[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

246852

 
 

909

 
 

194149

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CCE-9972-1
The 'Access Credential Manager as a trusted caller' user right should be assigned to the appropriate accounts.

CCE-11431-4
The "Default behavior for AutoRun" machine setting should be configured correctly.

CCE-10906-6
The "Enable user control over installs" machine setting should be configured correctly.

CCE-10857-1
Windows Firewall should allow or block inbound connections by default as appropriate for the Private Profile.

CCE-11563-4
The "Turn off downloading of print drivers over HTTP" machine setting should be configured correctly.

CCE-11028-8
The 'User Account Control: Admin Approval Mode for the Built-in Administrator account' setting should be configured correctly.

CCE-11405-8
The "Validate smart card certificate usage rule compliance" machine setting should be configured correctly.

CCE-12204-4
The "Backup log automatically when full" machine setting should be configured correctly for the system log.

CCE-10775-5
This policy setting determines whether a domain member can periodically change its computer account password. If you enable this policy setting, the domain member will be prevented from changing its computer account password. If you disable this policy setting, the domain member can change its compu ...

CCE-10518-9
The 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' setting should be configured correctly.

CCE-11958-6
The "Turn off the Windows Messenger Customer Experience Improvement Program" machine setting should be configured correctly.

CCE-11360-5
The "Turn off printing over HTTP" machine setting should be configured correctly.

CCE-10419-0
The 'Shutdown: Allow system to be shut down without having to log on' setting should be configured correctly.

CCE-10570-0
The 'User Account Control: Only elevate UIAccess applications that are installed in secure locations' setting should be configured correctly.

CCE-11317-5
The "Turn off Data Execution Prevention for HTML Help Executible" machine setting should be configured correctly.

CCE-10812-6
Allow NTLM to fall back to NULL session when used with LocalSystem. The default is TRUE up to Windows Vista and FALSE in Windows 7. Countermeasure: Configure Network security: Allow LocalSystem NULL session fallback to Disabled. Potential Impact: Any applications that require NULL ses ...

CCE-11587-3
The "Turn off the "Publish to Web" task for files and folders" machine setting should be configured correctly.

CCE-10751-6
The 'MSS: (Hidden) Hide Computer From the Browse List (not recommended except for highly secure environments)' setting should be configured correctly.

CCE-10123-8
Windows Firewall should allow or block outbound connections by default as appropriate for the Private Profile.

CCE-10691-4
The "Prevent the computer from joining a homegroup" machine setting should be configured correctly.

CCE-11136-9
The "Turn off Internet download for Web publishing and online ordering wizards" machine setting should be configured correctly.

CCE-10653-4
The 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' setting should be configured correctly.

CCE-11174-0
The "Maximum Log Size (KB)" machine setting should be configured correctly for the system log.

CCE-10422-4
The "Configure use of passwords for removable data drives" machine setting should be configured correctly.

CCE-11367-0
The "Turn off location" machine setting should be configured correctly.

CCE-11143-5
The "Maximum Log Size (KB)" machine setting should be configured correctly for the application log.

CCE-10113-9
Windows Firewall should allow or block outbound connections by default as appropriate for the Domain Profile.

CCE-11625-1
The "Offer Remote Assistance" machine setting should be configured correctly.

CCE-10381-2
The 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' setting should be configured correctly.

CCE-10817-5
When enabled, this policy setting causes Local System services that use Negotiate to use the computer identity when NTLM authentication is selected by the negotiation. This policy is supported on at least Windows 7 or Windows Server 2008 R2. Countermeasure: Configure Network security: Allo ...

CCE-10878-7
The 'Deny log on through Remote Desktop Services' user right should be assigned to the appropriate accounts.

CCE-10109-7
The 'User Account Control: Switch to the secure desktop when prompting for elevation' setting should be configured correctly.

CCE-11867-9
The "Allow users to connect remotely using Remote Desktop Services" machine setting should be configured correctly.

CCE-10881-1
The "Restrictions for Unauthenticated RPC clients" machine setting should be configured correctly.

CCE-11651-7
The "Require a Password When a Computer Wakes (Plugged In)" machine setting should be configured correctly.

CCE-11723-4
The "Solicited Remote Assistance" machine setting should be configured correctly.

CCE-10370-5
The 'Recovery console: Allow automatic administrative logon' setting should be configured correctly.

CCE-10926-4
The 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' setting should be configured correctly.

CCE-11010-6
This policy setting determines the strength of the default discretionary access control list (DACL) for objects. The setting helps secure objects that can be located and shared among processes and its default configuration strengthens the DACL, because it allows users who are not administrators to r ...

CCE-11033-8
The "Maximum Log Size (KB)" machine setting should be configured correctly for the secirity log.

CCE-10889-4
The "Turn off Search Companion content file updates" machine setting should be configured correctly.

CCE-10941-3
The 'MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)' setting should be configured correctly.

CCE-18944-9
The 'Require 128-bit encryption' option for the 'Network security: Minimum session security for NTLM SSP based (including secure RPC) servers' setting should be enabled or disabled as appropriate.

CCE-10760-7
The 'Minimum password age' setting should be configured correctly.

CCE-10768-0
The 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' setting should be configured correctly.

CCE-11833-1
The "Server Authentication Certificate Template" machine setting should be configured correctly.

CCE-10992-6
The 'Microsoft network server: Digitally sign communications (always)' setting should be configured correctly.

CCE-10745-8
The 'MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)' setting should be configured correctly.

CCE-10647-6
The "Turn Off the Display (On Battery)" machine setting should be configured correctly.

CCE-10481-0
Windows Firewall should allow or block outbound connections by default as appropriate for the Public Profile.

CCE-10772-2
The 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' setting should be configured correctly.

CCE-11138-5
The "Backup log automatically when full" machine setting should be configured correctly for the setup log.

CCE-11860-4
The "Allow Remote Shell Access" machine setting should be configured correctly.

CCE-11248-2
The "Allow remote access to the Plug and Play interface" machine setting should be configured correctly.

CCE-11709-3
The "Do not allow drive redirection" machine setting should be configured correctly.

CCE-9999-4
The 'Devices: Prevent users from installing printer drivers' setting should be configured correctly.

CCE-10804-3
The 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)' setting should be configured correctly.

CCE-10997-5
Windows Firewall should allow or block inbound connections by default as appropriate for the Domain Profile.

CCE-10684-9
This policy setting controls the behavior of all User Account Control (UAC) policy settings for the computer. If you change this policy setting, you must restart your computer. The options are: - Enabled: (Default) Admin Approval Mode is enabled. This policy must be enabled and related UAC pol ...

CCE-11450-4
The "Enumerate administrator accounts on elevation" machine setting should be configured correctly.

CCE-11375-3
The "Turn off Autoplay for non-volume devices" machine setting should be configured correctly.

CCE-10794-6
This policy setting controls the behavior of application installation detection for the computer. The options are: - Enabled: (Default for home) When an application installation package is detected that requires elevation of privilege, the user is prompted to enter an administrative user name ...

CCE-11905-7
The "Do not allow passwords to be saved" machine setting should be configured correctly.

CCE-10733-4
The 'Deny access to this computer from the network' user right should be assigned to the appropriate accounts.

CCE-10357-2
The "Turn off Windows Update device driver searching" machine setting should be configured correctly.

CCE-10901-7
The 'Password must meet complexity requirements' policy should be set correctly.

CCE-11992-5
The "Do not process the run once list" machine setting should be configured correctly.

CCE-11035-3
The 'System cryptography: Force strong key protection for user keys stored on the computer' setting should be configured correctly.

CCE-10372-1
The 'Minimum password length' setting should be configured correctly.

CCE-9992-9
The 'Accounts: Limit local account use of blank passwords to console logon only' setting should be configured correctly.

CCE-11046-0
The 'Account lockout threshold' setting should be configured correctly.

CCE-10705-2
Logon information is required to unlock a locked computer. For domain accounts, the Interactive logon: Require Domain Controller authentication to unlock workstation setting determines whether it is necessary to contact a domain controller to unlock a computer. If you enable this setting, a domain c ...

CCE-10789-6
The 'System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing' setting should be configured correctly.

CCE-10131-1
The 'Windows Firewall: Private: Apply local firewall rules' setting should be configured correctly.

CCE-11299-5
The "Always prompt for password upon connection" machine setting should be configured correctly.

CCE-12088-1
The "Require a Password When a Computer Wakes (On Battery)" machine setting should be configured correctly.

CCE-10018-0
The 'MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic.' setting should be configured correctly.

CCE-11714-3
The "Allow Standby States (S1-S3) When Sleeping (Plugged In)" machine setting should be configured correctly.

CCE-10839-9
The 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' setting should be configured correctly.

CCE-11400-9
The "Backup log automatically when full" machine setting should be configured correctly for the security log.

CCE-11677-2
The "Set client connection encryption level" machine setting should be configured correctly.

CCE-11011-4
The 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' setting should be configured correctly.

CCE-10732-6
The 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)' setting should be configured correctly.

CCE-10562-7
The 'Maximum password age' setting should be configured correctly.

CCE-10865-4
The 'User Account Control: Virtualize file and registry write failures to per-user locations' setting should be configured correctly.

CCE-10888-6
The 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' setting should be configured correctly.

CCE-10940-5
The 'Network access: Restrict anonymous access to Named Pipes and Shares' setting should be configured correctly.

CCE-10619-5
The 'Audit: Audit the use of Backup and Restore privilege' setting should be configured correctly.

CCE-10487-7
The 'Audit: Audit the access of global system objects' setting should be configured correctly.

CCE-10742-5
The 'Audit: Shut down system immediately if unable to log security audits' setting should be configured correctly.

CCE-10780-5
The 'Devices: Restrict CD-ROM access to locally logged-on user only' setting should be configured correctly.

CCE-10573-4
The 'Interactive logon: Smart card removal behavior' setting should be configured correctly.

CCE-10596-5
The 'Deny log on as a batch job' user right should be assigned to the appropriate accounts.

CCE-11049-4
The 'Shutdown: Clear virtual memory pagefile' setting should be configured correctly.

CCE-11245-8
The "Do not process the legacy run list" machine setting should be configured correctly.

CCE-10922-3
The 'User Account Control: Only elevate executables that are signed and validated' setting should be configured correctly.

CCE-9989-5
The 'Accounts: Guest account status' setting should be configured correctly.

CCE-12282-0
The "Turn Off the Display (Plugged In)" machine setting should be configured correctly.

CCE-10809-2
The "Enforce password history" setting should be configured correctly.

CCE-10726-8
The 'Manage auditing and security log' user right should be assigned to the appropriate accounts.

CCE-10534-6
This policy setting controls whether User Interface Accessibility (UIAccess or UIA) programs can automatically disable the secure desktop for elevation prompts used by a standard user. - Enabled: UIA programs, including Windows Remote Assistance, automatically disable the secure desktop for elevati ...

CCE-11837-2
The "Allow Standby States (S1-S3) When Sleeping (On Battery)" machine setting should be configured correctly.

CCE-11890-1
The "Backup log automatically when full" machine setting should be configured correctly for the application log.

CCE-10643-5
The 'Recovery console: Allow floppy copy and access to all drives and all folders' setting should be configured correctly.

CCE-10984-3
LAN Manager (LM) is a family of early Microsoft client/server software that allows users to link personal computers together on a single network. Network capabilities include transparent file and print sharing, user security features, and network administration tools. In Active Directory domains, th ...

CCE-10292-1
The 'Network access: Do not allow storage of passwords and credentials for network authentication' setting should be configured correctly.

CCE-10715-1
The "RPC Endpoint Mapper Client Authentication" machine setting should be configured correctly.

CCE-10171-7
Windows Firewall should allow or block inbound connections by default as appropriate for the Public Profile.

CCE-10825-8
The 'Network access: Sharing and security model for local accounts' setting should be configured correctly.

CCE-11273-0
The "Choose how BitLocker-protected fixed drives can be recovered" machine setting should be configured correctly.

CCE-11258-1
The "Provide the unique identifiers for your organization" machine setting should be configured correctly.

CCE-11973-5
The "Choose how BitLocker-protected removable drives can be recovered" machine setting should be configured correctly.

CCE-11332-4
The "Configure minimum PIN length for startup" machine setting should be configured correctly.

CCE-11465-2
The "Allow access to BitLocker-protected fixed data drives from earlier versions of Windows" machine setting should be configured correctly.

CCE-12237-4
The "Configure use of passwords for fixed data drives" machine setting should be configured correctly.

CCE-12060-0
The "Choose how BitLocker-protected operating system drives can be recovered" machine setting should be configured correctly.

CCE-11636-8
The "Allow access to BitLocker-protected removable data drives from earlier versions of Windows" machine setting should be configured correctly.

CCE-11933-9
The "Require additional authentication at startup" machine setting should be configured correctly.

CCE-11142-7
The "Deny write access to removable drives not protected by BitLocker" machine setting should be configured correctly.

CCE-12336-4
The "Configure use of smart cards on removable data drives" machine setting should be configured correctly.

CCE-11506-3
The "Set time limit for active but idle Remote Desktop Services sessions" machine setting should be configured correctly.

CCE-11239-1
The "Configure use of smart cards on fixed data drives" machine setting should be configured correctly.

CCE-11928-9
The "Prevent memory overwrite on restart" machine setting should be configured correctly.

CCE-11615-2
The "Deny write access to fixed drives not protected by BitLocker" machine setting should be configured correctly.

CCE-11326-6
The "Set time limit for active Remote Desktop Services sessions" machine setting should be configured correctly.

CCE-10612-0
The "Allow enhanced PINs for startup" machine setting should be configured correctly.

CCE-11117-9
The "Set time limit for disconnected sessions" machine setting should be configured correctly.

CCE-11377-9
The "Control use of BitLocker on removable drives" machine setting should be configured correctly.

CCE-10019-8
The time in seconds before the screen saver grace period expires (ScreenSaverGracePeriod) setting should be configured correctly.

CCE-10983-5
The 'Microsoft network server: Disconnect clients when logon hours expire' setting should be configured correctly.

CCE-12401-6
The "Always install with elevated privileges" machine setting should be configured correctly.

CCE-10637-7
The 'Devices: Allowed to format and eject removable media' setting should be configured correctly.

CCE-10750-8
The 'Deny log on locally' user right should be assigned to the appropriate accounts.

CCE-10807-6
The 'User Account Control: Behavior of the elevation prompt for standard users' setting should be configured correctly.

CCE-10830-8
The 'Network security: Do not store LAN Manager hash value on next password change' setting should be configured correctly.

CCE-11023-9
This policy setting controls the behavior of the elevation prompt for administrators. The options are: - Elevate without prompting: Allows privileged accounts to perform an operation that requires elevation without requiring consent or credentials. Note: Use this option only in the most co ...

CCE-10970-2
The 'Microsoft network client: Digitally sign communications (always)' setting should be configured correctly.

CCE-10978-5
This policy setting determines if the server side SMB service is able to sign SMB packets if it is requested to do so by a client that attempts to establish a connection. If no signing request comes from the client, a connection will be allowed without a signature if the Microsoft network server: Di ...

CCE-11368-8
The "Require secure RPC communication" machine setting should be configured correctly.

CCE-10399-4
The 'Account lockout duration' setting should be configured correctly.

CCE-10009-9
The 'Domain member: Digitally sign secure channel data (when possible)' setting should be configured correctly.

CCE-10944-7
The 'Network access: Named Pipes that can be accessed anonymously' setting should be configured correctly.

CCE-10810-0
The 'Interactive logon: Do not require CTRL+ALT+DEL' setting should be configured correctly.

CCE-18808-6
The 'Require 128-bit encryption' option for the 'Network security: Minimum session security for NTLM SSP based (including secure RPC) clients' setting should be enabled or disabled as appropriate.

CCE-10027-1
The 'Network access: Do not allow anonymous enumeration of SAM accounts' setting should be configured correctly.

CCE-10821-7
The 'Network access: Shares that can be accessed anonymously' setting should be configured correctly.

CCE-10974-4
The 'Microsoft network client: Digitally sign communications (if server agrees)' setting should be configured correctly.

CCE-10297-0
The 'Network access: Let Everyone permissions apply to anonymous users' setting should be configured correctly.

CCE-10986-8
The 'System objects: Require case insensitivity for non-Windows subsystems' setting should be configured correctly.

CCE-10557-7
The 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' setting should be configured correctly.

CCE-11059-3
The 'Reset account lockout counter after' setting should be configured correctly.

CCE-10112-1
The 'Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings' setting should be configured correctly.

CCE-10930-6
The 'Interactive logon: Prompt user to change password before expiration' setting should be configured correctly.

CCE-10903-3
The 'Domain member: Maximum machine account password age' setting should be configured correctly.

CCE-10614-6
The 'Network security: LDAP client signing requirements' setting should be configured correctly.

CCE-10541-1
The 'Domain member: Require strong (Windows 2000 or later) session key' setting should be configured correctly.

CCE-10838-1
The 'Microsoft network client: Send unencrypted password to third-party SMB servers' setting should be configured correctly.

CCE-10788-8
The 'Interactive logon: Do not display last user name' setting should be configured correctly.

CCE-10362-2
The 'Microsoft network server: Amount of idle time required before suspending session' setting should be configured correctly.

CPE    1
cpe:/o:microsoft:windows_server_2008:r2
*XCCDF
xccdf_org.secpod_benchmark_PCI_3_2_Windows_Server_2008_R2
OVAL    159
oval:org.secpod.oval:def:8738
oval:org.secpod.oval:def:8836
oval:org.secpod.oval:def:8839
oval:org.secpod.oval:def:8789
...

© SecPod Technologies