[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit Policy: Policy Change: Authorization Policy Change

ID: oval:org.secpod.oval:def:18745Date: (C)2014-05-29   (M)2021-06-02
Class: COMPLIANCEFamily: windows




Auditing of Policy Change: Authorization Policy Change events on failure should be enabled or disabled as appropriate. This security policy setting determines whether the operating system generates audit events when the following changes are made to the authorization policy: Assigning or removing of user rights (privileges) such as SeCreateTokenPrivilege, except for the system access rights that are audited by using the Audit Authentication Policy Change subcategory. Changing the Encrypting File System (EFS) policy. If this policy setting is configured, the following events are generated. The events appear on computers running Windows Server 2008 R2, Windows Server 2008, Windows 7, or Windows Vista. Fix: (1) GPO: Commandline: auditpol.exe (2) REG: NO INFO

Platform:
Microsoft Windows Server 2008 R2
Reference:
CCE-10132-9
CPE    1
cpe:/o:microsoft:windows_server_2008:r2
CCE    1
CCE-10132-9

© SecPod Technologies