S 2.407 Planning the administration of directory services

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Head of IT, Administrator

The administration of a directory service requires careful planning. The planning should take adequate division of the administrative tasks and the corresponding administrator accounts into account. As a general rule, the administration of the directory service itself should be separated from the administration of the data in the directory by creating administrative roles with names such as "Service Administration" and "Data Administration", for example, with each role having different areas of responsibility.

Service administrators should take care of the preparation of the entire directory service, specification of the directory-wide settings, installation and maintenance of the software, as well as installation of the operating system on the directory service servers.

In contrast, data administrators should be responsible for the administration of the data stored in the directory service, and therefore stored on the servers of the directory service. They should not be able to configure or provide the directory service. Data administrators should not be responsible for all of the data in the directory service, if possible. Data administrators usually administer a subset of the objects in the directory service. For this purpose, it should be possible to restrict the administration capabilities of a certain administrator account to special areas of the directory service using the settings in the access control lists for the objects stored in the directory service.

Some information needed for the administration or configuration of the directory service is controlled by objects in the directory service itself. Although this information, such as information on trust relationships, schemas, or rules for replication, is stored in the directory service, it should be administered by the service administrators. For this reason, service administrators can simultaneously be data administrators, but data administrators cannot simultaneously be service administrators.

Furthermore, it is also possible to plan an extended administrative model for the directory service. The configuration of role-based administration and the possibility of delegating administrative tasks have an impact on the security of the directory service and therefore need to be given special consideration. If the security administration is designed clearly, sensibly, and consistently, then it will also be possible to increase transparency and efficiency at the same time.

Every organisation needs to answer the following questions in the framework of planning the directory service administration:

The following security-related aspects should be considered when planning the administration of the directory service:

Review questions: