STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide Version: 3 Release: 7 Benchmark Date: 01 Apr 2026:

Access to need-to-know information must be restricted to an authorized community of interest.

DISA Rule

SV-243481r959010_rule

Vulnerability Number

V-243481

Group Title

SRG-OS-000480

Rule Version

AD.0170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Delete the unneeded trust relationship or document the access requirement or mission need for the trust.

Check Contents

1. Before performing this check, perform V-243494, which validates the trusts within the documentation are current within AD.

2. Obtain documentation of the site's approved trusts from the site representative.

3. For each of the identified trusts, verify the documentation includes a justification or explanation of the need-to-know basis of the trust.

4. If the need for the trust is not documented, this is a finding.

Vulnerability Number

V-243481

Documentable

False

Rule Version

AD.0170

Severity Override Guidance

1. Before performing this check, perform V-243494, which validates the trusts within the documentation are current within AD.

2. Obtain documentation of the site's approved trusts from the site representative.

3. For each of the identified trusts, verify the documentation includes a justification or explanation of the need-to-know basis of the trust.

4. If the need for the trust is not documented, this is a finding.

Check Content Reference

M

Target Key

5406