<?xml version="1.0" encoding="UTF-8"?>
<ocil xsi:schemaLocation="http://www.mitre.org/ocil/2 ocil.xsd" xmlns="http://www.mitre.org/ocil/2"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
    <generator>
        <schema_version>2.0</schema_version>
        <timestamp>2009-08-19T00:00:00</timestamp>
    </generator>

    <!-- ==================================================================================================== -->
    <!-- ========================================  QUESTIONNAIRES  ========================================== -->
    <!-- ==================================================================================================== -->
    <questionnaires>
        <questionnaire id="ocil:mitre.org:questionnaire:1" priority="LOW">
            <title>Physical security Requirements</title>
            <description>Inadequate physical protection can undermine all other security precautions
                utilized to protect the system. This can jeopardize the confidentiality,
                availability, and integrity of the system. Physical security of the AIS is the first
                line protection of any system. Note: Critical servers should be located in rooms, or
                locked cabinets, that are accessible only to authorized systems personnel. User
                workstations containing sensitive data should be in access controlled
                areas.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:11</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:2" priority="LOW">
            <title>Users with Administrative Privileges</title>
            <description>Using a privileged account to perform routine functions makes the computer
                vulnerable to attack by any virus or Trojan Horse inadvertently introduced during a
                session that has been granted full privileges. The rule of least privilege should
                always be enforced.</description>
            <actions priority="LOW" operation="AND">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:21</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:22</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:23</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:24</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:25</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:3" priority="LOW">
            <title>Backup Administrator Account</title>
            <description>Backup Operators are able to read and write to any file in the system,
                regardless of the rights assigned to it. Backup and restore rights permit users to
                cirvumvent the file access restrictions present on NTFS disk drives for the purpose
                of backup and restore. Members of the Backup Operators group should have special
                logon accounts for performing their backup duties.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:31</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:32</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:33</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:4" priority="LOW">
            <title>Administrator Account Password Changes</title>
            <description>Default and backup administrator passwords are not changed as
                required.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:41</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:5" priority="LOW">
            <title>Users with Backup Operator Privileges</title>
            <description>Backup Operators are able to read and write to any file in the system,
                regardless of the rights assigned to it. Backup and restore rights permit users to
                cirvumvent the file access restrictions present on NTFS disk drives for the purpose
                of backup and restore. Members of the Backup Operators group should have special
                logon accounts for performing their backup duties.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:51</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:52</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:53</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:54</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:6" priority="LOW">
            <title>Shared Accounts</title>
            <description>This check verifies that all shared accounts on the system are documented
                and justified. Any shared account must be documented with the IAO as shared accounts
                do not provide individual accountability for system access and resource usage.
                Documentation should include the reason for the account, who has access to this
                account, and how the risk of using a shared account, which provides no individual
                identification and accountability is mitigated.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:61</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:7" priority="LOW">
            <title>Access to Windows Event Logs</title>
            <description>The Security Event Log contains information on security exceptions that
                occur on the system. This data is critical for identifying security vulnerabilities
                and intrusions. The Application and System logs can also contain information that is
                critical in assessing security events. Therefore, these logs must be protected from
                unauthorized access and modification. Only individuals who have auditing
                responsibilities (IAO, IAM, auditors, etc.) should be members of this group. The
                individual System Administrators responsible for maintaining this system can also be
                members of this group. Note: The administrator, who is responsible for an individual
                system, should be added to the local auditors group, since he needs the audit user
                right to perform his tasks.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:71</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:8" priority="LOW">
            <title>Reviewing Audit Logs</title>
            <description>To be of value, audit logs will be reviewed on a regular basis to identify
                security breaches and potential weaknesses in the security structure.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:81</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:9" priority="LOW">
            <title>Archiving Audit Logs</title>
            <description>To be of value, audit logs will be archived on a regular basis to ensure
                data is not being lost. (and also save space)</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:91</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:10" priority="LOW">
            <title>System Recovery Backups</title>
            <description>Recovery of a damaged or compromised system will be difficult without an
                up-to-date Emergency Repair Disk (ERD). An ERD also allows recovery of a damaged or
                corrupted system that cannot be rebooted. The ERD, when used in the recovery
                process, can restore the local systems user database to the version that existed
                when the ERD was previously made. In particular, if the ERD contained an
                administrator account without a password, then that exposed account may be attacked.
                As a valuable system resource, the ERD should be protected and stored in a
                physically secure location.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:101</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:102</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:103</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:11" priority="LOW">
            <title>Security Configuration Tools</title>
            <description>The Microsoft Security Configuration Toolset that is integrated in Windows
                2000 should be used to configure platforms for security compliance. The SCM allows
                system administrators to consolidate all security related system settings into a
                single configuration file. These settings can then be applied consistently to any
                number of Windows Machines. The SCM can use the same configuration file to check
                platforms for compliance with security policy. If an alternate method is used to
                configure a system (e.g. manually), that achieves the same configured result, then
                this is acceptable. Note: The DISA FSO Gold Disk for Windows 2000 can be used to
                configure a system to meet security requirements.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:111</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:12" priority="LOW">
            <title>System Configuration Changes (Servers)</title>
            <description>System files should be checked for unauthorized changes.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:121</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:13" priority="LOW">
            <title>Unencrypted Remote Access</title>
            <description>Encryption of Userid and Password information is required. Encryption of
                the user data inside the network firewall is also highly recommended. Encryption of
                user data coming from or going outside the network firewall is required. Encryption
                for Administrator data is always required. Refer to the Enclave Security STIG
                section on “FTP and Telnet” for detailed information on their use.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:131</test_action_ref>
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:132</test_action_ref>
            </actions>
        </questionnaire>
        <questionnaire id="ocil:mitre.org:questionnaire:14" priority="LOW">
            <title>Intrusion Detection (Servers)</title>
            <description>Each Server should have a host-based Intrusion Detection
                System.</description>
            <actions priority="LOW">
                <test_action_ref priority="LOW">ocil:mitre.org:testaction:141</test_action_ref>
            </actions>
        </questionnaire>
    </questionnaires>
    <!-- ==================================================================================================== -->
    <!-- =========================================  TEST ACTIONS  =========================================== -->
    <!-- ==================================================================================================== -->
    <test_actions>
        <boolean_question_test_action id="ocil:mitre.org:testaction:11"
            question_ref="ocil:mitre.org:question:11">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:21"
            question_ref="ocil:mitre.org:question:21">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:22"
            question_ref="ocil:mitre.org:question:22">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:23"
            question_ref="ocil:mitre.org:question:23">
            <when_true>
                <result>FAIL</result>
            </when_true>
            <when_false>
                <result>PASS</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:24"
            question_ref="ocil:mitre.org:question:24">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:25"
            question_ref="ocil:mitre.org:question:25">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:31"
            question_ref="ocil:mitre.org:question:31">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:32"
            question_ref="ocil:mitre.org:question:32">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:33"
            question_ref="ocil:mitre.org:question:33">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:41"
            question_ref="ocil:mitre.org:question:41">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:51"
            question_ref="ocil:mitre.org:question:51">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:52"
            question_ref="ocil:mitre.org:question:52">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:53"
            question_ref="ocil:mitre.org:question:53">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:54"
            question_ref="ocil:mitre.org:question:54">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:61"
            question_ref="ocil:mitre.org:question:61">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:71"
            question_ref="ocil:mitre.org:question:71">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:81"
            question_ref="ocil:mitre.org:question:81">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:91"
            question_ref="ocil:mitre.org:question:91">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:101"
            question_ref="ocil:mitre.org:question:101">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:102"
            question_ref="ocil:mitre.org:question:102">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:103"
            question_ref="ocil:mitre.org:question:103">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:111"
            question_ref="ocil:mitre.org:question:111">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:121"
            question_ref="ocil:mitre.org:question:121">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:131"
            question_ref="ocil:mitre.org:question:131">
            <when_true>
                <result>FAIL</result>
            </when_true>
            <when_false>
                <result>PASS</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:132"
            question_ref="ocil:mitre.org:question:132">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
        <boolean_question_test_action id="ocil:mitre.org:testaction:141"
            question_ref="ocil:mitre.org:question:141">
            <when_true>
                <result>PASS</result>
            </when_true>
            <when_false>
                <result>FAIL</result>
            </when_false>
        </boolean_question_test_action>
    </test_actions>
    <!-- ==================================================================================================== -->
    <!-- ==================================================================================================== -->
    <!-- ==================================================================================================== -->
    <!-- ==================================================================================================== -->
    <!-- ===========================================  QUESTIONS  ============================================ -->
    <!-- ==================================================================================================== -->
    <questions>
        <boolean_question id="ocil:mitre.org:question:11" model="MODEL_YES_NO">
            <question_text>Has equipment been relocated to a controlled access area?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:21" model="MODEL_YES_NO">
            <question_text>Does each System Administrator have a unique userid dedicated for
                administering the system?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:22" model="MODEL_YES_NO">
            <question_text>Does each System Administrator have a separate account for normal user
                tasks?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:23" model="MODEL_YES_NO">
            <question_text>Is the built-in Administrator account used to administer the
                system?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:24" model="MODEL_YES_NO">
            <question_text>Have System Administrators been properly trained?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:25" model="MODEL_YES_NO">
            <question_text>Does the IAO maintain a list of users belonging to the Administrators
                group?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:31" model="MODEL_YES_NO">
            <question_text>Does each Backup Administrator have a unique userid dedicated for backup
                duites?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:32" model="MODEL_YES_NO">
            <question_text>Does each Backup Administrator have a separate account for normal user
                tasks?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:33" model="MODEL_YES_NO">
            <question_text>Has the IAO stored details about the backup administrator account in a
                secure location?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:41" model="MODEL_YES_NO">
            <question_text>Is a policy in place for changing the default and backup administrator
                account passwords at least on an annual basis, and when any member of the
                administrative team leaves the organization?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:51" model="MODEL_YES_NO">
            <question_text>Does each Backup Operator have a unique userid dedicated for backing up
                the system?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:52" model="MODEL_YES_NO">
            <question_text>Does each Backup Operator have a separate account for normal user
                tasks?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:53" model="MODEL_YES_NO">
            <question_text>Have Backup Operators been properly trained?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:54" model="MODEL_YES_NO">
            <question_text>Does the IAO maintain a list of users belonging to the Backup Operators
                group?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:61" model="MODEL_YES_NO">
            <question_text>Has the IAO documented and justified all shared accounts on the
                system?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:71" model="MODEL_YES_NO">
            <question_text>Has the site has created an Auditors group to restrict access to the
                Event Logs?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:81" model="MODEL_YES_NO">
            <question_text>Does the site have a policy in place that defines procedures for
                reviewing audit logs?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:91" model="MODEL_YES_NO">
            <question_text>Does the site have a policy in place that defines procedures for
                archiving audit logs?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:101" model="MODEL_YES_NO">
            <question_text>Does the site maintain emergency system recovery data?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:102" model="MODEL_YES_NO">
            <question_text>Is the emergency system recovery data protected from destruction and
                stored in locked storage container?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:103" model="MODEL_YES_NO">
            <question_text>Has the emergency system recovery data been updated following the last
                system modification?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:111" model="MODEL_YES_NO">
            <question_text>Is the Security Configuration Toolset (or an acceptable alternative) used
                to configure the Windows systems to meet security requirements?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:121" model="MODEL_YES_NO">
            <question_text>Does the site use a tool to compare system files (*.exe, *.bat, *.com,
                *.cmd and *.dll) on servers against a baseline on a weekly basis?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:131" model="MODEL_YES_NO">
            <question_text>Does the User account used for unencrypted remote access within the
                Enclave (premise router) have administrator privileges?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:132" model="MODEL_YES_NO">
            <question_text>Is User ID and Password information used for remote access to system
                services from outside the Enclave encrypted?</question_text>
        </boolean_question>
        <boolean_question id="ocil:mitre.org:question:141" model="MODEL_YES_NO">
            <question_text>Does each Server have a host-based intrusion detection (HID) system
                installed and enabled?</question_text>
        </boolean_question>
    </questions>
</ocil>
