Level II Assessment Forms

The following forms, as shown in Tables B.5, B.6, and B.7, can be used when assessing servers and during system demonstrations.

Table B.5. Password Controls
Password ActionRecommended ValueActual Value
Enforce password history10 days 
Maximum password age30 days 
Minimum password age1 day 
Minimum password length7 characters 
Passwords must meet complexityEnabled 
Account lockout thresholdAfter 3 attempts 
Table B.6. Audit Controls
AuditingRecommended ValueActual Value
Audit system eventsSuccess and failure 
Audit process trackingNone 
Audit privilege useFailure 
Audit account logon eventsFailure 
Audit account managementSuccess and failure 
Audit directory service accessNone 
Audit logon eventsFailure 
Audit object accessSuccess

Get Inside Network Security Assessment: Guarding Your IT Infrastructure now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.