SUMMARY
Scenario: You are a security consultant for an information systems security firm and have a new health care provider client under HIPAA compliance. Your new client wants to know the requirements and business drivers for securing the Workstation Domain in their health care environment. Your new client requires compliance with HIPAA. Similarly, your firm has a U.S. government DoD client who also wants you to perform a Workstation Domain compliance audit per DoD workstation hardening guidelines and baseline requirements. Lab #6 Student Steps: Students should perform the following steps: 1. Log on to a workstation with access to the Internet 2. The instructor will lead a classroom discussion regarding how compliance law requirements and business drivers for Workstation Domain security in a corporation may be different from the U.S. Department of Defense (DoD) 3. Use the Internet and CVE database listing (http://cve.mitre.org/) to identify risks, threats, and vulnerabilities commonly found in the Workstation Domain 4. The students will review the STIGs available via the DISA websites as well as the proper implementation of security, based on DoD recommended workstation/desktop hardening guidelines http://iase.disa.mil/stigs/index.html 5. Browse to the IASE/DISA STIGs website and the first document that needs review is the Generic Desktop Application STIG Version 4, Release 1 http://iase.disa.mil/stigs/downloads/pdf/unclassified_DesktopApplicationsGeneral_V4R1_STIG.p df 6. This PDF reviews the potential vulnerabilities and configuration recommendations for control of desktop applications in the workstation domain per DoD guidelines. Review the following concepts from this overarching DoD standards document for desktop hardening: a. Appropriate backup strategy does not exist b. Public instant message clients are installed c. Peer to Peer clients or utilities are installed d. Execution Restricted File Type Properties e. Open-restricted File Type Properties 7. Next, the Windows OS Security Guidelines will be reviewed and assessed to determine which technical controls of these are appropriate for the project assigned to the student (Windows 7 & Windows Server 2008): http://iase.disa.mil/stigs/os/index.html# 8. Download the following Windows OS Security Guideline Documents/ZIP Files: a. Windows 7 STIG, Version 1, Release 2 (unclassified_windows_7_v1r2_stig_20100827.zi b. Windows 2008 STIG Version 6, Release 1.12 (unclassified_windows_2008_v6r1.12_stig_20100827.zip) 9. Extract the Windows 7 STIG, Version 1, Release 2 .ZIP file and browse to the unzipped directory 10. Find the U_Windows_7_V1R2_STIG_Manual.zip file and extract its contents as well 11. Find and open the U_Windows_7_V1R2_STIG_Manual-XCCDF.xml in the directory of the newly extracted Manual .ZIP file. Review some of the following concepts and vulnerabilities for configuring and hardening Windows 2008 Domain Controllers: a. Display Shutdown Button b. Clear System Pagefile c. Removable media devices d. Halt on Audit Failure e. Security Configuration Tools 12. Extract the Windows 2008 STIG Version 6, Release 1.12 .ZIP file and browse to the unzipped directory 13. Find the U_Windows_2008_V6R1.12_STIG_Manual.zip file and extract its contents as well 14. Find and open the U_Windows_2008_DC_V6R1.12_STIG_Manual-XCCDF.xml in the Domain Controller directory of the newly extracted Manual .ZIP file. Review some of the following concepts and vulnerabilities for configuring and hardening Windows 2008 Domain Controllers: a. System Recovery Backups b. Caching of logon credentials c. Dormant Accounts d. Recycle Bin Configuration e. Privilege passwords are not unique f. Printer Share Permissions 15. Review the National Cyber Security Division of the U.S. Homeland Security Departments CVE listing hosted by the Mitre Corporation. http://cve.mitre.org/. Demonstrate how Workstation Domain OS and application software vulnerabilities are housed on the CVE listing and National Vulnerability Database. Discuss how this is both a security control tool and an attack tool used by hackers 16. Explain to the students that they are to craft an executive summary summarizing the top Workstation Domain risks, threats, and vulnerabilities and include a description of the risk mitigation tactics you would perform in order audit the Workstation Domain for Compliance. Use the U.S. DoD Workstation Hardening Guidelines as your example for a baseline definition for compliance.








Jermaine Byrant
Nicole Johnson



