20.15 Ensure 'Data files owned by users must be on a different logical partition from the directory server data files' (STIG DC only)

Information

This policy setting ensure that data files that are owned by users are on a different logical partition from the directory server data files.

When directory service data files, especially for directories used for identification, authentication, or authorization, reside on the same logical partition as user-owned files, the directory service data may be more vulnerable to unauthorized access or other availability compromises. Directory service and user-owned data files sharing a partition may be configured with less restrictive permissions in order to allow access to the user data.

The directory service may be vulnerable to a denial of service attack when user-owned files on a common partition are expanded to an extent preventing the directory service from acquiring more space for directory or audit data.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Move shares used to store files owned by users to a different logical partition than the directory server data files.

Impact:

Multiple partitions must be created for the system.

See Also

https://workbench.cisecurity.org/benchmarks/15301

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-4

Plugin: Windows

Control ID: 50cb95d6737d1b26d8b1f6749226800077cf9d81ce1de150db9e7cf3c948a4bb