Microsoft Windows 11 STIG SCAP Benchmark
Open a previous version of this SCAP benchmark.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-00-000005
- Vuln IDs
- V-253254
- Rule IDs
- SV-253254r991589_rule
Fix: F-56657r828845_fix
Use Windows 11 Enterprise 64-bit version for domain-joined systems.
- RMF Control
- SC-28
- Severity
- H
- CCI
- CCI-002475
- Version
- WN11-00-000030
- Vuln IDs
- V-253259
- Rule IDs
- SV-253259r958870_rule
Fix: F-56662r828860_fix
Enable full disk encryption on all information systems (including SIPRNet) using BitLocker. BitLocker, included in Windows, can be enabled in the Control Panel under "BitLocker Drive Encryption" as well as other management tools. Note: An alternate encryption application may be used in lieu of BitLocker providing it is configured for full disk encryption and satisfies the pre-boot authentication requirements (WN11-00-000031 and WN11-00-000032).
- RMF Control
- SC-28
- Severity
- H
- CCI
- CCI-002476
- Version
- WN11-00-000031
- Vuln IDs
- V-253260
- Rule IDs
- SV-253260r958872_rule
Fix: F-56663r828863_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> BitLocker Drive Encryption >> Operating System Drives "Require additional authentication at startup" to "Enabled" with "Configure TPM Startup PIN:" set to "Require startup PIN with TPM" or with "Configure TPM startup key and PIN:" set to "Require startup key and PIN with TPM".
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- WN11-00-000032
- Vuln IDs
- V-253261
- Rule IDs
- SV-253261r958504_rule
Fix: F-56664r828866_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> BitLocker Drive Encryption >> Operating System Drives "Configure minimum PIN length for startup" to "Enabled" with "Minimum characters:" set to "6" or greater.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN11-00-000040
- Vuln IDs
- V-253263
- Rule IDs
- SV-253263r1016364_rule
Fix: F-56666r1016363_fix
Update systems on the Semi-Annual Channel to "Microsoft Windows 11 Version 22H2 (OS Build 22621.380)" or greater.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- WN11-00-000050
- Vuln IDs
- V-253265
- Rule IDs
- SV-253265r1137691_rule
Fix: F-56668r828878_fix
Format all local volumes to use NTFS.
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-000381
- Version
- WN11-00-000100
- Vuln IDs
- V-253275
- Rule IDs
- SV-253275r958478_rule
Fix: F-56678r828908_fix
Uninstall "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-00-000110
- Vuln IDs
- V-253277
- Rule IDs
- SV-253277r958478_rule
Fix: F-56680r828914_fix
Uninstall "Simple TCPIP Services (i.e. echo, daytime etc.)" from the system. Run "Programs and Features". Select "Turn Windows Features on or off". De-select "Simple TCPIP Services (i.e. echo, daytime etc.)".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WN11-00-000115
- Vuln IDs
- V-253278
- Rule IDs
- SV-253278r958480_rule
Fix: F-56681r828917_fix
Uninstall "Telnet Client" from the system. Run "Programs and Features". Select "Turn Windows Features on or off". De-select "Telnet Client".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WN11-00-000120
- Vuln IDs
- V-253279
- Rule IDs
- SV-253279r958480_rule
Fix: F-56682r828920_fix
Uninstall "TFTP Client" from the system. Run "Programs and Features". Select "Turn Windows Features on or off". De-select "TFTP Client".
- RMF Control
- SI-16
- Severity
- H
- CCI
- CCI-002824
- Version
- WN11-00-000150
- Vuln IDs
- V-253284
- Rule IDs
- SV-253284r958928_rule
Fix: F-56687r828935_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Enable Structured Exception Handling Overwrite Protection (SEHOP)" to "Enabled". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-00-000155
- Vuln IDs
- V-253285
- Rule IDs
- SV-253285r958478_rule
Fix: F-56688r828938_fix
Disable "Windows PowerShell 2.0" on the system. Run "Windows PowerShell" with elevated privileges (run as administrator). Enter the following: Disable-WindowsOptionalFeature -Online -FeatureName MicrosoftWindowsPowerShellV2Root This command must disable both "MicrosoftWindowsPowerShellV2Root" and "MicrosoftWindowsPowerShellV2" which correspond to "Windows PowerShell 2.0" and "Windows PowerShell 2.0 Engine" respectively in "Turn Windows features on or off". Alternately: Search for "Features". Select "Turn Windows features on or off". De-select "Windows PowerShell 2.0".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-00-000160
- Vuln IDs
- V-253286
- Rule IDs
- SV-253286r958478_rule
Fix: F-56689r828941_fix
Disable the SMBv1 protocol. Run "Windows PowerShell" with elevated privileges (run as administrator). Enter the following: Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol Alternately: Search for "Features". Select "Turn Windows features on or off". De-select "SMB 1.0/CIFS File Sharing Support".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-00-000165
- Vuln IDs
- V-253287
- Rule IDs
- SV-253287r958478_rule
Fix: F-56690r828944_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Configure SMBv1 Server" to "Disabled". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories, respectively. The system must be restarted for the change to take effect.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-00-000170
- Vuln IDs
- V-253288
- Rule IDs
- SV-253288r958478_rule
Fix: F-56691r828947_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Configure SMBv1 client driver" to "Enabled" with "Disable driver (recommended)" selected for "Configure MrxSmb10 driver". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories, respectively. The system must be restarted for the changes to take effect.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-00-000175
- Vuln IDs
- V-253289
- Rule IDs
- SV-253289r958478_rule
Fix: F-56692r828950_fix
Configure the "Secondary Logon" service "Startup Type" to "Disabled".
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-002238
- Version
- WN11-AC-000005
- Vuln IDs
- V-253297
- Rule IDs
- SV-253297r958736_rule
Fix: F-56700r828974_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy >> "Account lockout duration" to "15" minutes or greater. A value of "0" is also acceptable, requiring an administrator to unlock the account.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- WN11-AC-000010
- Vuln IDs
- V-253298
- Rule IDs
- SV-253298r958388_rule
Fix: F-56701r828977_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy >> "Account lockout threshold" to "3" or less invalid logon attempts (excluding "0" which is unacceptable).
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- WN11-AC-000015
- Vuln IDs
- V-253299
- Rule IDs
- SV-253299r958388_rule
Fix: F-56702r828980_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy >> "Reset account lockout counter after" to "15" minutes.
- RMF Control
- Severity
- M
- CCI
- CCI-004061
- Version
- WN11-AC-000020
- Vuln IDs
- V-253300
- Rule IDs
- SV-253300r1000103_rule
Fix: F-56703r828983_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Enforce password history" to "24" passwords remembered.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- WN11-AC-000025
- Vuln IDs
- V-253301
- Rule IDs
- SV-253301r1051042_rule
Fix: F-56704r828986_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Maximum Password Age" to "60" days or less (excluding "0" which is unacceptable).
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- WN11-AC-000030
- Vuln IDs
- V-253302
- Rule IDs
- SV-253302r1051043_rule
Fix: F-56705r828989_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Minimum Password Age" to at least "1" day.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- WN11-AC-000035
- Vuln IDs
- V-253303
- Rule IDs
- SV-253303r1051044_rule
Fix: F-56706r857205_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Minimum password length" to "14" characters.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- WN11-AC-000040
- Vuln IDs
- V-253304
- Rule IDs
- SV-253304r1051045_rule
Fix: F-56707r828995_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Password must meet complexity requirements" to "Enabled".
- RMF Control
- Severity
- H
- CCI
- CCI-004062
- Version
- WN11-AC-000045
- Vuln IDs
- V-253305
- Rule IDs
- SV-253305r1051046_rule
Fix: F-56708r828998_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Store passwords using reversible encryption" to "Disabled".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000005
- Vuln IDs
- V-253306
- Rule IDs
- SV-253306r991570_rule
Fix: F-56709r829001_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Logon >> "Audit Credential Validation" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000010
- Vuln IDs
- V-253307
- Rule IDs
- SV-253307r991570_rule
Fix: F-56710r829004_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Logon >> "Audit Credential Validation" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-001914
- Version
- WN11-AU-000030
- Vuln IDs
- V-253308
- Rule IDs
- SV-253308r971541_rule
Fix: F-56711r829007_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> "Audit Security Group Management" with "Success" selected.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001314
- Version
- WN11-AU-000035
- Vuln IDs
- V-253309
- Rule IDs
- SV-253309r958566_rule
Fix: F-56712r829010_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> "Audit User Account Management" with "Failure" selected.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001403
- Version
- WN11-AU-000040
- Vuln IDs
- V-253310
- Rule IDs
- SV-253310r991551_rule
Fix: F-56713r829013_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> "Audit User Account Management" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000050
- Vuln IDs
- V-253312
- Rule IDs
- SV-253312r1051048_rule
Fix: F-56715r829019_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Detailed Tracking >> "Audit Process Creation" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000054
- Vuln IDs
- V-253313
- Rule IDs
- SV-253313r991578_rule
Fix: F-56716r829022_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Account Lockout" with "Failure" selected.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WN11-AU-000065
- Vuln IDs
- V-253315
- Rule IDs
- SV-253315r958406_rule
Fix: F-56718r829028_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Logoff" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000070
- Vuln IDs
- V-253316
- Rule IDs
- SV-253316r991581_rule
Fix: F-56719r829031_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Logon" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000075
- Vuln IDs
- V-253317
- Rule IDs
- SV-253317r991581_rule
Fix: F-56720r829034_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Logon" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000080
- Vuln IDs
- V-253318
- Rule IDs
- SV-253318r991578_rule
Fix: F-56721r829037_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Special Logon" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000081
- Vuln IDs
- V-253319
- Rule IDs
- SV-253319r991572_rule
Fix: F-56722r829040_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit File Share" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000082
- Vuln IDs
- V-253320
- Rule IDs
- SV-253320r991572_rule
Fix: F-56723r829043_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit File Share" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000083
- Vuln IDs
- V-253321
- Rule IDs
- SV-253321r991572_rule
Fix: F-56724r829046_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Other Object Access Events" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000084
- Vuln IDs
- V-253322
- Rule IDs
- SV-253322r991572_rule
Fix: F-56725r829049_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Other Object Access Events" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000100
- Vuln IDs
- V-253325
- Rule IDs
- SV-253325r991572_rule
Fix: F-56728r829058_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> "Audit Policy Change" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000105
- Vuln IDs
- V-253326
- Rule IDs
- SV-253326r991572_rule
Fix: F-56729r829061_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> "Audit Authentication Policy Change" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000107
- Vuln IDs
- V-253327
- Rule IDs
- SV-253327r991572_rule
Fix: F-56730r829064_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> "Audit Authorization Policy Change" with "Success" selected.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002234
- Version
- WN11-AU-000110
- Vuln IDs
- V-253328
- Rule IDs
- SV-253328r958732_rule
Fix: F-56731r829067_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Privilege Use >> "Audit Sensitive Privilege Use" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000115
- Vuln IDs
- V-253329
- Rule IDs
- SV-253329r991575_rule
Fix: F-56732r829070_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Privilege Use >> "Audit Sensitive Privilege Use" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000120
- Vuln IDs
- V-253330
- Rule IDs
- SV-253330r991586_rule
Fix: F-56733r829073_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit IPsec Driver" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000130
- Vuln IDs
- V-253331
- Rule IDs
- SV-253331r991579_rule
Fix: F-56734r829076_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit Other System Events" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000135
- Vuln IDs
- V-253332
- Rule IDs
- SV-253332r991579_rule
Fix: F-56735r829079_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit Other System Events" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000140
- Vuln IDs
- V-253333
- Rule IDs
- SV-253333r991575_rule
Fix: F-56736r829082_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit Security State Change" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000150
- Vuln IDs
- V-253334
- Rule IDs
- SV-253334r991575_rule
Fix: F-56737r829085_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit Security System Extension" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000155
- Vuln IDs
- V-253335
- Rule IDs
- SV-253335r991573_rule
Fix: F-56738r829088_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit System Integrity" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000160
- Vuln IDs
- V-253336
- Rule IDs
- SV-253336r991573_rule
Fix: F-56739r829091_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit System Integrity" with "Success" selected.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN11-AU-000500
- Vuln IDs
- V-253337
- Rule IDs
- SV-253337r958752_rule
Fix: F-56740r829094_fix
If the system is configured to send audit records directly to an audit server, this is NA. This must be documented with the ISSO. Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> Application >> "Specify the maximum log file size (KB)" to "Enabled" with a "Maximum Log Size (KB)" of "32768" or greater.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN11-AU-000505
- Vuln IDs
- V-253338
- Rule IDs
- SV-253338r958752_rule
Fix: F-56741r829097_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> Security >> "Specify the maximum log file size (KB)" to "Enabled" with a "Maximum Log Size (KB)" of "1024000" or greater. If the system is configured to send audit records directly to an audit server, this must be documented with the ISSO.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN11-AU-000510
- Vuln IDs
- V-253339
- Rule IDs
- SV-253339r958752_rule
Fix: F-56742r829100_fix
If the system is configured to send audit records directly to an audit server, this is NA. This must be documented with the ISSO. Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> System >> "Specify the maximum log file size (KB)" to "Enabled" with a "Maximum Log Size (KB)" of "32768" or greater.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN11-AU-000515
- Vuln IDs
- V-253340
- Rule IDs
- SV-253340r958434_rule
Fix: F-56743r829103_fix
Ensure the permissions on the Application event log (Application.evtx) are configured to prevent standard user accounts or groups from having access. The default permissions listed below satisfy this requirement. Eventlog - Full Control SYSTEM - Full Control Administrators - Full Control The default location is the "%SystemRoot%\SYSTEM32\WINEVT\LOGS" directory. If the location of the logs has been changed, when adding Eventlog to the permissions, it must be entered as "NT Service\Eventlog".
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN11-AU-000520
- Vuln IDs
- V-253341
- Rule IDs
- SV-253341r958434_rule
Fix: F-56744r829106_fix
Ensure the permissions on the Security event log (Security.evtx) are configured to prevent standard user accounts or groups from having access. The default permissions listed below satisfy this requirement. Eventlog - Full Control SYSTEM - Full Control Administrators - Full Control The default location is the "%SystemRoot%\SYSTEM32\WINEVT\LOGS" directory. If the location of the logs has been changed, when adding Eventlog to the permissions, it must be entered as "NT Service\Eventlog".
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN11-AU-000525
- Vuln IDs
- V-253342
- Rule IDs
- SV-253342r958434_rule
Fix: F-56745r829109_fix
Ensure the permissions on the System event log (System.evtx) are configured to prevent standard user accounts or groups from having access. The default permissions listed below satisfy this requirement. Eventlog - Full Control SYSTEM - Full Control Administrators - Full Control The default location is the "%SystemRoot%\SYSTEM32\WINEVT\LOGS" directory. If the location of the logs has been changed, when adding Eventlog to the permissions, it must be entered as "NT Service\Eventlog".
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- WN11-AU-000550
- Vuln IDs
- V-253343
- Rule IDs
- SV-253343r958412_rule
Fix: F-56746r829112_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change>> "Audit Other Policy Change Events" with "Success" selected.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- WN11-AU-000555
- Vuln IDs
- V-253344
- Rule IDs
- SV-253344r958412_rule
Fix: F-56747r829115_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change>> "Audit Other Policy Change Events" with "Failure" selected.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- WN11-AU-000560
- Vuln IDs
- V-253345
- Rule IDs
- SV-253345r958412_rule
Fix: F-56748r829118_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Other Logon/Logoff Events" with "Success" selected.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- WN11-AU-000565
- Vuln IDs
- V-253346
- Rule IDs
- SV-253346r958412_rule
Fix: F-56749r829121_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Other Logon/Logoff Events" with "Failure" selected.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- WN11-AU-000570
- Vuln IDs
- V-253347
- Rule IDs
- SV-253347r958412_rule
Fix: F-56750r829124_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> Audit Detailed File Share" with "Failure" selected.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- WN11-AU-000575
- Vuln IDs
- V-253348
- Rule IDs
- SV-253348r958412_rule
Fix: F-56751r829127_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> Audit MPSSVC Rule-Level Policy Change" with "Success" selected.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- WN11-AU-000580
- Vuln IDs
- V-253349
- Rule IDs
- SV-253349r958412_rule
Fix: F-56752r829130_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> Audit MPSSVC Rule-Level Policy Change" with "Failure" selected.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000010
- Vuln IDs
- V-253352
- Rule IDs
- SV-253352r958478_rule
Fix: F-56755r829139_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Control Panel >> Personalization >> "Prevent enabling lock screen slide show" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000020
- Vuln IDs
- V-253353
- Rule IDs
- SV-253353r991589_rule
Fix: F-56756r829142_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> "MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)" to "Highest protection, source routing is completely disabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000025
- Vuln IDs
- V-253354
- Rule IDs
- SV-253354r991589_rule
Fix: F-56757r829145_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> "MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)" to "Highest protection, source routing is completely disabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN11-CC-000030
- Vuln IDs
- V-253355
- Rule IDs
- SV-253355r991589_rule
Fix: F-56758r829148_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> "MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes" to "Disabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN11-CC-000035
- Vuln IDs
- V-253356
- Rule IDs
- SV-253356r958902_rule
Fix: F-56759r829151_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> "MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers" to "Enabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN11-CC-000037
- Vuln IDs
- V-253357
- Rule IDs
- SV-253357r958518_rule
Fix: F-56760r829154_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Apply UAC restrictions to local accounts on network logons" to "Enabled". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000038
- Vuln IDs
- V-253358
- Rule IDs
- SV-253358r958478_rule
Fix: F-56761r829157_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "WDigest Authentication (disabling may require KB2871997)" to "Disabled". The patch referenced in the policy title is not required for Windows 11. This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000039
- Vuln IDs
- V-253359
- Rule IDs
- SV-253359r958478_rule
Fix: F-56762r829160_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Remove "Run as Different User" from context menus" to "Enabled". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000040
- Vuln IDs
- V-253360
- Rule IDs
- SV-253360r991589_rule
Fix: F-56763r829163_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Lanman Workstation >> "Enable insecure guest logons" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000044
- Vuln IDs
- V-253361
- Rule IDs
- SV-253361r958478_rule
Fix: F-56764r829166_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Network Connections >> "Prohibit use of Internet Connection Sharing on your DNS domain network" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000050
- Vuln IDs
- V-253362
- Rule IDs
- SV-253362r991589_rule
Fix: F-56765r829169_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Network Provider >> "Hardened UNC Paths" to "Enabled" with at least the following configured in "Hardened UNC Paths:" (click the "Show" button to display). Value Name: \\*\SYSVOL Value: RequireMutualAuthentication=1, RequireIntegrity=1 Value Name: \\*\NETLOGON Value: RequireMutualAuthentication=1, RequireIntegrity=1
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN11-CC-000055
- Vuln IDs
- V-253364
- Rule IDs
- SV-253364r958358_rule
Fix: F-56767r890454_fix
The default behavior for "Minimize the number of simultaneous connections to the Internet or a Windows Domain" is "Enabled". If this needs to be corrected, configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Windows Connection Manager >> "Minimize the number of simultaneous connections to the Internet or a Windows Domain" to "Enabled". Under "Options", set "Minimize Policy Options" to "3 = Prevent Wi-Fi When on Ethernet".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000060
- Vuln IDs
- V-253365
- Rule IDs
- SV-253365r991589_rule
Fix: F-56768r829178_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Windows Connection Manager >> "Prohibit connection to non-domain networks when connected to domain authenticated network" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000065
- Vuln IDs
- V-253366
- Rule IDs
- SV-253366r991589_rule
Fix: F-56769r829181_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> WLAN Service >> WLAN Settings>> "Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services" to "Disabled".
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000135
- Version
- WN11-CC-000066
- Vuln IDs
- V-253367
- Rule IDs
- SV-253367r958422_rule
Fix: F-56770r829184_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Audit Process Creation >> "Include command line in process creation events" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000068
- Vuln IDs
- V-253368
- Rule IDs
- SV-253368r991589_rule
Fix: F-56771r829187_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Credentials Delegation >> "Remote host allows delegation of non-exportable credentials" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000085
- Vuln IDs
- V-253372
- Rule IDs
- SV-253372r991589_rule
Fix: F-56775r829199_fix
Ensure that Early Launch Antimalware - Boot-Start Driver Initialization policy is set to enforce "Good, unknown and bad but critical" (preventing "bad"). To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> System >> Early Launch Antimalware >> "Boot-Start Driver Initialization Policy" to "Enabled with "Good, unknown and bad but critical" selected.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000090
- Vuln IDs
- V-253373
- Rule IDs
- SV-253373r991589_rule
Fix: F-56776r829202_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Group Policy >> "Configure registry policy processing" to "Enabled" and select the option "Process even if the Group Policy objects have not changed".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000100
- Vuln IDs
- V-253374
- Rule IDs
- SV-253374r958478_rule
Fix: F-56777r829205_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Internet Communication Management >> Internet Communication settings >> "Turn off downloading of print drivers over HTTP" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000105
- Vuln IDs
- V-253375
- Rule IDs
- SV-253375r958478_rule
Fix: F-56778r829208_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Internet Communication Management >> Internet Communication settings >> "Turn off Internet download for Web publishing and online ordering wizards" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000110
- Vuln IDs
- V-253376
- Rule IDs
- SV-253376r958478_rule
Fix: F-56779r829211_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Internet Communication Management >> Internet Communication settings >> "Turn off printing over HTTP" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000115
- Vuln IDs
- V-253377
- Rule IDs
- SV-253377r991589_rule
Fix: F-56780r829214_fix
This requirement is applicable to domain-joined systems, for standalone systems this is NA. The default behavior for "Support device authentication using certificate" is "Automatic". To correct this, configured the policy value for Computer Configuration >> Administrative Templates >> System >> Kerberos >> "Support device authentication using certificate" to "Not Configured or "Enabled" with either option selected in "Device authentication behavior using certificate:".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000120
- Vuln IDs
- V-253378
- Rule IDs
- SV-253378r958478_rule
Fix: F-56781r829217_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Logon >> "Do not display network selection UI" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000130
- Vuln IDs
- V-253379
- Rule IDs
- SV-253379r958478_rule
Fix: F-56782r829220_fix
This requirement is applicable to domain-joined systems, for standalone systems this is NA. Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Logon >> "Enumerate local users on domain-joined computers" to "Disabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-CC-000145
- Vuln IDs
- V-253380
- Rule IDs
- SV-253380r1051049_rule
Fix: F-56783r829223_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Power Management >> Sleep Settings >> "Require a password when a computer wakes (on battery)" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-CC-000150
- Vuln IDs
- V-253381
- Rule IDs
- SV-253381r1051050_rule
Fix: F-56784r829226_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Power Management >> Sleep Settings >> "Require a password when a computer wakes (plugged in)" to "Enabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN11-CC-000155
- Vuln IDs
- V-253382
- Rule IDs
- SV-253382r1137695_rule
Fix: F-56785r829229_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Remote Assistance >> "Configure Solicited Remote Assistance" to "Disabled".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- WN11-CC-000165
- Vuln IDs
- V-253383
- Rule IDs
- SV-253383r971545_rule
Fix: F-56786r829232_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Remote Procedure Call >> "Restrict Unauthenticated RPC clients" to "Enabled" and "Authenticated".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN11-CC-000170
- Vuln IDs
- V-253384
- Rule IDs
- SV-253384r991589_rule
Fix: F-56787r829235_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> App Runtime >> "Allow Microsoft accounts to be optional" to "Enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN11-CC-000175
- Vuln IDs
- V-253385
- Rule IDs
- SV-253385r958478_rule
Fix: F-56788r829238_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Application Compatibility >> "Turn off Inventory Collector" to "Enabled".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN11-CC-000180
- Vuln IDs
- V-253386
- Rule IDs
- SV-253386r958804_rule
Fix: F-56789r829241_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> AutoPlay Policies >> "Disallow Autoplay for non-volume devices" to "Enabled".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN11-CC-000185
- Vuln IDs
- V-253387
- Rule IDs
- SV-253387r958804_rule
Fix: F-56790r829244_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> AutoPlay Policies >> "Set the default behavior for AutoRun" to "Enabled:Do not execute any autorun commands".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN11-CC-000190
- Vuln IDs
- V-253388
- Rule IDs
- SV-253388r958804_rule
Fix: F-56791r829247_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> AutoPlay Policies >> "Turn off AutoPlay" to "Enabled:All Drives".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000195
- Vuln IDs
- V-253389
- Rule IDs
- SV-253389r991589_rule
Fix: F-56792r829250_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Biometrics >> Facial Features >> "Configure enhanced anti-spoofing" to "Enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN11-CC-000197
- Vuln IDs
- V-253390
- Rule IDs
- SV-253390r958478_rule
Fix: F-56793r829253_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Cloud Content >> "Turn off Microsoft consumer experiences" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN11-CC-000200
- Vuln IDs
- V-253391
- Rule IDs
- SV-253391r958518_rule
Fix: F-56794r829256_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Credential User Interface >> "Enumerate administrator accounts on elevation" to "Disabled".
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- WN11-CC-000205
- Vuln IDs
- V-253393
- Rule IDs
- SV-253393r958564_rule
Fix: F-56796r829262_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Data Collection and Preview Builds >> "Allow Diagnostic Data" to "Enabled" with "Send required diagnostic data" selected in "Options:".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN11-CC-000206
- Vuln IDs
- V-253394
- Rule IDs
- SV-253394r991589_rule
Fix: F-56797r829265_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Delivery Optimization >> "Download Mode" to "Enabled" with any option except "Internet" selected. Acceptable selections include: Bypass (100) Group (2) HTTP only (0) LAN (1) Simple (99) .
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000210
- Vuln IDs
- V-253395
- Rule IDs
- SV-253395r958478_rule
Fix: F-56798r829268_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> "Configure Windows Defender SmartScreen" to "Enabled" with "Warn and prevent bypass" selected. Windows 11 includes duplicate policies for this setting. It can also be configured under Computer Configuration >> Administrative Templates >> Windows Components >> Windows Defender SmartScreen >> Explorer.
- RMF Control
- SI-16
- Severity
- M
- CCI
- CCI-002824
- Version
- WN11-CC-000215
- Vuln IDs
- V-253396
- Rule IDs
- SV-253396r958928_rule
Fix: F-56799r829271_fix
The default behavior is for data execution prevention to be turned on for file explorer. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> "Turn off Data Execution Prevention for Explorer" to "Not Configured" or "Disabled".
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN11-CC-000220
- Vuln IDs
- V-253397
- Rule IDs
- SV-253397r958902_rule
Fix: F-56800r829274_fix
The default behavior is for File Explorer heap termination on corruption to be enabled. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> "Turn off heap termination on corruption" to "Not Configured" or "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000225
- Vuln IDs
- V-253398
- Rule IDs
- SV-253398r991589_rule
Fix: F-56801r829277_fix
The default behavior is for shell protected mode to be turned on for file explorer. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> "Turn off shell protocol protected mode" to "Not Configured" or "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000252
- Vuln IDs
- V-253399
- Rule IDs
- SV-253399r958478_rule
Fix: F-56802r829280_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Game Recording and Broadcasting >> "Enables or disables Windows Game Recording and Broadcasting" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000255
- Vuln IDs
- V-253400
- Rule IDs
- SV-253400r991589_rule
Fix: F-56803r829283_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Hello for Business >> "Use a hardware security device" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000260
- Vuln IDs
- V-253401
- Rule IDs
- SV-253401r991589_rule
Fix: F-56804r829286_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> PIN Complexity >> "Minimum PIN length" to "6" or greater.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-CC-000270
- Vuln IDs
- V-253402
- Rule IDs
- SV-253402r1051051_rule
Fix: F-56805r829289_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Connection Client >> "Do not allow passwords to be saved" to "Enabled".
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- WN11-CC-000275
- Vuln IDs
- V-253403
- Rule IDs
- SV-253403r1137695_rule
Fix: F-56806r829292_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Device and Resource Redirection >> "Do not allow drive redirection" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-CC-000280
- Vuln IDs
- V-253404
- Rule IDs
- SV-253404r1051052_rule
Fix: F-56807r829295_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security >> "Always prompt for password upon connection" to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- WN11-CC-000285
- Vuln IDs
- V-253405
- Rule IDs
- SV-253405r991554_rule
Fix: F-56808r829298_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security "Require secure RPC communication" to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- WN11-CC-000290
- Vuln IDs
- V-253406
- Rule IDs
- SV-253406r958408_rule
Fix: F-56809r829301_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security >> "Set client connection encryption level" to "Enabled" and "High Level".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000295
- Vuln IDs
- V-253407
- Rule IDs
- SV-253407r991589_rule
Fix: F-56810r829304_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> RSS Feeds >> "Prevent downloading of enclosures" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000300
- Vuln IDs
- V-253408
- Rule IDs
- SV-253408r958478_rule
Fix: F-56811r829307_fix
The default behavior is for the Windows RSS platform to not use Basic authentication over HTTP connections. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> RSS Feeds >> "Turn on Basic feed authentication over HTTP" to "Not Configured" or "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000305
- Vuln IDs
- V-253409
- Rule IDs
- SV-253409r958478_rule
Fix: F-56812r829310_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Search >> "Allow indexing of encrypted files" to "Disabled".
- RMF Control
- Severity
- M
- CCI
- CCI-003980
- Version
- WN11-CC-000310
- Vuln IDs
- V-253410
- Rule IDs
- SV-253410r1051053_rule
Fix: F-56813r829313_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Installer >> "Allow user control over installs" to "Disabled".
- RMF Control
- Severity
- H
- CCI
- CCI-003980
- Version
- WN11-CC-000315
- Vuln IDs
- V-253411
- Rule IDs
- SV-253411r1051054_rule
Fix: F-56814r829316_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Installer >> "Always install with elevated privileges" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000320
- Vuln IDs
- V-253412
- Rule IDs
- SV-253412r991589_rule
Fix: F-56815r829319_fix
The default behavior is for Internet Explorer to warn users and select whether to allow or refuse installation when a web-based program attempts to install software on the system. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Installer >> "Prevent Internet Explorer security prompt for Windows Installer scripts" to "Not Configured" or "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000325
- Vuln IDs
- V-253413
- Rule IDs
- SV-253413r991591_rule
Fix: F-56816r829322_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Logon Options >> "Sign-in last interactive user automatically after a system-initiated restart" to "Disabled".
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000135
- Version
- WN11-CC-000326
- Vuln IDs
- V-253414
- Rule IDs
- SV-253414r958422_rule
Fix: F-56817r829325_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows PowerShell >> "Turn on PowerShell Script Block Logging" to "Enabled".
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- WN11-CC-000327
- Vuln IDs
- V-253415
- Rule IDs
- SV-253415r958420_rule
Fix: F-56818r829328_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows PowerShell >> "Turn on PowerShell Transcription" to "Enabled". Specify the Transcript output directory to point to a Central Log Server or another secure location to prevent user access.
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-000877
- Version
- WN11-CC-000330
- Vuln IDs
- V-253416
- Rule IDs
- SV-253416r958510_rule
Fix: F-56819r829331_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Client >> "Allow Basic authentication" to "Disabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002890
- Version
- WN11-CC-000335
- Vuln IDs
- V-253417
- Rule IDs
- SV-253417r958848_rule
Fix: F-56820r829334_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Client >> "Allow unencrypted traffic" to "Disabled".
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-000877
- Version
- WN11-CC-000345
- Vuln IDs
- V-253418
- Rule IDs
- SV-253418r958510_rule
Fix: F-56821r829337_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Service >> "Allow Basic authentication" to "Disabled". Severity Override Guidance: The AO can allow the severity override if they have reviewed the overall protection. This would only be allowed temporarily for implementation as documented and approved. .... Allowing Basic authentication to be used for the sole creation of Office 365 DoD tenants. .... A documented mechanism and or script that can disable Basic authentication once administration completes. .... Use of a Privileged Access Workstation (PAW) and adherence to the Clean Source principle for administration.
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-003123
- Version
- WN11-CC-000350
- Vuln IDs
- V-253419
- Rule IDs
- SV-253419r958850_rule
Fix: F-56822r829340_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Service >> "Allow unencrypted traffic" to "Disabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-CC-000355
- Vuln IDs
- V-253420
- Rule IDs
- SV-253420r1051055_rule
Fix: F-56823r829343_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Service >> "Disallow WinRM from storing RunAs credentials" to "Enabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-000877
- Version
- WN11-CC-000360
- Vuln IDs
- V-253421
- Rule IDs
- SV-253421r958510_rule
Fix: F-56824r829346_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Client >> "Disallow Digest authentication" to "Enabled".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- WN11-CC-000365
- Vuln IDs
- V-253422
- Rule IDs
- SV-253422r958400_rule
Fix: F-56825r829349_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> App Privacy >> "Let Windows apps activate with voice while the system is locked" to "Enabled" with Default for all Apps: set to Force Deny. The requirement is NA if the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> App Privacy >> "Let Windows apps activate with voice" is configured to "Enabled" with Default for all Apps: set to Force Deny.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN11-CC-000370
- Vuln IDs
- V-253423
- Rule IDs
- SV-253423r958478_rule
Fix: F-56826r840184_fix
Disable the convenience PIN sign-in. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> System >> Logon >> Set "Turn on convenience PIN sign-in" to "Disabled".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000060
- Version
- WN11-CC-000385
- Vuln IDs
- V-253424
- Rule IDs
- SV-253424r958404_rule
Fix: F-56827r829355_fix
Disable the convenience PIN sign-in. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Ink Workspace >> Set "Allow Windows Ink Workspace" to "Enabled and set Options "On, but disallow access above lock".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-EP-000310
- Vuln IDs
- V-253426
- Rule IDs
- SV-253426r991580_rule
Fix: F-56829r829361_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Kernel DMA Protection >> "Enumeration policy for external devices incompatible with Kernel DMA Protection" to "Enabled" with "Enumeration Policy" set to "Block All".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN11-PK-000005
- Vuln IDs
- V-253427
- Rule IDs
- SV-253427r958448_rule
Fix: F-56830r922038_fix
Install the DoD Root CA certificates. DoD Root CA 3 DoD Root CA 4 DoD Root CA 5 DoD Root CA 6 The InstallRoot tool is available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. PKI can be found at https://crl.gds.disa.mil/.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN11-PK-000010
- Vuln IDs
- V-253428
- Rule IDs
- SV-253428r958448_rule
Fix: F-56831r890460_fix
Install the ECA Root CA certificates on unclassified systems. ECA Root CA 4 The InstallRoot tool is available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. PKI can be found at https://crl.gds.disa.mil/.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- WN11-PK-000015
- Vuln IDs
- V-253429
- Rule IDs
- SV-253429r958448_rule
Fix: F-56832r890463_fix
Install the DoD Interoperability Root CA cross-certificates on unclassified systems. Issued To - Issued By - Thumbprint DoD Root CA 3 - DoD Interoperability Root CA 2 - 49CBE933151872E17C8EAE7F0ABA97FB610F6477 The certificates can be installed using the InstallRoot tool. The tool and user guide are available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. Certificate bundles published by the PKI can be found at https://crl.gds.disa.mil/.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- WN11-PK-000020
- Vuln IDs
- V-253430
- Rule IDs
- SV-253430r1081058_rule
Fix: F-56833r1081057_fix
Install the US DOD CCEB Interoperability Root CA cross-certificate on unclassified systems. Issued To - Issued By - Thumbprint 9B74964506C7ED9138070D08D5F8B969866560C8 NotAfter: 7/18/2025 9:56:22 AM Issued To: DOD Root CA 6 Issued By: US DOD CCEB Interoperability Root CA 2 Thumbprint: D471CA32F7A692CE6CBB6196BD3377FE4DBCD106 NotAfter: 7/18/2026 The certificates can be installed using the InstallRoot tool. The tool and user guide are available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. Certificate bundles published by the PKI can be found at https://crl.gds.disa.mil/.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- WN11-SO-000005
- Vuln IDs
- V-253432
- Rule IDs
- SV-253432r958482_rule
Fix: F-56835r829379_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Accounts: Administrator account status" to "Disabled".
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- WN11-SO-000010
- Vuln IDs
- V-253433
- Rule IDs
- SV-253433r958504_rule
Fix: F-56836r829382_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Accounts: Guest account status" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000015
- Vuln IDs
- V-253434
- Rule IDs
- SV-253434r991589_rule
Fix: F-56837r829385_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Accounts: Limit local account use of blank passwords to console logon only" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000020
- Vuln IDs
- V-253435
- Rule IDs
- SV-253435r991589_rule
Fix: F-56838r829388_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Accounts: Rename administrator account" to a name other than "Administrator".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000025
- Vuln IDs
- V-253436
- Rule IDs
- SV-253436r991589_rule
Fix: F-56839r829391_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Accounts: Rename guest account" to a name other than "Guest".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- WN11-SO-000030
- Vuln IDs
- V-253437
- Rule IDs
- SV-253437r958442_rule
Fix: F-56840r829394_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings" to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN11-SO-000035
- Vuln IDs
- V-253438
- Rule IDs
- SV-253438r958908_rule
Fix: F-56841r829397_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Digitally encrypt or sign secure channel data (always)" to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN11-SO-000040
- Vuln IDs
- V-253439
- Rule IDs
- SV-253439r958908_rule
Fix: F-56842r829400_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Digitally encrypt secure channel data (when possible)" to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN11-SO-000045
- Vuln IDs
- V-253440
- Rule IDs
- SV-253440r958908_rule
Fix: F-56843r829403_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Digitally sign secure channel data (when possible)" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN11-SO-000050
- Vuln IDs
- V-253441
- Rule IDs
- SV-253441r991589_rule
Fix: F-56844r829406_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Disable machine account password changes" to "Disabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN11-SO-000055
- Vuln IDs
- V-253442
- Rule IDs
- SV-253442r991589_rule
Fix: F-56845r829409_fix
This is the default configuration for this setting (30 days). Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Maximum machine account password age" to "30" or less (excluding 0 which is unacceptable).
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN11-SO-000060
- Vuln IDs
- V-253443
- Rule IDs
- SV-253443r958908_rule
Fix: F-56846r829412_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Require strong (Windows 2000 or Later) session key" to "Enabled".
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- WN11-SO-000070
- Vuln IDs
- V-253444
- Rule IDs
- SV-253444r958636_rule
Fix: F-56847r829415_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Interactive logon: Machine inactivity limit" to "900" seconds" or less, excluding "0" which is effectively disabled.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN11-SO-000085
- Vuln IDs
- V-253447
- Rule IDs
- SV-253447r991589_rule
Fix: F-56850r829424_fix
This is the default configuration for this setting (10 logons to cache). Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Interactive logon: Number of previous logons to cache (in case domain controller is not available)" to "10" logons or less. This setting only applies to domain-joined systems, however, it is configured by default on all systems.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000095
- Vuln IDs
- V-253448
- Rule IDs
- SV-253448r991589_rule
Fix: F-56851r829427_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Interactive logon: Smart card removal behavior" to "Lock Workstation" or "Force Logoff".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN11-SO-000100
- Vuln IDs
- V-253449
- Rule IDs
- SV-253449r958908_rule
Fix: F-56852r829430_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Microsoft network client: Digitally sign communications (always)" to "Enabled".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- WN11-SO-000110
- Vuln IDs
- V-253450
- Rule IDs
- SV-253450r987796_rule
Fix: F-56853r829433_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Microsoft network client: Send unencrypted password to third-party SMB servers" to "Disabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN11-SO-000120
- Vuln IDs
- V-253451
- Rule IDs
- SV-253451r958908_rule
Fix: F-56854r829436_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Microsoft network server: Digitally sign communications (always)" to "Enabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN11-SO-000145
- Vuln IDs
- V-253453
- Rule IDs
- SV-253453r991589_rule
Fix: F-56856r829442_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network access: Do not allow anonymous enumeration of SAM accounts" to "Enabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN11-SO-000150
- Vuln IDs
- V-253454
- Rule IDs
- SV-253454r1137695_rule
Fix: F-56857r829445_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network access: Do not allow anonymous enumeration of SAM accounts and shares" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000160
- Vuln IDs
- V-253455
- Rule IDs
- SV-253455r991589_rule
Fix: F-56858r829448_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network access: Let Everyone permissions apply to anonymous users" to "Disabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN11-SO-000165
- Vuln IDs
- V-253456
- Rule IDs
- SV-253456r1137695_rule
Fix: F-56859r829451_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network access: Restrict anonymous access to Named Pipes and Shares" to "Enabled".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-SO-000167
- Vuln IDs
- V-253457
- Rule IDs
- SV-253457r1081060_rule
Fix: F-56860r829454_fix
Navigate to the policy Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network access: Restrict clients allowed to make remote calls to SAM". Select "Edit Security" to configure the "Security descriptor:". Add "Administrators" in "Group or user names:" if it is not already listed (this is the default). Select "Administrators" in "Group or user names:". Select "Allow" for "Remote Access" in "Permissions for "Administrators". Click "OK". The "Security descriptor:" must be populated with "O:BAG:BAD:(A;;RC;;;BA) for the policy to be enforced.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000180
- Vuln IDs
- V-253458
- Rule IDs
- SV-253458r991589_rule
Fix: F-56861r829457_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Allow LocalSystem NULL session fallback" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000185
- Vuln IDs
- V-253459
- Rule IDs
- SV-253459r991589_rule
Fix: F-56862r829460_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Allow PKU2U authentication requests to this computer to use online identities" to "Disabled".
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- WN11-SO-000190
- Vuln IDs
- V-253460
- Rule IDs
- SV-253460r971535_rule
Fix: F-56863r829463_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Configure encryption types allowed for Kerberos" to "Enabled" with only the following selected: AES128_HMAC_SHA1 AES256_HMAC_SHA1 Future encryption types
- RMF Control
- Severity
- H
- CCI
- CCI-004062
- Version
- WN11-SO-000195
- Vuln IDs
- V-253461
- Rule IDs
- SV-253461r1051056_rule
Fix: F-56864r829466_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Do not store LAN Manager hash value on next password change" to "Enabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN11-SO-000205
- Vuln IDs
- V-253462
- Rule IDs
- SV-253462r991589_rule
Fix: F-56865r829469_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: LAN Manager authentication level" to "Send NTLMv2 response only. Refuse LM & NTLM".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000210
- Vuln IDs
- V-253463
- Rule IDs
- SV-253463r991589_rule
Fix: F-56866r829472_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: LDAP client signing requirements" to "Negotiate signing" at a minimum.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000215
- Vuln IDs
- V-253464
- Rule IDs
- SV-253464r991589_rule
Fix: F-56867r829475_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Minimum session security for NTLM SSP based (including secure RPC) clients" to "Require NTLMv2 session security" and "Require 128-bit encryption" (all options selected).
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-SO-000220
- Vuln IDs
- V-253465
- Rule IDs
- SV-253465r991589_rule
Fix: F-56868r829478_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Minimum session security for NTLM SSP based (including secure RPC) servers" to "Require NTLMv2 session security" and "Require 128-bit encryption" (all options selected).
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- WN11-SO-000230
- Vuln IDs
- V-253466
- Rule IDs
- SV-253466r1137699_rule
Fix: F-56869r829481_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN11-SO-000240
- Vuln IDs
- V-253467
- Rule IDs
- SV-253467r991589_rule
Fix: F-56870r829484_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "System objects: Strengthen default permissions of internal system objects (e.g. Symbolic links)" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-SO-000245
- Vuln IDs
- V-253468
- Rule IDs
- SV-253468r1051057_rule
Fix: F-56871r829487_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Admin Approval Mode for the Built-in Administrator account" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN11-SO-000250
- Vuln IDs
- V-253469
- Rule IDs
- SV-253469r958518_rule
Fix: F-56872r829490_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode" to "Prompt for consent on the secure desktop".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000765
- Version
- WN11-SO-000251
- Vuln IDs
- V-253470
- Rule IDs
- SV-253470r1106510_rule
Fix: F-56873r890469_fix
For nondomain joined systems, configuring Windows Hello for sign-on options would be suggested based on the organization's needs and capabilities.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-SO-000255
- Vuln IDs
- V-253471
- Rule IDs
- SV-253471r1051058_rule
Fix: F-56874r829496_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Behavior of the elevation prompt for standard users" to "Automatically deny elevation requests".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN11-SO-000260
- Vuln IDs
- V-253472
- Rule IDs
- SV-253472r958518_rule
Fix: F-56875r829499_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Detect application installations and prompt for elevation" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN11-SO-000265
- Vuln IDs
- V-253473
- Rule IDs
- SV-253473r958518_rule
Fix: F-56876r829502_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Only elevate UIAccess applications that are installed in secure locations" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN11-SO-000270
- Vuln IDs
- V-253474
- Rule IDs
- SV-253474r1051059_rule
Fix: F-56877r829505_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Run all administrators in Admin Approval Mode" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN11-SO-000275
- Vuln IDs
- V-253475
- Rule IDs
- SV-253475r958518_rule
Fix: F-56878r829508_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Virtualize file and registry write failures to per-user locations" to "Enabled".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000005
- Vuln IDs
- V-253479
- Rule IDs
- SV-253479r958726_rule
Fix: F-56882r829520_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Access Credential Manager as a trusted caller" to be defined but containing no entries (blank).
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN11-UR-000010
- Vuln IDs
- V-253480
- Rule IDs
- SV-253480r1137691_rule
Fix: F-56883r829523_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Access this computer from the network" to only include the following groups or accounts: Administrators Remote Desktop Users
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN11-UR-000015
- Vuln IDs
- V-253481
- Rule IDs
- SV-253481r958726_rule
Fix: F-56884r829526_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Act as part of the operating system" to be defined but containing no entries (blank).
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN11-UR-000025
- Vuln IDs
- V-253482
- Rule IDs
- SV-253482r1137691_rule
Fix: F-56885r829529_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Allow log on locally" to only include the following groups or accounts: Administrators Users
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000030
- Vuln IDs
- V-253483
- Rule IDs
- SV-253483r958726_rule
Fix: F-56886r829532_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Back up files and directories" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000035
- Vuln IDs
- V-253484
- Rule IDs
- SV-253484r958726_rule
Fix: F-56887r829535_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Change the system time" to only include the following groups or accounts: Administrators LOCAL SERVICE
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000040
- Vuln IDs
- V-253485
- Rule IDs
- SV-253485r958726_rule
Fix: F-56888r829538_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create a pagefile" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN11-UR-000045
- Vuln IDs
- V-253486
- Rule IDs
- SV-253486r958726_rule
Fix: F-56889r829541_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create a token object" to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000050
- Vuln IDs
- V-253487
- Rule IDs
- SV-253487r958726_rule
Fix: F-56890r829544_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create global objects" to only include the following groups or accounts: Administrators LOCAL SERVICE NETWORK SERVICE SERVICE
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000055
- Vuln IDs
- V-253488
- Rule IDs
- SV-253488r958726_rule
Fix: F-56891r829547_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create permanent shared objects" to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000060
- Vuln IDs
- V-253489
- Rule IDs
- SV-253489r958726_rule
Fix: F-56892r829550_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create symbolic links" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN11-UR-000065
- Vuln IDs
- V-253490
- Rule IDs
- SV-253490r958726_rule
Fix: F-56893r829553_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Debug programs" to only include the following groups or accounts: Administrators
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN11-UR-000070
- Vuln IDs
- V-253491
- Rule IDs
- SV-253491r1137691_rule
Fix: F-56894r829556_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny access to this computer from the network" to include the following: Domain Systems Only: Enterprise Admins group Domain Admins group Local account (see Note below) All Systems: Guests group Privileged Access Workstations (PAWs) dedicated to the management of Active Directory are exempt from denying the Enterprise Admins and Domain Admins groups. (See the Windows Privileged Access Workstation STIG for PAW requirements.) Note: "Local account" is a built-in security group used to assign user rights and permissions to all local accounts.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN11-UR-000075
- Vuln IDs
- V-253492
- Rule IDs
- SV-253492r1137691_rule
Fix: F-56895r829559_fix
This requirement is applicable to domain-joined systems, for standalone systems this is NA. Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny log on as a batch job" to include the following: Domain Systems Only: Enterprise Admin Group Domain Admin Group
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN11-UR-000080
- Vuln IDs
- V-253493
- Rule IDs
- SV-253493r1137691_rule
Fix: F-56896r829562_fix
This requirement is applicable to domain-joined systems, for standalone systems this is NA. Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny log on as a service" to include the following: Domain Systems Only: Enterprise Admins Group Domain Admins Group
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN11-UR-000085
- Vuln IDs
- V-253494
- Rule IDs
- SV-253494r1137691_rule
Fix: F-56897r829565_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny log on locally" to include the following: Domain Systems Only: Enterprise Admins Group Domain Admins Group Privileged Access Workstations (PAWs) dedicated to the management of Active Directory are exempt from denying the Enterprise Admins and Domain Admins groups. (See the Windows Privileged Access Workstation STIG for PAW requirements.) All Systems: Guests Group
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN11-UR-000090
- Vuln IDs
- V-253495
- Rule IDs
- SV-253495r1137691_rule
Fix: F-56898r829568_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny log on through Remote Desktop Services" to include the following: If Remote Desktop Services is not used by the organization, assign the Everyone group this right to prevent all access. Domain Systems Only: Enterprise Admins group Domain Admins group Local account (see Note below) All Systems: Guests group Privileged Access Workstations (PAWs) dedicated to the management of Active Directory are exempt from denying the Enterprise Admins and Domain Admins groups. (See the Windows Privileged Access Workstation STIG for PAW requirements.) Note: "Local account" is a built-in security group used to assign user rights and permissions to all local accounts.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000095
- Vuln IDs
- V-253496
- Rule IDs
- SV-253496r958726_rule
Fix: F-56899r829571_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Enable computer and user accounts to be trusted for delegation" to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000100
- Vuln IDs
- V-253497
- Rule IDs
- SV-253497r958726_rule
Fix: F-56900r829574_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Force shutdown from a remote system" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000110
- Vuln IDs
- V-253498
- Rule IDs
- SV-253498r1138526_rule
Fix: F-56901r1138525_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Impersonate a client after authentication" to only include the following groups or accounts: Administrators LOCAL SERVICE NETWORK SERVICE RESTRICTED SERVICES\PrintSpoolerService SERVICE
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000120
- Vuln IDs
- V-253499
- Rule IDs
- SV-253499r958726_rule
Fix: F-56902r829580_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Load and unload device drivers" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000125
- Vuln IDs
- V-253500
- Rule IDs
- SV-253500r958726_rule
Fix: F-56903r829583_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Lock pages in memory" to be defined but containing no entries (blank).
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN11-UR-000130
- Vuln IDs
- V-253501
- Rule IDs
- SV-253501r958434_rule
Fix: F-56904r829586_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Manage auditing and security log" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000140
- Vuln IDs
- V-253502
- Rule IDs
- SV-253502r958726_rule
Fix: F-56905r829589_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Modify firmware environment values" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000145
- Vuln IDs
- V-253503
- Rule IDs
- SV-253503r958726_rule
Fix: F-56906r829592_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Perform volume maintenance tasks" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000150
- Vuln IDs
- V-253504
- Rule IDs
- SV-253504r958726_rule
Fix: F-56907r829595_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Profile single process" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000160
- Vuln IDs
- V-253505
- Rule IDs
- SV-253505r958726_rule
Fix: F-56908r829598_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Restore files and directories" to only include the following groups or accounts: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN11-UR-000165
- Vuln IDs
- V-253506
- Rule IDs
- SV-253506r958726_rule
Fix: F-56909r829601_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Take ownership of files or other objects" to only include the following groups or accounts: Administrators
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN11-CC-000391
- Vuln IDs
- V-256893
- Rule IDs
- SV-256893r958552_rule
Fix: F-60511r891268_fix
For Windows 11 semi-annual channel, remove or disable the IE11 application. To disable IE11 as a standalone browser: Set the policy value for "Computer Configuration/Administrative Templates/Windows Components/Internet Explorer/Disable Internet Explorer 11 as a standalone browser" to "Enabled" with the option value set to "Never".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002234
- Version
- WN11-AU-000585
- Vuln IDs
- V-257770
- Rule IDs
- SV-257770r958412_rule
Fix: F-61435r956042_fix
Go to Computer Configuration >> Windows Settings >>Security Settings>> Advanced Audit Policy Configuration >> System Audit Policies >> Detailed Tracking >> Set "Audit Process Creation" to "Failure".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000581
- Vuln IDs
- V-278926
- Rule IDs
- SV-278926r1135296_rule
Fix: F-83365r1135295_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit File System" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000582
- Vuln IDs
- V-278927
- Rule IDs
- SV-278927r1135299_rule
Fix: F-83366r1135298_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit File System" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000583
- Vuln IDs
- V-278928
- Rule IDs
- SV-278928r1135302_rule
Fix: F-83367r1135301_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Handle Manipulation" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000584
- Vuln IDs
- V-278929
- Rule IDs
- SV-278929r1135305_rule
Fix: F-83368r1135304_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Handle Manipulation" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000589
- Vuln IDs
- V-278930
- Rule IDs
- SV-278930r1135308_rule
Fix: F-83369r1135307_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Registry" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN11-AU-000586
- Vuln IDs
- V-278931
- Rule IDs
- SV-278931r1135311_rule
Fix: F-83370r1135310_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Registry" with "Success" selected.