################################################################################
DOCUMENT         : MS_Exchange_2019_Edge_Server_STIG
VERSION          : 002.002.001.001
CHECKSUM         : 7b30500fd55a7141ab7906329d7ba2097dae54512236b8cc133ffb1c9dc3f6de
MANUAL QUESTIONS : 13

IMPORTANT: Make sure to save the completed version of this file to: 
<SCC Install>/Resources/Content/Manual_Questions/Completed_Files

This file contains all of the non-automated STIG requirements found in the STIG.
Results from this file will be combined with automated checks in SCC to provide
complete STIG compliance results.

This file will be programmaticaly imported, so do not modify anything in this file
except for placing an '[X]' to select a Single answer, and entering text comments.

The list of questions is printed in order of severity, listing CAT I (High), then CAT II, etc..

################################################################################

QUESTION         : 1 of 13
TITLE            : CAT I, V-259640, SV-259640r961632, SRG-APP-000439
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:12701
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:12701
RULE             : Exchange must provide redundancy.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

From a Mailbox server in the subscribed Edge Subscription site, determine if the Exchange servers are using redundancy by entering the following command:

Get-EdgeSubscription

If the value returned is not at least two Edge servers, this is a finding.

References:
CCI-002418
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 1 *******************************

QUESTION         : 2 of 13
TITLE            : CAT II, V-259584, SV-259584r960918, SRG-APP-000111
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:1501
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:1501
RULE             : Exchange queue monitoring must be configured with threshold and action.
QUESTION_TEXT    : Note: By default, there are two user-defined data collector sets created by Exchange: ExchangeDiagnosticsDailyPerformanceLog and ExchangeDiagnosticsPerformanceLog. These are not providing enough data to monitor SMTP queues per the requirement. Additionally, if a third-party application is performing monitoring functions, the reviewer should verify the application is monitoring correctly and mark the vulnerability Not Applicable.

Open the Exchange Management Shell and enter the following command:

perfmon

In the left pane, navigate to Performance >> Data Collector Sets >> User Defined.

If no sets are defined or queues are not being monitored, this is a finding.

References:
CCI-000154
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 2 *******************************

QUESTION         : 3 of 13
TITLE            : CAT II, V-259585, SV-259585r960930, SRG-APP-000118
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:1701
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:1701
RULE             : Exchange audit data must be protected against unauthorized access (read access).
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine the authorized groups or users that should have read access to the audit data.

If any group or user has read access to the audit data that is not documented in the EDSP, this is a finding.

References:
CCI-000162
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 3 *******************************

QUESTION         : 4 of 13
TITLE            : CAT II, V-259586, SV-259586r960933, SRG-APP-000119
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:1901
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:1901
RULE             : Exchange audit data must be protected against unauthorized access for modification.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine the authorized groups or users that should have modify permissions to the audit data.

If any group or user has modify permissions for the audit data that is not documented in the EDSP, this is a finding.

References:
CCI-000163
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 4 *******************************

QUESTION         : 5 of 13
TITLE            : CAT II, V-259587, SV-259587r960936, SRG-APP-000120
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:2101
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:2101
RULE             : Exchange audit data must be protected against unauthorized access for deletion.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP). 

Determine the authorized groups or users that should have delete permissions for the audit data.

If any group or user has delete permissions for the audit data that is not documented in the EDSP, this is a finding.

References:
CCI-000164
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 5 *******************************

QUESTION         : 6 of 13
TITLE            : CAT II, V-259588, SV-259588r960948, SRG-APP-000125
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:2301
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:2301
RULE             : Exchange audit data must be on separate partitions.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine the audit logs' assigned partition.

Note: By default, the logs are located on the application partition in \Program Files\Microsoft\Exchange Server\V15\Logging\.

If the log files are not on a separate partition from the application, this is a finding.

References:
CCI-001348
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 6 *******************************

QUESTION         : 7 of 13
TITLE            : CAT II, V-259596, SV-259596r961152, SRG-APP-000246
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:3901
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:3901
RULE             : More than one Edge server must be deployed.
QUESTION_TEXT    : Review the EDSP for current configuration.

On the mailbox server, open a PowerShell prompt and run the following command:

Get-EdgeSubscription

If there is only one subscription on each server, this is a finding.

References:
CCI-001094
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 7 *******************************

QUESTION         : 8 of 13
TITLE            : CAT II, V-259608, SV-259608r961161, SRG-APP-000261
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:6301
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:6301
RULE             : Active hyperlinks in messages from non .mil domains must be rendered unclickable.
QUESTION_TEXT    : Note: If using another DOD-approved anti-spam product for email or a DOD-approved Email Gateway spamming device, such as Enterprise Email Security Gateway (EEMSG), this is not applicable.

Note: If system is on SIPRNet, this is not applicable.

Review the Email Domain Security Plan (EDSP).

Determine the name of the Transport Agent. 

Open the Windows PowerShell console and enter the following command:

Get-TransportAgent -Name 'customAgent' | Format-List

If the value does not return "customAgent", this is a finding.

Note: "customAgent" is the name of the custom agent developed to render hyperlink email sources from non .mil domains as unclickable.

References:
CCI-001308
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 8 *******************************

QUESTION         : 9 of 13
TITLE            : CAT II, V-259628, SV-259628r961161, SRG-APP-000261
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:10301
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:10301
RULE             : Exchange must have anti-spam filtering configured.
QUESTION_TEXT    : The site should use an approved DOD scanner as Exchange Malware software has a limited scanning capability.

If an approved DOD scanner is not being used, this is a finding.

References:
CCI-001308
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 9 *******************************

QUESTION         : 10 of 13
TITLE            : CAT II, V-259631, SV-259631r961353, SRG-APP-000340
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:10901
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:10901
RULE             : Role-Based Access Control must be defined for privileged and nonprivileged users.
QUESTION_TEXT    : Check the EDSP to verify who should be in each built in RBAC management role group.

If this is not found, this is a finding.

References:
CCI-002235
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 10 *******************************

QUESTION         : 11 of 13
TITLE            : CAT II, V-259632, SV-259632r1015763, SRG-APP-000378
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:11101
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:11101
RULE             : The Exchange application directory must be protected from unauthorized access.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine the authorized groups and users that have access to the Exchange application directories.

Determine if the access permissions on the directory match the access permissions listed in the EDSP.

If any group or user has different access permissions than listed in the EDSP, this is a finding.

Note: The default installation directory is \Program Files\Microsoft\Exchange Server\V15.

References:
CCI-003980
CCI-001812
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 11 *******************************

QUESTION         : 12 of 13
TITLE            : CAT II, V-259633, SV-259633r961461, SRG-APP-000380
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:11301
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:11301
RULE             : The Exchange software baseline copy must exist.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine the baseline documentation.

Review the application software baseline procedures and implementation artifacts.

Note the list of files and directories included in the baseline procedure for completeness.

If an email software copy exists to serve as a baseline and is available for comparison during scanning efforts, this is not a finding.

References:
CCI-001813
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 12 *******************************

QUESTION         : 13 of 13
TITLE            : CAT II, V-259643, SV-259643r961638, SRG-APP-000441
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:13301
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:13301
RULE             : Exchange must render hyperlinks from email sources from non-.mil domains as unclickable.
QUESTION_TEXT    : Note: If using another DOD-approved anti-spam product for email or a DOD-approved Email Gateway spamming device, such as Enterprise Email Security Gateway (EEMSG), this is not applicable.

Note: If system is on SIPRNet, this is not applicable.

Review the Email Domain Security Plan (EDSP).

Determine the name of the Transport Agent.

Open the Windows PowerShell console and enter the following command:

Get-TransportAgent -Name 'customAgent' | Format-List

If the value does not return "customAgent", this is a finding.

Note: "customAgent" is the name of the custom agent developed to render hyperlink email sources from non .mil domains as unclickable.

References:
CCI-002420
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 13 *******************************

