Australian Information Security Manual
Guidelines for system hardening

Australian Information Security Manual ISM-1847: Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are change

Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past 12 months.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Guidelines for system hardening

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.