EconPapers    
Economics at your fingertips  
 

Lessons learned from offline assessment of security-critical systems: the case of microsoft’s active directory

Shouki A. Ebad ()
Additional contact information
Shouki A. Ebad: Northern Border University

International Journal of System Assurance Engineering and Management, 2022, vol. 13, issue 1, No 39, 535-545

Abstract: Abstract One of the famous directory services on the market is Active Directory (AD) by Microsoft. It consists of a set of services that work on Windows Server to manage access to networked resources. In this paper, an offline assessment is conducted to identify the security threats on an AD in an operational environment. The assessment and open discussion were performed, in which AD issues were first identified. This paper was written from a security auditor’s perspective, with a detailed experience report of the assessment findings and risk mitigation plan. As results, risk issues covered a variety of areas such as operational excellence, privileged computer/user accounts, trusts and forest configuration, operating system security updates, and security compliance manager (SCM) analysis. Lessons learned were also discussed as a guidance for security researchers and practitioners dealing with analogous issues in similar contexts. Such lessons included a remediation plan and formal security policies and procedures.

Keywords: System management; Systems security; Active directory; Risk assessment; Access control (search for similar items in EconPapers)
Date: 2022
References: View complete reference list from CitEc
Citations: View citations in EconPapers (1)

Downloads: (external link)
http://link.springer.com/10.1007/s13198-021-01236-2 Abstract (text/html)
Access to the full text of the articles in this series is restricted.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:spr:ijsaem:v:13:y:2022:i:1:d:10.1007_s13198-021-01236-2

Ordering information: This journal article can be ordered from
http://www.springer.com/engineering/journal/13198

DOI: 10.1007/s13198-021-01236-2

Access Statistics for this article

International Journal of System Assurance Engineering and Management is currently edited by P.K. Kapur, A.K. Verma and U. Kumar

More articles in International Journal of System Assurance Engineering and Management from Springer, The Society for Reliability, Engineering Quality and Operations Management (SREQOM),India, and Division of Operation and Maintenance, Lulea University of Technology, Sweden
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().

 
Page updated 2025-03-20
Handle: RePEc:spr:ijsaem:v:13:y:2022:i:1:d:10.1007_s13198-021-01236-2