusts (cross-directory configurations) are necessary, verify that the policy to implement these actions has been documented.
7. If actions to disable manual AD trusts (cross-directory configurations) are needed and no policy has been documented, then this is a finding.
Fix Text
Evaluate cross-directory configurations (such as trusts and pass-through authentication) and provide documentation that indicates:
1. An evaluation was performed.
2. The specific AD trust configurations, if any, that must be disabled during changes in CPCON status because they could represent increased risk.
STIG Reference
- STIG
- Active Directory Domain Security Technical Implementation Guide
- Version
- 3
- Release
- 7
- Rule ID
- SV-243501r1016334_rule
All Occurrences
This vulnerability appears on 1 ship(s)
| Ship | Hull # | Source File | Status | Assigned To | Scan Date | Actions |
|---|---|---|---|---|---|---|
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-DC-003/Checklist/MONT-DC-003_ADDomain_V3R5_20251023-171837.ckl | Unassigned | 2026-01-14T12:57:36.435963 | View in Context |