STIGQter STIGQter: STIG Summary: Windows PAW Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 15 May 2020:

In a Windows PAW, administrator accounts used for maintaining the PAW must be separate from administrative accounts used to manage high-value IT resources.

DISA Rule

SV-92879r1_rule

Vulnerability Number

V-78173

Group Title

PAW-00-001500

Rule Version

WPAW-00-001500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set up separate domain administrative accounts to manage PAWs from domain administrative accounts used to manage high-value IT resources. Each of these accounts is not to be used for any other purpose.

Note: Personnel assigned as PAW administrators should be the most trusted and experienced administrators within an organization.

Check Contents

Verify at least one group has been set up in Active Directory (usually Tier 0) for administrators responsible for maintaining PAW workstations (for example, PAW Maintenance group).

Verify no administrator account or administrator account group has been assigned to both the group of PAW workstation administrators and any group for administrators of high-value IT resources.

If separate PAW administrator groups and administrators of high-value IT resources have not been set up, this is a finding.

If a member of any group of PAW maintenance administrators is also a member of any group of administrators of high-value IT resources, this is a finding.

Vulnerability Number

V-78173

Documentable

False

Rule Version

WPAW-00-001500

Severity Override Guidance

Verify at least one group has been set up in Active Directory (usually Tier 0) for administrators responsible for maintaining PAW workstations (for example, PAW Maintenance group).

Verify no administrator account or administrator account group has been assigned to both the group of PAW workstation administrators and any group for administrators of high-value IT resources.

If separate PAW administrator groups and administrators of high-value IT resources have not been set up, this is a finding.

If a member of any group of PAW maintenance administrators is also a member of any group of administrators of high-value IT resources, this is a finding.

Check Content Reference

M

Target Key

3283

Comments