*Manual intervention required* If the server is in a domain trusted by other domains, this information should be documented and the trusted domain should only have the necessary rights to the SQL Server and its database(s). ref. http://www.cisecurity.org/tools2/sqlserver/CIS_SQL2005_Benchmark_v1.0.pdf, pg 5.