[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings

ID: oval:org.secpod.oval:def:22619Date: (C)2015-01-07   (M)2023-07-14
Class: COMPLIANCEFamily: windows




Windows Vista and later versions of Windows allow audit policy to be managed in a more precise way using audit policy subcategories. Setting audit policy at the category level will override the new subcategory audit policy feature. Group Policy only allows audit policy to be set at the category level, and existing group policy may override the subcategory settings of new machines as they are joined to the domain or upgraded to Windows Vista or later versions. To allow audit policy to be managed using subcategories without requiring a change to Group Policy, there is a new registry value in Windows Vista and later versions, SCENoApplyLegacyAuditPolicy, which prevents the application of category-level audit policy from Group Policy and from the Local Security Policy administrative tool. If the category level audit policy set here is not consistent with the events that are currently being generated, the cause might be that this registry key is set. Default: Enabled Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options!Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings (2) REG: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa!scenoapplylegacyauditpolicy

Platform:
Microsoft Windows 8.1
Reference:
CCE-35533-9
CPE    1
cpe:/o:microsoft:windows_8.1
CCE    1
CCE-35533-9
XCCDF    7
xccdf_org.secpod_benchmark_HIPAA_45CFR_164_Windows_8_1
xccdf_org.secpod_benchmark_ISO27001_Windows_8_1
xccdf_org.secpod_benchmark_NIST_800_53_r4_Windows_8_1
xccdf_org.secpod_benchmark_PCI_3_2_Windows_8_1
...

© SecPod Technologies