Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
Procedure: Interview the SA to determine the type of data being housed on the machine. Interview the SA to determine the backup process being used for the data. Criteria: If there is no backup process or the backup process is inadequate for the data on the machine, this is a finding.
Interview the SA to determine the type of data on the machine and its backup process. If there is no backup process or the process is inadequate, have the SA create a new backup process.
Procedure: Using Windows explorer search for the following files: ymsgr*.exe, aim.exe Criteria: If any of the files are found, this is a finding. Note: If the file is tied to an IM application that is DOD controlled, this is not a finding.
Use Windows explorer to search for the files ymsgr*.exe and aim.exe. If found, delete them unless the file is tied to an IM application that is DoD controlled.
Procedure: Using Windows explorer search for the following files: *napv*.exe, Gnutella.exe Criteria: If any of the files are found examine it to determine if it is a file sharing utility. If it is, this is a finding.
Use Windows explorer to search for the files *napv.exe and Gnutella.exe. If found and they are determined to be a file sharing utility, delete them.
On Windows NT/2000/2003/XP-- Start the Windows Explorer application. On the Tools menu, select the Folder Options… item. On the Folder Options window, select the File Types tab. For each of the file types in the table below, select the Edit… button for Windows NT or the Advanced button for Windows 2000/2003/XP. On Windows 7/8/2008/2008R2-- Click on Start. Select Default Programs from the right side of the menu. Choose the Associate a file or protocol with a program option. a) Determine the default Action by looking in the Actions: list for an action in bold font. A typical default action is indicated as “Open”. If none of the entries in the Actions: list appears in bold font, the “Open” action is the default Action. Select the default Action and the Edit… button to determine the application used to perform the action. b) Determine the value of the Always show extension option. File Type Extensions JScript Script File JS Windows Script Component SCT,WSC JScript Encoded Script File JSE Windows Script File WSF Scrap object SHS,SHB Windows Script Host Settings File WSH HTML Applications as Mobile Code HTA VBScript Encoded Script File VBE VBScript Script File VBS NOTE: The File Type strings (e.g., “JScript Script File”) may vary according to the specific software release. The key element for the check is the Extension value. Criteria: If a file type is not defined, this is not a Finding. a) If the application defined to perform the default Action could execute code in the file, then this is a Finding. For example, if the default Action for file type .VBS specifies wscript.exe as the application, a Finding is indicated. On the other hand, if the default Action for any file type specifies notepad.exe as the application, there is not a Finding. b) If the Always show extension option is not enabled for each file type, then this is a Finding. For Windows Vista open the Control Panel select Default Programs select Associate a file type or protocol with a Program: a) Determine the default program by looking in the Current Default: list. A typical default action is indicated as “Open”. If none of the entries in the Actions: list appears in bold font, the “Open” action is the default Action. Select the default Action and the Edit… button to determine the application used to perform the action. b) Determine the value of the Always show extension option. File Type Extensions File Type Extensions JScript Script File JS Windows Script Component SCT,WSC JScript Encoded Script File JSE Windows Script File WSF Scrap object SHS,SHB Windows Script Host Settings File WSH HTML Applications as Mobile Code HTA VBScript Encoded Script File VBE VBScript Script File VBS NOTE: The File Type strings (e.g., “JScript Script File”) may vary according to the specific software release. The key element for the check is the Extension value. Criteria: If a file type is not defined, this is not a Finding. a) If the application defined in the Current Default list could execute code in the file, then this is a Finding. For example, if the default program for file type .VBS specifies wscript.exe as the application, a Finding is indicated. On the other hand, if the default Action for any file type specifies notepad.exe as the application, there is not a Finding.
Change the default action to an application that will not execute the file such as notepad.exe and ensure that the Always show extension is enabled for the filetype in question.
On Windows NT/2000/2003/XP-- Start the Windows Explorer application. On the Tools menu, select the Folder Options… item. On the Folder Options window, select the File Types tab. For each of the file types in the table below, select the Edit… button for Windows NT or the Advanced button for Windows 2000/2003/XP. On the Edit File Type window: a) Determine the value of the Confirm open after download option. b) Determine the value of the Always show extension option. On Windows 7/8/2008/2008R2-- Start the Windows Explorer application. Click on the drop-down arrow of the Organize option and select Folder and Search Options. In the Folder Options dialog box, click on the View TAB. a) Ensure the "Hide extensions for known file types" is not selected. File Type Extensions Adobe Acrobat Document PDF Microsoft PowerPoint Slide Show PPS LotusScript Library LSL Microsoft PowerPoint Template POT LotusScript Object LSO Microsoft Word Backup Document WBK Jscript JS,JSE HTML Applications HTA LotusScript Source LSS Microsoft Word Document DOC Microsoft Excel Backup File XLK Microsoft Word Template DOT Microsoft Excel OLE DB Query Files RQY MS-DOS Batch File BAT Microsoft Excel Web Query File IQY PostScript PS,EPS Microsoft Excel Template XLT Rich Text Format RTF Microsoft Excel Worksheet XLS,XLB WordPerfect Coach WCH VISIO VSS,VST,VSD,VSW Microsoft Access AD, ADP,MDB,MDE Shockwave DCR,DXR,DIR,SPL, SWF Flash FLS Shell Scrap Object SHS, SHB WordPerfect Macro WCM Windows Script Component WSC, SCT Windows Script File WSF Windows Script Host Settings File WSH VBScript VBE, VBS Microsoft PowerPoint Presentation PPT NOTE: The File Type strings (e.g., “LotusScript Library”) may vary according to the specific software release. The key element for the check is the Extension value. Criteria: If a file type is not defined, this is not a Finding. a) If the Confirm open after download option in Windows NT/2000/2003/XP is not enabled for each file type, then this is a Finding. In Windows 7/8/2008/2008R2, this is Not Applicable. b) If the Always show extension option in Windows NT/2000/2003/XP is not enabled for each file type, then this is a Finding. c) If the Hide extensions for know file types in Windows 7/8/2008/2008R2 is selected, then this is a Finding. *Note: this check does not apply to Windows Vista
For each of the filetypes in question, verify the Confirm after download option and the always show extension option are checked.