ISM-1847—ISM-1847
>Control Description
Credentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft Active Directory Domain Services domain controllers in-between each change, if:
· the domain has been directly compromised
· the domain is suspected of being compromised
· they have not been changed in the past 12 months.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.