Microsoft Windows Server 2012/2012 R2 Member Server STIG SCAP Benchmark
Open a previous version of this SCAP benchmark.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-00-000160
- Vuln IDs
- V-225259
- Rule IDs
- SV-225259r569185_rule
Fix: F-26946r471120_fix
Run "Windows PowerShell" with elevated privileges (run as administrator). Enter the following: Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol Alternately: Search for "Features". Select "Turn Windows features on or off". De-select "SMB 1.0/CIFS File Sharing Support". The system must be restarted for the changes to take effect.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-00-000170
- Vuln IDs
- V-225260
- Rule IDs
- SV-225260r569185_rule
Fix: F-26947r471123_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Configure SMBv1 Server" to "Disabled". The system must be restarted for the change to take effect. This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-00-000180
- Vuln IDs
- V-225261
- Rule IDs
- SV-225261r569185_rule
Fix: F-26948r471126_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Configure SMBv1 client driver" to "Enabled" with "Disable driver (recommended)" selected for "Configure MrxSmb10 driver". Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Configure SMBv1 client (extra setting needed for pre-Win8.1/2012R2)" to "Enabled" with the following three lines of text entered for "Configure LanmanWorkstation Dependencies": Bowser MRxSmb20 NSI The system must be restarted for the changes to take effect. These policy settings requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-00-000220
- Vuln IDs
- V-225265
- Rule IDs
- SV-225265r569185_rule
Fix: F-26952r471138_fix
Windows PowerShell 2.0 is not installed by default. Uninstall it if it has been installed. Open "Windows PowerShell". Enter "Uninstall-WindowsFeature -Name PowerShell-v2". Alternately: Use the "Remove Roles and Features Wizard" and deselect "Windows PowerShell 2.0 Engine" under "Windows PowerShell".
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-002238
- Version
- WN12-AC-000001
- Vuln IDs
- V-225266
- Rule IDs
- SV-225266r852182_rule
Fix: F-26953r471141_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy >> "Account lockout duration" to "15" minutes or greater. A value of "0" is also acceptable, requiring an administrator to unlock the account.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- WN12-AC-000002
- Vuln IDs
- V-225267
- Rule IDs
- SV-225267r569185_rule
Fix: F-26954r471144_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Account Lockout Policy -> "Account lockout threshold" to "3" or less invalid logon attempts (excluding "0" which is unacceptable).
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- WN12-AC-000003
- Vuln IDs
- V-225268
- Rule IDs
- SV-225268r852183_rule
Fix: F-26955r471147_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy >> "Reset account lockout counter after" to at least "15" minutes.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000200
- Version
- WN12-AC-000004
- Vuln IDs
- V-225269
- Rule IDs
- SV-225269r569185_rule
Fix: F-26956r471150_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy >> "Enforce password history" to "24" passwords remembered.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000199
- Version
- WN12-AC-000005
- Vuln IDs
- V-225270
- Rule IDs
- SV-225270r569185_rule
Fix: F-26957r471153_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Password Policy -> "Maximum password age" to "60" days or less (excluding "0" which is unacceptable).
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000198
- Version
- WN12-AC-000006
- Vuln IDs
- V-225271
- Rule IDs
- SV-225271r569185_rule
Fix: F-26958r471156_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Password Policy -> "Minimum password age" to at least "1" day.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- WN12-AC-000007
- Vuln IDs
- V-225272
- Rule IDs
- SV-225272r569185_rule
Fix: F-26959r471159_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Password Policy -> "Minimum password length" to "14" characters.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- WN12-AC-000008
- Vuln IDs
- V-225273
- Rule IDs
- SV-225273r569185_rule
Fix: F-26960r471162_fix
Configure the policy value for Computer Configuration >> Windows Settings -> Security Settings >> Account Policies >> Password Policy >> "Password must meet complexity requirements" to "Enabled".
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000196
- Version
- WN12-AC-000009
- Vuln IDs
- V-225274
- Rule IDs
- SV-225274r569185_rule
Fix: F-26961r471165_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Password Policy -> "Store password using reversible encryption" to "Disabled".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000001
- Vuln IDs
- V-225275
- Rule IDs
- SV-225275r569185_rule
Fix: F-26962r471168_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Account Logon -> "Audit Credential Validation" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000002
- Vuln IDs
- V-225276
- Rule IDs
- SV-225276r569185_rule
Fix: F-26963r471171_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Account Logon -> "Audit Credential Validation" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000015
- Vuln IDs
- V-225277
- Rule IDs
- SV-225277r852184_rule
Fix: F-26964r471174_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Account Management -> "Audit Other Account Management Events" with "Success" selected.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- WN12-AU-000017
- Vuln IDs
- V-225278
- Rule IDs
- SV-225278r852185_rule
Fix: F-26965r471177_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Account Management -> "Audit Security Group Management" with "Success" selected.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- WN12-AU-000019
- Vuln IDs
- V-225279
- Rule IDs
- SV-225279r852186_rule
Fix: F-26966r471180_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Account Management -> "Audit User Account Management" with "Success" selected.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- WN12-AU-000020
- Vuln IDs
- V-225280
- Rule IDs
- SV-225280r852187_rule
Fix: F-26967r471183_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Account Management -> "Audit User Account Management" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000023
- Vuln IDs
- V-225281
- Rule IDs
- SV-225281r569185_rule
Fix: F-26968r471186_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Detailed Tracking -> "Audit Process Creation" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000030
- Vuln IDs
- V-225282
- Rule IDs
- SV-225282r569185_rule
Fix: F-26969r471189_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Account Lockout" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000031
- Vuln IDs
- V-225283
- Rule IDs
- SV-225283r569185_rule
Fix: F-26970r471192_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> "Audit Account Lockout" with "Failure" selected.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WN12-AU-000045
- Vuln IDs
- V-225284
- Rule IDs
- SV-225284r569185_rule
Fix: F-26971r471195_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Logon/Logoff -> "Audit Logoff" with "Success" selected.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WN12-AU-000047
- Vuln IDs
- V-225285
- Rule IDs
- SV-225285r569185_rule
Fix: F-26972r471198_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Logon/Logoff -> "Audit Logon" with "Success" selected.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WN12-AU-000048
- Vuln IDs
- V-225286
- Rule IDs
- SV-225286r569185_rule
Fix: F-26973r471201_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Logon/Logoff -> "Audit Logon" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000053
- Vuln IDs
- V-225287
- Rule IDs
- SV-225287r569185_rule
Fix: F-26974r471204_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Logon/Logoff -> "Audit Special Logon" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000085
- Vuln IDs
- V-225292
- Rule IDs
- SV-225292r569185_rule
Fix: F-26979r471219_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Policy Change -> "Audit Audit Policy Change" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000086
- Vuln IDs
- V-225293
- Rule IDs
- SV-225293r852188_rule
Fix: F-26980r471222_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Policy Change -> "Audit Audit Policy Change" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000087
- Vuln IDs
- V-225294
- Rule IDs
- SV-225294r852189_rule
Fix: F-26981r471225_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Policy Change -> "Audit Authentication Policy Change" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000089
- Vuln IDs
- V-225295
- Rule IDs
- SV-225295r569185_rule
Fix: F-26982r471228_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Policy Change -> "Audit Authorization Policy Change" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000101
- Vuln IDs
- V-225296
- Rule IDs
- SV-225296r852190_rule
Fix: F-26983r471231_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Privilege Use -> "Audit Sensitive Privilege Use" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000102
- Vuln IDs
- V-225297
- Rule IDs
- SV-225297r852191_rule
Fix: F-26984r471234_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Privilege Use -> "Audit Sensitive Privilege Use" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000103
- Vuln IDs
- V-225298
- Rule IDs
- SV-225298r569185_rule
Fix: F-26985r471237_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> System -> "Audit IPsec Driver" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000104
- Vuln IDs
- V-225299
- Rule IDs
- SV-225299r569185_rule
Fix: F-26986r471240_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> System -> "Audit IPsec Driver" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000105
- Vuln IDs
- V-225300
- Rule IDs
- SV-225300r852192_rule
Fix: F-26987r471243_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit Other System Events" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000106
- Vuln IDs
- V-225301
- Rule IDs
- SV-225301r852193_rule
Fix: F-26988r471246_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> "Audit Other System Events" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000107
- Vuln IDs
- V-225302
- Rule IDs
- SV-225302r852194_rule
Fix: F-26989r471249_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> System -> "Audit Security State Change" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000109
- Vuln IDs
- V-225303
- Rule IDs
- SV-225303r852195_rule
Fix: F-26990r471252_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> System -> "Audit Security System Extension" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000111
- Vuln IDs
- V-225304
- Rule IDs
- SV-225304r852196_rule
Fix: F-26991r471255_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> System -> "Audit System Integrity" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN12-AU-000112
- Vuln IDs
- V-225305
- Rule IDs
- SV-225305r852197_rule
Fix: F-26992r471258_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> System -> "Audit System Integrity" with "Failure" selected.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001494
- Version
- WN12-AU-000213
- Vuln IDs
- V-225313
- Rule IDs
- SV-225313r569185_rule
Fix: F-27000r471282_fix
Ensure only TrustedInstaller has permissions to change or modify Event Viewer ("%SystemRoot%\SYSTEM32\Eventvwr.exe). The default permissions below satisfy this requirement. TrustedInstaller - Full Control Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES - Read & Execute
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000001
- Vuln IDs
- V-225314
- Rule IDs
- SV-225314r569185_rule
Fix: F-27001r471285_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Link-Layer Topology Discovery -> "Turn on Mapper I/O (LLTDIO) driver" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000002
- Vuln IDs
- V-225315
- Rule IDs
- SV-225315r569185_rule
Fix: F-27002r471288_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Link-Layer Topology Discovery -> "Turn on Responder (RSPNDR) driver" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000003
- Vuln IDs
- V-225316
- Rule IDs
- SV-225316r569185_rule
Fix: F-27003r471291_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Microsoft Peer-to-Peer Networking Services -> "Turn off Microsoft Peer-to-Peer Networking Services" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000004
- Vuln IDs
- V-225317
- Rule IDs
- SV-225317r569185_rule
Fix: F-27004r471294_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Network Connections -> "Prohibit installation and configuration of Network Bridge on your DNS domain network" to "Enabled".
- RMF Control
- SC-3
- Severity
- L
- CCI
- CCI-001084
- Version
- WN12-CC-000005
- Vuln IDs
- V-225318
- Rule IDs
- SV-225318r569185_rule
Fix: F-27005r471297_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Network Connections -> "Require domain users to elevate when setting a network's location" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-CC-000006
- Vuln IDs
- V-225319
- Rule IDs
- SV-225319r569185_rule
Fix: F-27006r471300_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Network Connections -> "Route all traffic through the internal network" to "Enabled: Enabled State".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-CC-000011
- Vuln IDs
- V-225324
- Rule IDs
- SV-225324r569185_rule
Fix: F-27011r471315_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> TCPIP Settings -> Parameters -> "Set IP Stateless Autoconfiguration Limits State" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000012
- Vuln IDs
- V-225325
- Rule IDs
- SV-225325r569185_rule
Fix: F-27012r471318_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Windows Connect Now -> "Configuration of wireless settings using Windows Connect Now" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000013
- Vuln IDs
- V-225326
- Rule IDs
- SV-225326r569185_rule
Fix: F-27013r471321_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Windows Connect Now -> "Prohibit access of the Windows Connect Now wizards" to "Enabled".
- RMF Control
- CM-11
- Severity
- L
- CCI
- CCI-001812
- Version
- WN12-CC-000016
- Vuln IDs
- V-225327
- Rule IDs
- SV-225327r852200_rule
Fix: F-27014r471324_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Printers -> "Extend Point and Print connection to search Windows Update" to "Disabled".
- RMF Control
- CM-11
- Severity
- L
- CCI
- CCI-001812
- Version
- WN12-CC-000018
- Vuln IDs
- V-225328
- Rule IDs
- SV-225328r852201_rule
Fix: F-27015r471327_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> "Specify settings for optional component installation and component repair" to "Enabled" and with "Never attempt to download payload from Windows Update" selected.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000019
- Vuln IDs
- V-225329
- Rule IDs
- SV-225329r569185_rule
Fix: F-27016r471330_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Device Installation -> "Allow remote access to the Plug and Play interface" to "Disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000020
- Vuln IDs
- V-225330
- Rule IDs
- SV-225330r569185_rule
Fix: F-27017r471333_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Device Installation -> "Do not send a Windows error report when a generic driver is installed on a device" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-CC-000021
- Vuln IDs
- V-225331
- Rule IDs
- SV-225331r569185_rule
Fix: F-27018r471336_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Device Installation -> "Prevent creation of a system restore point during device activity that would normally prompt creation of a restore point" to "Disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000022
- Vuln IDs
- V-225332
- Rule IDs
- SV-225332r569185_rule
Fix: F-27019r471339_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Device Installation >> "Prevent device metadata retrieval from the Internet" to "Enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000023
- Vuln IDs
- V-225333
- Rule IDs
- SV-225333r569185_rule
Fix: F-27020r471342_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Device Installation -> "Prevent Windows from sending an error report when a device driver requests additional software during installation" to "Enabled".
- RMF Control
- CM-11
- Severity
- L
- CCI
- CCI-001812
- Version
- WN12-CC-000024
- Vuln IDs
- V-225334
- Rule IDs
- SV-225334r852202_rule
Fix: F-27021r471345_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Device Installation -> "Specify search order for device driver source locations" to "Enabled: Do not search Windows Update".
- RMF Control
- CM-11
- Severity
- L
- CCI
- CCI-001812
- Version
- WN12-CC-000025
- Vuln IDs
- V-225335
- Rule IDs
- SV-225335r852203_rule
Fix: F-27022r471348_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Device Installation -> "Specify the search server for device driver updates" to "Enabled" with "Search Managed Server" selected.
- RMF Control
- CM-11
- Severity
- L
- CCI
- CCI-001812
- Version
- WN12-CC-000026
- Vuln IDs
- V-225336
- Rule IDs
- SV-225336r852204_rule
Fix: F-27023r471351_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Driver Installation -> "Turn off Windows Update device driver search prompt" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000027
- Vuln IDs
- V-225337
- Rule IDs
- SV-225337r569185_rule
Fix: F-27024r471354_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Early Launch Antimalware -> "Boot-Start Driver Initialization Policy" to "Enabled" with "Good and Unknown" selected.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000028
- Vuln IDs
- V-225338
- Rule IDs
- SV-225338r569185_rule
Fix: F-27025r471357_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Group Policy -> "Configure registry policy processing" to "Enabled" and select the option "Process even if the Group Policy objects have not changed".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000029
- Vuln IDs
- V-225339
- Rule IDs
- SV-225339r569185_rule
Fix: F-27026r471360_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Group Policy -> "Turn off background refresh of Group Policy" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000030
- Vuln IDs
- V-225340
- Rule IDs
- SV-225340r569185_rule
Fix: F-27027r471363_fix
If the \Windows\WinStore directory exists, configure the policy value for Computer Configuration >> Administrative Templates >> System >> Internet Communication Management >> Internet Communication settings >> "Turn off access to the Store" to "Enabled". Alternately, uninstall the "Desktop Experience" feature from Windows 2012. This is located under "User Interfaces and Infrastructure" in the "Add Roles and Features Wizard". The \Windows\WinStore directory may need to be manually deleted after this.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000032
- Vuln IDs
- V-225341
- Rule IDs
- SV-225341r569185_rule
Fix: F-27028r471366_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings -> "Turn off downloading of print drivers over HTTP" to "Enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000033
- Vuln IDs
- V-225342
- Rule IDs
- SV-225342r569185_rule
Fix: F-27029r471369_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings -> "Turn off Event Viewer "Events.asp" links" to "Enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000035
- Vuln IDs
- V-225343
- Rule IDs
- SV-225343r569185_rule
Fix: F-27030r471372_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings -> "Turn off handwriting recognition error reporting" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000038
- Vuln IDs
- V-225344
- Rule IDs
- SV-225344r569185_rule
Fix: F-27031r471375_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings -> "Turn off Internet File Association service" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000039
- Vuln IDs
- V-225345
- Rule IDs
- SV-225345r569185_rule
Fix: F-27032r471378_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings -> "Turn off printing over HTTP" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000045
- Vuln IDs
- V-225346
- Rule IDs
- SV-225346r569185_rule
Fix: F-27033r471381_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication Settings -> "Turn off Windows Customer Experience Improvement Program" to "Enabled".
- RMF Control
- CM-11
- Severity
- M
- CCI
- CCI-001812
- Version
- WN12-CC-000047
- Vuln IDs
- V-225347
- Rule IDs
- SV-225347r852205_rule
Fix: F-27034r471384_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Internet Communication Management -> Internet Communication settings -> "Turn off Windows Update device driver searching" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000048
- Vuln IDs
- V-225348
- Rule IDs
- SV-225348r569185_rule
Fix: F-27035r471387_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Locale Services -> "Disallow copying of user input methods to the system account for sign-in" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000051
- Vuln IDs
- V-225349
- Rule IDs
- SV-225349r569185_rule
Fix: F-27036r471390_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Logon -> "Enumerate local users on domain-joined computers" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000052
- Vuln IDs
- V-225350
- Rule IDs
- SV-225350r569185_rule
Fix: F-27037r471393_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Logon -> "Turn off app notifications on the lock screen" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-CC-000054
- Vuln IDs
- V-225351
- Rule IDs
- SV-225351r852206_rule
Fix: F-27038r471396_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Power Management -> Sleep Settings -> "Require a password when a computer wakes (on battery)" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-CC-000055
- Vuln IDs
- V-225352
- Rule IDs
- SV-225352r852207_rule
Fix: F-27039r471399_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Power Management -> Sleep Settings -> "Require a password when a computer wakes (plugged in)" to "Enabled".
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- WN12-CC-000058
- Vuln IDs
- V-225353
- Rule IDs
- SV-225353r569185_rule
Fix: F-27040r471402_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Remote Assistance -> "Configure Offer Remote Assistance" to "Disabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN12-CC-000059
- Vuln IDs
- V-225354
- Rule IDs
- SV-225354r569185_rule
Fix: F-27041r471405_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Remote Assistance -> "Configure Solicited Remote Assistance" to "Disabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-CC-000062
- Vuln IDs
- V-225355
- Rule IDs
- SV-225355r569185_rule
Fix: F-27042r471408_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Remote Assistance -> "Turn on session logging" to "Enabled".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- WN12-CC-000064-MS
- Vuln IDs
- V-225356
- Rule IDs
- SV-225356r852208_rule
Fix: F-27043r471411_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Remote Procedure Call -> "Restrict Unauthenticated RPC clients" to "Enabled" and "Authenticated".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000065
- Vuln IDs
- V-225357
- Rule IDs
- SV-225357r569185_rule
Fix: F-27044r471414_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Troubleshooting and Diagnostics -> Application Compatibility Diagnostics -> "Detect compatibility issues for applications and drivers" to "Disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000066
- Vuln IDs
- V-225358
- Rule IDs
- SV-225358r569185_rule
Fix: F-27045r471417_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Troubleshooting and Diagnostics -> Microsoft Support Diagnostic Tool -> "Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider" to "Disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000067
- Vuln IDs
- V-225359
- Rule IDs
- SV-225359r569185_rule
Fix: F-27046r471420_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Troubleshooting and Diagnostics -> Scripted Diagnostics -> "Troubleshooting: Allow users to access online troubleshooting content on Microsoft servers from the Troubleshooting Control Panel (via the Windows Online Troubleshooting Service - WOTS)" to "Disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000068
- Vuln IDs
- V-225360
- Rule IDs
- SV-225360r569185_rule
Fix: F-27047r471423_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Troubleshooting and Diagnostics -> Windows Performance PerfTrack -> "Enable/Disable PerfTrack" to "Disabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-CC-000070
- Vuln IDs
- V-225362
- Rule IDs
- SV-225362r569185_rule
Fix: F-27049r471429_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> App Package Deployment -> "Allow all trusted apps to install" to "Enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-CC-000071
- Vuln IDs
- V-225363
- Rule IDs
- SV-225363r569185_rule
Fix: F-27050r471432_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Application Compatibility -> "Turn off Inventory Collector" to "Enabled".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN12-CC-000072
- Vuln IDs
- V-225364
- Rule IDs
- SV-225364r852210_rule
Fix: F-27051r471435_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> AutoPlay Policies -> "Disallow Autoplay for non-volume devices" to "Enabled".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN12-CC-000073
- Vuln IDs
- V-225365
- Rule IDs
- SV-225365r852211_rule
Fix: F-27052r471438_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> AutoPlay Policies -> "Set the default behavior for AutoRun" to "Enabled:Do not execute any autorun commands".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN12-CC-000074
- Vuln IDs
- V-225366
- Rule IDs
- SV-225366r852212_rule
Fix: F-27053r471441_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> AutoPlay Policies -> "Turn off AutoPlay" to "Enabled:All Drives".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000075
- Vuln IDs
- V-225367
- Rule IDs
- SV-225367r569185_rule
Fix: F-27054r471444_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Biometrics -> "Allow the use of biometrics" to "Disabled".
- RMF Control
- IA-6
- Severity
- M
- CCI
- CCI-000206
- Version
- WN12-CC-000076
- Vuln IDs
- V-225368
- Rule IDs
- SV-225368r569185_rule
Fix: F-27055r471447_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Credential User Interface -> "Do not display the password reveal button" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-CC-000077
- Vuln IDs
- V-225369
- Rule IDs
- SV-225369r569185_rule
Fix: F-27056r471450_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Credential User Interface >> "Enumerate administrator accounts on elevation" to "Disabled".
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN12-CC-000084
- Vuln IDs
- V-225370
- Rule IDs
- SV-225370r852213_rule
Fix: F-27057r471453_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> Application >> "Specify the maximum log file size (KB)" to "Enabled" with a "Maximum Log Size (KB)" of "32768" or greater.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN12-CC-000085
- Vuln IDs
- V-225371
- Rule IDs
- SV-225371r852214_rule
Fix: F-27058r471456_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> Security >> "Specify the maximum log file size (KB)" to "Enabled" with a "Maximum Log Size (KB)" of "196608" or greater.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN12-CC-000086
- Vuln IDs
- V-225372
- Rule IDs
- SV-225372r852215_rule
Fix: F-27059r471459_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> Setup >> "Specify the maximum log file size (KB)" to "Enabled" with a "Maximum Log Size (KB)" of "32768" or greater.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN12-CC-000087
- Vuln IDs
- V-225373
- Rule IDs
- SV-225373r852216_rule
Fix: F-27060r471462_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> System >> "Specify the maximum log file size (KB)" to "Enabled" with a "Maximum Log Size (KB)" of "32768" or greater.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000088
- Vuln IDs
- V-225374
- Rule IDs
- SV-225374r569185_rule
Fix: F-27061r471465_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> "Configure Windows SmartScreen" to "Enabled" with either "Give user a warning before running downloaded unknown software" or "Require approval from an administrator before running downloaded unknown software" selected. Microsoft has changed this setting several times in the Windows 10 administrative templates, which will affect group policies in a domain if later templates are used. v1607 of Windows 10 and Windows Server 2016 changed the setting to only Enabled or Disabled without additional selections. Enabled is effectively "Give user a warning…". v1703 of Windows 10 or later administrative templates changed the policy name to "Configure Windows Defender SmartScreen", and the selectable options are "Warn" and "Warn and prevent bypass". When either of these are applied to a Windows 2012/2012 R2 system, it will configure the registry equivalent of "Give user a warning…").
- RMF Control
- SI-16
- Severity
- M
- CCI
- CCI-002824
- Version
- WN12-CC-000089
- Vuln IDs
- V-225375
- Rule IDs
- SV-225375r852217_rule
Fix: F-27062r471468_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> File Explorer -> "Turn off Data Execution Prevention for Explorer" to "Disabled".
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN12-CC-000090
- Vuln IDs
- V-225376
- Rule IDs
- SV-225376r852218_rule
Fix: F-27063r471471_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> File Explorer -> "Turn off heap termination on corruption" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000091
- Vuln IDs
- V-225377
- Rule IDs
- SV-225377r569185_rule
Fix: F-27064r471474_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> File Explorer -> "Turn off shell protocol protected mode" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000095
- Vuln IDs
- V-225378
- Rule IDs
- SV-225378r569185_rule
Fix: F-27065r471477_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Location and Sensors -> "Turn off location" to "Enabled". If location services are approved by the organization for a device, this must be documented.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-CC-000096
- Vuln IDs
- V-225379
- Rule IDs
- SV-225379r852219_rule
Fix: F-27066r471480_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Connection Client -> "Do not allow passwords to be saved" to "Enabled".
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- WN12-CC-000098
- Vuln IDs
- V-225380
- Rule IDs
- SV-225380r569185_rule
Fix: F-27067r471483_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Device and Resource Redirection -> "Do not allow drive redirection" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-CC-000099
- Vuln IDs
- V-225381
- Rule IDs
- SV-225381r852220_rule
Fix: F-27068r471486_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Security -> "Always prompt for password upon connection" to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- WN12-CC-000100
- Vuln IDs
- V-225382
- Rule IDs
- SV-225382r852221_rule
Fix: F-27069r471489_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Security -> "Set client connection encryption level" to "Enabled" and "High Level".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000103
- Vuln IDs
- V-225383
- Rule IDs
- SV-225383r569185_rule
Fix: F-27070r471492_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Temporary Folders -> "Do not delete temp folder upon exit" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000104
- Vuln IDs
- V-225384
- Rule IDs
- SV-225384r569185_rule
Fix: F-27071r471495_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Temporary Folders -> "Do not use temporary folders per session" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000105
- Vuln IDs
- V-225385
- Rule IDs
- SV-225385r569185_rule
Fix: F-27072r471498_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> RSS Feeds -> "Prevent downloading of enclosures" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000106
- Vuln IDs
- V-225386
- Rule IDs
- SV-225386r569185_rule
Fix: F-27073r471501_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> RSS Feeds -> "Turn on Basic feed authentication over HTTP" to "Disabled".
- RMF Control
- CM-11
- Severity
- M
- CCI
- CCI-001812
- Version
- WN12-CC-000115
- Vuln IDs
- V-225389
- Rule IDs
- SV-225389r852222_rule
Fix: F-27076r471510_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer -> "Allow user control over installs" to "Disabled".
- RMF Control
- CM-11
- Severity
- H
- CCI
- CCI-001812
- Version
- WN12-CC-000116
- Vuln IDs
- V-225390
- Rule IDs
- SV-225390r852223_rule
Fix: F-27077r471513_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer -> "Always install with elevated privileges" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-CC-000117
- Vuln IDs
- V-225391
- Rule IDs
- SV-225391r569185_rule
Fix: F-27078r471516_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer -> "Prevent Internet Explorer security prompt for Windows Installer scripts" to "Disabled".
- RMF Control
- CM-11
- Severity
- L
- CCI
- CCI-001812
- Version
- WN12-CC-000118
- Vuln IDs
- V-225392
- Rule IDs
- SV-225392r852224_rule
Fix: F-27079r471519_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer -> "Prohibit non-administrators from applying vendor signed updates" to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-CC-000120
- Vuln IDs
- V-225393
- Rule IDs
- SV-225393r569185_rule
Fix: F-27080r471522_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Media Digital Rights Management -> "Prevent Windows Media DRM Internet Access" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-CC-000121
- Vuln IDs
- V-225394
- Rule IDs
- SV-225394r569185_rule
Fix: F-27081r471525_fix
If Windows Media Player is installed, configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Media Player -> "Do Not Show First Use Dialog Boxes" to "Enabled".
- RMF Control
- CM-11
- Severity
- M
- CCI
- CCI-001812
- Version
- WN12-CC-000122
- Vuln IDs
- V-225395
- Rule IDs
- SV-225395r852225_rule
Fix: F-27082r471528_fix
If Windows Media Player is installed, configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Media Player -> "Prevent Automatic Updates" to "Enabled".
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-000877
- Version
- WN12-CC-000123
- Vuln IDs
- V-225396
- Rule IDs
- SV-225396r569185_rule
Fix: F-27083r471531_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Remote Management (WinRM) -> WinRM Client -> "Allow Basic authentication" to "Disabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002890
- Version
- WN12-CC-000124
- Vuln IDs
- V-225397
- Rule IDs
- SV-225397r852226_rule
Fix: F-27084r471534_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Remote Management (WinRM) -> WinRM Client -> "Allow unencrypted traffic" to "Disabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-000877
- Version
- WN12-CC-000125
- Vuln IDs
- V-225398
- Rule IDs
- SV-225398r569185_rule
Fix: F-27085r471537_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Remote Management (WinRM) -> WinRM Client -> "Disallow Digest authentication" to "Enabled".
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-000877
- Version
- WN12-CC-000126
- Vuln IDs
- V-225399
- Rule IDs
- SV-225399r569185_rule
Fix: F-27086r471540_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Remote Management (WinRM) -> WinRM Service -> "Allow Basic authentication" to "Disabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002890
- Version
- WN12-CC-000127
- Vuln IDs
- V-225400
- Rule IDs
- SV-225400r852227_rule
Fix: F-27087r471543_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Remote Management (WinRM) -> WinRM Service -> "Allow unencrypted traffic" to "Disabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-CC-000128
- Vuln IDs
- V-225401
- Rule IDs
- SV-225401r852228_rule
Fix: F-27088r471546_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Remote Management (WinRM) -> WinRM Service -> "Disallow WinRM from storing RunAs credentials" to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- WN12-CC-000130
- Vuln IDs
- V-225402
- Rule IDs
- SV-225402r569185_rule
Fix: F-27089r471549_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Security -> "Require secure RPC communication" to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- WN12-CC-000132
- Vuln IDs
- V-225404
- Rule IDs
- SV-225404r852229_rule
Fix: F-27091r471555_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Device and Resource Redirection -> "Do not allow COM port redirection" to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- WN12-CC-000133
- Vuln IDs
- V-225405
- Rule IDs
- SV-225405r852230_rule
Fix: F-27092r471558_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Device and Resource Redirection -> "Do not allow LPT port redirection" to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- WN12-CC-000134
- Vuln IDs
- V-225406
- Rule IDs
- SV-225406r852231_rule
Fix: F-27093r471561_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Device and Resource Redirection -> "Do not allow smart card device redirection" to "Disabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- WN12-CC-000135
- Vuln IDs
- V-225407
- Rule IDs
- SV-225407r852232_rule
Fix: F-27094r471564_fix
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Device and Resource Redirection -> "Do not allow supported Plug and Play device redirection" to "Enabled".
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000135
- Version
- WN12-CC-000139
- Vuln IDs
- V-225410
- Rule IDs
- SV-225410r569185_rule
Fix: F-27097r471573_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Audit Process Creation >> "Include command line in process creation events" to "Enabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN12-GE-000001
- Vuln IDs
- V-225417
- Rule IDs
- SV-225417r569185_rule
Fix: F-27104r471594_fix
Update the system to a supported release or service pack level.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN12-PK-000001
- Vuln IDs
- V-225441
- Rule IDs
- SV-225441r860007_rule
Fix: F-27128r819687_fix
Install the DoD Root CA certificates: DoD Root CA 3 DoD Root CA 4 DoD Root CA 5 The InstallRoot tool is available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN12-PK-000003
- Vuln IDs
- V-225442
- Rule IDs
- SV-225442r860005_rule
Fix: F-27129r819690_fix
Install the DoD Interoperability Root CA cross-certificates on unclassified systems. Issued To - Issued By - Thumbprint DoD Root CA 3 - DoD Interoperability Root CA 2 - 49CBE933151872E17C8EAE7F0ABA97FB610F6477 DoD Root CA 3 - DoD Interoperability Root CA 2 - AC06108CA348CC03B53795C64BF84403C1DBD341 The certificates can be installed using the InstallRoot tool. The tool and user guide are available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN12-PK-000004
- Vuln IDs
- V-225443
- Rule IDs
- SV-225443r852241_rule
Fix: F-27130r852240_fix
Install the US DoD CCEB Interoperability Root CA cross-certificate on unclassified systems. Issued To - Issued By - Thumbprint DoD Root CA 3 - US DoD CCEB Interoperability Root CA 2 - AF132AC65DE86FC4FB3FE51FD637EBA0FF0B12A9 The certificates can be installed using the InstallRoot tool. The tool and user guide are available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files.
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN12-RG-000001
- Vuln IDs
- V-225444
- Rule IDs
- SV-225444r852242_rule
Fix: F-27131r471675_fix
Maintain permissions at least as restrictive as the defaults listed below for the "WinLogon" registry key. It is recommended to not change the permissions from the defaults. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ The following are the same for each permission listed: Type - Allow Inherited from - MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion Applies to - This key and subkeys Columns: Principal - Access TrustedInstaller - Full Control SYSTEM - Full Control Administrators - Full Control Users - Read ALL APPLICATION PACKAGES - Read
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN12-RG-000002
- Vuln IDs
- V-225445
- Rule IDs
- SV-225445r852243_rule
Fix: F-27132r471678_fix
Maintain the default permissions of the following registry keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\ (64-bit systems only) Users - Read Administrators - Full Control SYSTEM - Full Control CREATOR OWNER - Full Control (Subkeys only) ALL APPLICATION PACKAGES - Read
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-RG-000003-MS
- Vuln IDs
- V-225446
- Rule IDs
- SV-225446r569185_rule
Fix: F-27133r471681_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> "Apply UAC restrictions to local accounts on network logons" to "Enabled". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN12-RG-000004
- Vuln IDs
- V-225447
- Rule IDs
- SV-225447r852244_rule
Fix: F-27134r471684_fix
Maintain permissions at least as restrictive as the defaults listed below for the "winreg" registry key. It is recommended to not change the permissions from the defaults. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg\ The following are the same for each permission listed: Type - Allow Inherited from - None Columns: Principal - Access - Applies to Administrators - Full Control - This key and subkeys Backup Operators - Read - This key only LOCAL SERVICE - Read - This key and subkeys
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- WN12-SO-000003
- Vuln IDs
- V-225448
- Rule IDs
- SV-225448r569185_rule
Fix: F-27135r471687_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Accounts: Guest account status" to "Disabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN12-SO-000004
- Vuln IDs
- V-225449
- Rule IDs
- SV-225449r569185_rule
Fix: F-27136r471690_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Accounts: Limit local account use of blank passwords to console logon only" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000005
- Vuln IDs
- V-225450
- Rule IDs
- SV-225450r569185_rule
Fix: F-27137r471693_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Accounts: Rename administrator account" to a name other than "Administrator".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000006
- Vuln IDs
- V-225451
- Rule IDs
- SV-225451r569185_rule
Fix: F-27138r471696_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Accounts: Rename guest account" to a name other than "Guest".
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001095
- Version
- WN12-SO-000007
- Vuln IDs
- V-225452
- Rule IDs
- SV-225452r569185_rule
Fix: F-27139r471699_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Audit: Audit the access of global system objects" to "Disabled".
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001095
- Version
- WN12-SO-000008
- Vuln IDs
- V-225453
- Rule IDs
- SV-225453r569185_rule
Fix: F-27140r471702_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Audit: Audit the use of Backup and Restore privilege" to "Disabled".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- WN12-SO-000009
- Vuln IDs
- V-225454
- Rule IDs
- SV-225454r569185_rule
Fix: F-27141r471705_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000011
- Vuln IDs
- V-225455
- Rule IDs
- SV-225455r569185_rule
Fix: F-27142r471708_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Devices: Allowed to format and eject removable media" to "Administrators".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000012
- Vuln IDs
- V-225456
- Rule IDs
- SV-225456r852245_rule
Fix: F-27143r471711_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Domain member: Digitally encrypt or sign secure channel data (always)" to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000013
- Vuln IDs
- V-225457
- Rule IDs
- SV-225457r852246_rule
Fix: F-27144r471714_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Digitally encrypt secure channel data (when possible)" to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000014
- Vuln IDs
- V-225458
- Rule IDs
- SV-225458r852247_rule
Fix: F-27145r471717_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Digitally sign secure channel data (when possible)" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000015
- Vuln IDs
- V-225459
- Rule IDs
- SV-225459r569185_rule
Fix: F-27146r471720_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Domain member: Disable machine account password changes" to "Disabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000016
- Vuln IDs
- V-225460
- Rule IDs
- SV-225460r569185_rule
Fix: F-27147r471723_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Domain member: Maximum machine account password age" to "30" or less (excluding "0" which is unacceptable).
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000017
- Vuln IDs
- V-225461
- Rule IDs
- SV-225461r852248_rule
Fix: F-27148r471726_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Domain member: Require strong (Windows 2000 or Later) session key" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000018
- Vuln IDs
- V-225462
- Rule IDs
- SV-225462r569185_rule
Fix: F-27149r471729_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Interactive logon: Do not display last user name" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000019
- Vuln IDs
- V-225463
- Rule IDs
- SV-225463r569185_rule
Fix: F-27150r471732_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Interactive Logon: Do not require CTRL+ALT+DEL" to "Disabled".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- WN12-SO-000021
- Vuln IDs
- V-225464
- Rule IDs
- SV-225464r569185_rule
Fix: F-27151r471735_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Interactive logon: Machine inactivity limit" to "900" seconds" or less, excluding "0" which is effectively disabled.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000024
- Vuln IDs
- V-225467
- Rule IDs
- SV-225467r569185_rule
Fix: F-27154r471744_fix
If the system is not a member of a domain, this is NA. Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Interactive Logon: Number of previous logons to cache (in case Domain Controller is not available)" to "4" logons or less.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000025
- Vuln IDs
- V-225468
- Rule IDs
- SV-225468r569185_rule
Fix: F-27155r471747_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Interactive Logon: Prompt user to change password before expiration" to "14" days or more.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000027
- Vuln IDs
- V-225469
- Rule IDs
- SV-225469r569185_rule
Fix: F-27156r471750_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Interactive logon: Smart card removal behavior" to "Lock Workstation" or "Force Logoff".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000028
- Vuln IDs
- V-225470
- Rule IDs
- SV-225470r852249_rule
Fix: F-27157r471753_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Microsoft network client: Digitally sign communications (always)" to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000029
- Vuln IDs
- V-225471
- Rule IDs
- SV-225471r852250_rule
Fix: F-27158r471756_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Microsoft network client: Digitally sign communications (if server agrees)" to "Enabled".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- WN12-SO-000030
- Vuln IDs
- V-225472
- Rule IDs
- SV-225472r569185_rule
Fix: F-27159r471759_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Microsoft Network Client: Send unencrypted password to third-party SMB servers" to "Disabled".
- RMF Control
- SC-10
- Severity
- L
- CCI
- CCI-001133
- Version
- WN12-SO-000031
- Vuln IDs
- V-225473
- Rule IDs
- SV-225473r852251_rule
Fix: F-27160r471762_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Microsoft Network Server: Amount of idle time required before suspending session" to "15" minutes or less.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000032
- Vuln IDs
- V-225474
- Rule IDs
- SV-225474r852252_rule
Fix: F-27161r471765_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Microsoft network server: Digitally sign communications (always)" to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN12-SO-000033
- Vuln IDs
- V-225475
- Rule IDs
- SV-225475r852253_rule
Fix: F-27162r471768_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Microsoft network server: Digitally sign communications (if client agrees)" to "Enabled".
- RMF Control
- SC-10
- Severity
- L
- CCI
- CCI-001133
- Version
- WN12-SO-000034
- Vuln IDs
- V-225476
- Rule IDs
- SV-225476r569185_rule
Fix: F-27163r471771_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Microsoft network server: Disconnect clients when logon hours expire" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000035
- Vuln IDs
- V-225477
- Rule IDs
- SV-225477r569185_rule
Fix: F-27164r471774_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Microsoft network server: Server SPN target name validation level" to "Off".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000036
- Vuln IDs
- V-225478
- Rule IDs
- SV-225478r569185_rule
Fix: F-27165r641828_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)" to "Disabled". Ensure no passwords are stored in the "DefaultPassword" registry value noted below: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ Value Name: DefaultPassword (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.) Severity Override Guidance: If the DefaultName or DefaultDomainName in the same registry path contain an administrator account name and the DefaultPassword contains a value, this is a CAT I finding.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000037
- Vuln IDs
- V-225479
- Rule IDs
- SV-225479r569185_rule
Fix: F-27166r471780_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)" to "Highest protection, source routing is completely disabled". (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000038
- Vuln IDs
- V-225480
- Rule IDs
- SV-225480r569185_rule
Fix: F-27167r471783_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)" to "Highest protection, source routing is completely disabled". (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000039
- Vuln IDs
- V-225481
- Rule IDs
- SV-225481r569185_rule
Fix: F-27168r471786_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes" to "Disabled". (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN12-SO-000041
- Vuln IDs
- V-225482
- Rule IDs
- SV-225482r852254_rule
Fix: F-27169r471789_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds" to "300000 or 5 minutes (recommended)" or less. (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000042
- Vuln IDs
- V-225483
- Rule IDs
- SV-225483r569185_rule
Fix: F-27170r471792_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic" to "Only ISAKMP is exempt (recommended for Windows Server 2003)". (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN12-SO-000043
- Vuln IDs
- V-225484
- Rule IDs
- SV-225484r852255_rule
Fix: F-27171r471795_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers" to "Enabled". (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN12-SO-000044
- Vuln IDs
- V-225485
- Rule IDs
- SV-225485r852256_rule
Fix: F-27172r471798_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)" to "Disabled". (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000045
- Vuln IDs
- V-225486
- Rule IDs
- SV-225486r569185_rule
Fix: F-27173r471801_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)" to "Enabled". (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000046
- Vuln IDs
- V-225487
- Rule IDs
- SV-225487r569185_rule
Fix: F-27174r471804_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)" to "5" or less. (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN12-SO-000047
- Vuln IDs
- V-225488
- Rule IDs
- SV-225488r852257_rule
Fix: F-27175r471807_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)" to "3" or less. (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN12-SO-000048
- Vuln IDs
- V-225489
- Rule IDs
- SV-225489r852258_rule
Fix: F-27176r471810_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)" to "3" or less. (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- AU-5
- Severity
- L
- CCI
- CCI-000139
- Version
- WN12-SO-000049
- Vuln IDs
- V-225490
- Rule IDs
- SV-225490r852259_rule
Fix: F-27177r471813_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning" to "90" or less. (See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN12-SO-000051
- Vuln IDs
- V-225492
- Rule IDs
- SV-225492r569185_rule
Fix: F-27179r471819_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Do not allow anonymous enumeration of SAM accounts" to "Enabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN12-SO-000052
- Vuln IDs
- V-225493
- Rule IDs
- SV-225493r569185_rule
Fix: F-27180r471822_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Do not allow anonymous enumeration of SAM accounts and shares" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000054
- Vuln IDs
- V-225494
- Rule IDs
- SV-225494r569185_rule
Fix: F-27181r471825_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Let everyone permissions apply to anonymous users" to "Disabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN12-SO-000055-MS
- Vuln IDs
- V-225495
- Rule IDs
- SV-225495r569185_rule
Fix: F-27182r471828_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Named pipes that can be accessed anonymously" to be defined but containing no entries (blank).
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN12-SO-000056
- Vuln IDs
- V-225496
- Rule IDs
- SV-225496r569185_rule
Fix: F-27183r471831_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Remotely accessible registry paths" with the following entries: System\CurrentControlSet\Control\ProductOptions System\CurrentControlSet\Control\Server Applications Software\Microsoft\Windows NT\CurrentVersion
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN12-SO-000057
- Vuln IDs
- V-225497
- Rule IDs
- SV-225497r569185_rule
Fix: F-27184r471834_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Remotely accessible registry paths and sub-paths" with the following entries: Software\Microsoft\OLAP Server Software\Microsoft\Windows NT\CurrentVersion\Perflib Software\Microsoft\Windows NT\CurrentVersion\Print Software\Microsoft\Windows NT\CurrentVersion\Windows System\CurrentControlSet\Control\ContentIndex System\CurrentControlSet\Control\Print\Printers System\CurrentControlSet\Control\Terminal Server System\CurrentControlSet\Control\Terminal Server\UserConfig System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration System\CurrentControlSet\Services\Eventlog System\CurrentControlSet\Services\Sysmonlog
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN12-SO-000058
- Vuln IDs
- V-225498
- Rule IDs
- SV-225498r569185_rule
Fix: F-27185r471837_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Restrict anonymous access to Named Pipes and Shares" to "Enabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN12-SO-000059
- Vuln IDs
- V-225499
- Rule IDs
- SV-225499r569185_rule
Fix: F-27186r471840_fix
Ensure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Shares that can be accessed anonymously" contains no entries (blank).
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- WN12-SO-000060
- Vuln IDs
- V-225500
- Rule IDs
- SV-225500r569185_rule
Fix: F-27187r471843_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network access: Sharing and security model for local accounts" to "Classic - local users authenticate as themselves".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000778
- Version
- WN12-SO-000061
- Vuln IDs
- V-225501
- Rule IDs
- SV-225501r569185_rule
Fix: F-27188r471846_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: Allow Local System to use computer identity for NTLM" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000062
- Vuln IDs
- V-225502
- Rule IDs
- SV-225502r569185_rule
Fix: F-27189r471849_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: Allow LocalSystem NULL session fallback" to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000063
- Vuln IDs
- V-225503
- Rule IDs
- SV-225503r569185_rule
Fix: F-27190r471852_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: Allow PKU2U authentication requests to this computer to use online identities" to "Disabled".
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- WN12-SO-000064
- Vuln IDs
- V-225504
- Rule IDs
- SV-225504r569185_rule
Fix: F-27191r471855_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Configure encryption types allowed for Kerberos" to "Enabled" with only the following selected: AES128_HMAC_SHA1 AES256_HMAC_SHA1 Future encryption types Note: Removing the previously allowed RC4_HMAC_MD5 encryption suite may have operational impacts and must be thoroughly tested for the environment before changing. This includes but is not limited to parent\child trusts where RC4 is still enabled; selecting "The other domain supports Kerberos AES Encryption" may be required on the domain trusts to allow client communication across the trust relationship.
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000196
- Version
- WN12-SO-000065
- Vuln IDs
- V-225505
- Rule IDs
- SV-225505r569185_rule
Fix: F-27192r471858_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: Do not store LAN Manager hash value on next password change" to "Enabled".
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- WN12-SO-000066
- Vuln IDs
- V-225506
- Rule IDs
- SV-225506r569185_rule
Fix: F-27193r471861_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: Force logoff when logon hours expire" to "Enabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN12-SO-000067
- Vuln IDs
- V-225507
- Rule IDs
- SV-225507r569185_rule
Fix: F-27194r471864_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: LAN Manager authentication level" to "Send NTLMv2 response only. Refuse LM & NTLM".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000068
- Vuln IDs
- V-225508
- Rule IDs
- SV-225508r569185_rule
Fix: F-27195r471867_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: LDAP client signing requirements" to "Negotiate signing" at a minimum.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000069
- Vuln IDs
- V-225509
- Rule IDs
- SV-225509r569185_rule
Fix: F-27196r471870_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: Minimum session security for NTLM SSP based (including secure RPC) clients" to "Require NTLMv2 session security" and "Require 128-bit encryption" (all options selected).
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000070
- Vuln IDs
- V-225510
- Rule IDs
- SV-225510r569185_rule
Fix: F-27197r471873_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network security: Minimum session security for NTLM SSP based (including secure RPC) servers" to "Require NTLMv2 session security" and "Require 128-bit encryption" (all options selected).
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000073
- Vuln IDs
- V-225511
- Rule IDs
- SV-225511r569185_rule
Fix: F-27198r471876_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Shutdown: Allow system to be shutdown without having to log on" to "Disabled".
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- WN12-SO-000074
- Vuln IDs
- V-225512
- Rule IDs
- SV-225512r852260_rule
Fix: F-27199r471879_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SO-000075
- Vuln IDs
- V-225513
- Rule IDs
- SV-225513r569185_rule
Fix: F-27200r471882_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "System objects: Require case insensitivity for non-Windows subsystems" to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN12-SO-000076
- Vuln IDs
- V-225514
- Rule IDs
- SV-225514r569185_rule
Fix: F-27201r471885_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-SO-000077
- Vuln IDs
- V-225515
- Rule IDs
- SV-225515r852261_rule
Fix: F-27202r471888_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Admin Approval Mode for the Built-in Administrator account" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-SO-000078
- Vuln IDs
- V-225516
- Rule IDs
- SV-225516r569185_rule
Fix: F-27203r471891_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode" to "Prompt for consent". More secure options for this setting would also be acceptable (e.g., Prompt for credentials, Prompt for consent (or credentials) on the secure desktop).
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-SO-000079
- Vuln IDs
- V-225517
- Rule IDs
- SV-225517r852262_rule
Fix: F-27204r471894_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Behavior of the elevation prompt for standard users" to "Automatically deny elevation requests".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-SO-000080
- Vuln IDs
- V-225518
- Rule IDs
- SV-225518r569185_rule
Fix: F-27205r471897_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Detect application installations and prompt for elevation" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-SO-000081
- Vuln IDs
- V-225519
- Rule IDs
- SV-225519r569185_rule
Fix: F-27206r471900_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Only elevate executables that are signed and validated" to "Disabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-SO-000082
- Vuln IDs
- V-225520
- Rule IDs
- SV-225520r569185_rule
Fix: F-27207r471903_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Only elevate UIAccess applications that are installed in secure locations" to "Enabled".
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- WN12-SO-000083
- Vuln IDs
- V-225521
- Rule IDs
- SV-225521r852263_rule
Fix: F-27208r471906_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Run all administrators in Admin Approval Mode" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-SO-000084
- Vuln IDs
- V-225522
- Rule IDs
- SV-225522r569185_rule
Fix: F-27209r471909_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Switch to the secure desktop when prompting for elevation" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-SO-000085
- Vuln IDs
- V-225523
- Rule IDs
- SV-225523r569185_rule
Fix: F-27210r471912_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Virtualize file and registry write failures to per-user locations" to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN12-SO-000086
- Vuln IDs
- V-225524
- Rule IDs
- SV-225524r569185_rule
Fix: F-27211r471915_fix
UAC requirements are NA on Server Core installations. Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop" to "Disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN12-SO-000088
- Vuln IDs
- V-225525
- Rule IDs
- SV-225525r569185_rule
Fix: F-27212r471918_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "System settings: Optional subsystems" to "Blank" (Configured with no entries).
- RMF Control
- CM-11
- Severity
- L
- CCI
- CCI-001812
- Version
- WN12-SO-000089
- Vuln IDs
- V-225526
- Rule IDs
- SV-225526r852264_rule
Fix: F-27213r471921_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Devices: Prevent users from installing printer drivers" to "Enabled".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000186
- Version
- WN12-SO-000092
- Vuln IDs
- V-225527
- Rule IDs
- SV-225527r569185_rule
Fix: F-27214r471924_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "System cryptography: Force strong key protection for user keys stored on the computer" to "User must enter a password each time they use a key".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-SV-000100
- Vuln IDs
- V-225528
- Rule IDs
- SV-225528r569185_rule
Fix: F-27215r471927_fix
Remove or disable the Fax (fax) service.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WN12-SV-000101
- Vuln IDs
- V-225529
- Rule IDs
- SV-225529r569185_rule
Fix: F-27216r471930_fix
Remove or disable the "Microsoft FTP Service" (Service name: FTPSVC). To remove the "FTP Server" role from a system: Start "Server Manager" Select the server with the "FTP Server" role. Scroll down to "ROLES AND FEATURES" in the left pane. Select "Remove Roles and Features" from the drop down "TASKS" list. Select the appropriate server on the "Server Selection" page, click "Next". De-select "FTP Server" under "Web Server (IIS). Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-SV-000103
- Vuln IDs
- V-225530
- Rule IDs
- SV-225530r569185_rule
Fix: F-27217r471933_fix
Remove or disable the Peer Networking Identity Manager (p2pimsvc) service.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN12-SV-000104
- Vuln IDs
- V-225531
- Rule IDs
- SV-225531r569185_rule
Fix: F-27218r471936_fix
Remove or disable the Simple TCP/IP Services (simptcp) service.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WN12-SV-000105
- Vuln IDs
- V-225532
- Rule IDs
- SV-225532r569185_rule
Fix: F-27219r471939_fix
Remove or disable the Telnet (tlntsvr) service.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN12-SV-000106
- Vuln IDs
- V-225533
- Rule IDs
- SV-225533r569185_rule
Fix: F-27220r471942_fix
Configure the Startup Type for the Smart Card Removal Policy service to "Automatic".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000001
- Vuln IDs
- V-225545
- Rule IDs
- SV-225545r852266_rule
Fix: F-27232r471978_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Access Credential Manager as a trusted caller" to be defined but containing no entries (blank).
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000002-MS
- Vuln IDs
- V-225546
- Rule IDs
- SV-225546r569185_rule
Fix: F-27233r471981_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Access this computer from the network" to only include the following accounts or groups: Administrators Authenticated Users
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN12-UR-000003
- Vuln IDs
- V-225547
- Rule IDs
- SV-225547r852267_rule
Fix: F-27234r471984_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Act as part of the operating system" to be defined but containing no entries (blank).
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000005
- Vuln IDs
- V-225548
- Rule IDs
- SV-225548r569185_rule
Fix: F-27235r471987_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Allow log on locally" to only include the following accounts or groups: Administrators
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000006-MS
- Vuln IDs
- V-225549
- Rule IDs
- SV-225549r569185_rule
Fix: F-27236r471990_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Allow log on through Remote Desktop Services" to only include the following accounts or groups: Administrators If the system serves the Remote Desktop Services role, the Remote Desktop Users group or another more restrictive group may be included. Organizations may grant this to other groups, such as more restrictive groups with administrative or management functions, if required. Remote Desktop Services access must be restricted to the accounts that require it. This must be documented with the ISSO.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000007
- Vuln IDs
- V-225550
- Rule IDs
- SV-225550r852268_rule
Fix: F-27237r471993_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Back up files and directories" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000011
- Vuln IDs
- V-225551
- Rule IDs
- SV-225551r852269_rule
Fix: F-27238r471996_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create a pagefile" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN12-UR-000012
- Vuln IDs
- V-225552
- Rule IDs
- SV-225552r852270_rule
Fix: F-27239r471999_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create a token object" to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000013
- Vuln IDs
- V-225553
- Rule IDs
- SV-225553r852271_rule
Fix: F-27240r472002_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create global objects" to only include the following accounts or groups: Administrators Service Local Service Network Service
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000014
- Vuln IDs
- V-225554
- Rule IDs
- SV-225554r852272_rule
Fix: F-27241r472005_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create permanent shared objects" to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000015
- Vuln IDs
- V-225555
- Rule IDs
- SV-225555r852273_rule
Fix: F-27242r472008_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Create symbolic links" to only include the following accounts or groups: Administrators Systems that have the Hyper-V role will also have "Virtual Machines" given this user right. If this needs to be added manually, enter it as "NT Virtual Machine\Virtual Machines".
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN12-UR-000016
- Vuln IDs
- V-225556
- Rule IDs
- SV-225556r852274_rule
Fix: F-27243r472011_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Debug programs" to only include the following accounts or groups: Administrators
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000017-MS
- Vuln IDs
- V-225557
- Rule IDs
- SV-225557r569185_rule
Fix: F-27244r472014_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny access to this computer from the network" to include the following: Domain Systems Only: Enterprise Admins group Domain Admins group "Local account and member of Administrators group" or "Local account" (see Note below) All Systems: Guests group Note: Windows Server 2012 R2 added new built-in security groups, "Local account" and "Local account and member of Administrators group". "Local account" is more restrictive but may cause issues on servers such as systems that provide Failover Clustering. Microsoft Security Advisory Patch 2871997 adds the new security groups to Windows Server 2012.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000018-MS
- Vuln IDs
- V-225558
- Rule IDs
- SV-225558r569185_rule
Fix: F-27245r472017_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment -> "Deny log on as a batch job" to include the following: Domain Systems Only: Enterprise Admins Group Domain Admins Group All Systems: Guests Group
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000019-MS
- Vuln IDs
- V-225559
- Rule IDs
- SV-225559r569185_rule
Fix: F-27246r472020_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment -> "Deny log on as a service" to include the following for domain-joined systems: Enterprise Admins Group Domain Admins Group Configure the "Deny log on as a service" for nondomain systems to include no entries (blank).
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000020-MS
- Vuln IDs
- V-225560
- Rule IDs
- SV-225560r569185_rule
Fix: F-27247r472023_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment -> "Deny log on locally" to include the following: Domain Systems Only: Enterprise Admins Group Domain Admins Group All Systems: Guests Group
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN12-UR-000021-MS
- Vuln IDs
- V-225561
- Rule IDs
- SV-225561r569185_rule
Fix: F-27248r472026_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny log on through Remote Desktop Services" to include the following: Domain Systems Only: Enterprise Admins group Domain Admins group Local account (see Note below) All Systems: Guests group Note: Windows Server 2012 R2 added new built-in security groups, including "Local account", for assigning permissions and rights to all local accounts. Microsoft Security Advisory Patch 2871997 adds the new security groups to Windows Server 2012.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000022-MS
- Vuln IDs
- V-225562
- Rule IDs
- SV-225562r852275_rule
Fix: F-27249r472029_fix
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment -> "Enable computer and user accounts to be trusted for delegation" to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000023
- Vuln IDs
- V-225563
- Rule IDs
- SV-225563r852276_rule
Fix: F-27250r472032_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Force shutdown from a remote system" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000024
- Vuln IDs
- V-225564
- Rule IDs
- SV-225564r852277_rule
Fix: F-27251r472035_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Generate security audits" to only include the following accounts or groups: Local Service Network Service
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000025
- Vuln IDs
- V-225565
- Rule IDs
- SV-225565r852278_rule
Fix: F-27252r472038_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Impersonate a client after authentication" to only include the following accounts or groups: Administrators Service Local Service Network Service
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000027
- Vuln IDs
- V-225566
- Rule IDs
- SV-225566r852279_rule
Fix: F-27253r472041_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Increase scheduling priority" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000028
- Vuln IDs
- V-225567
- Rule IDs
- SV-225567r852280_rule
Fix: F-27254r472044_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Load and unload device drivers" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000029
- Vuln IDs
- V-225568
- Rule IDs
- SV-225568r852281_rule
Fix: F-27255r472047_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Lock pages in memory" to be defined but containing no entries (blank).
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN12-UR-000032
- Vuln IDs
- V-225569
- Rule IDs
- SV-225569r852282_rule
Fix: F-27256r472050_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Manage auditing and security log" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000034
- Vuln IDs
- V-225570
- Rule IDs
- SV-225570r852283_rule
Fix: F-27257r472053_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Modify firmware environment values" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000035
- Vuln IDs
- V-225571
- Rule IDs
- SV-225571r852284_rule
Fix: F-27258r472056_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Perform volume maintenance tasks" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000036
- Vuln IDs
- V-225572
- Rule IDs
- SV-225572r852285_rule
Fix: F-27259r472059_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Profile single process" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000040
- Vuln IDs
- V-225573
- Rule IDs
- SV-225573r852286_rule
Fix: F-27260r472062_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Restore files and directories" to only include the following accounts or groups: Administrators
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN12-UR-000042
- Vuln IDs
- V-225574
- Rule IDs
- SV-225574r852287_rule
Fix: F-27261r472065_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Take ownership of files or other objects" to only include the following accounts or groups: Administrators