1. Home
  2. Security Hardening
  3. DISA MS Windows Privileged Access Workstation V2R1
  4. WPAW-00-000700 – The Windows PAW must be configured with a vendor-supported version of Windows 10 and applicable security patches that are DoD approved – ProductName

WPAW-00-000700 – The Windows PAW must be configured with a vendor-supported version of Windows 10 and applicable security patches that are DoD approved – ProductName

Details

Older versions of operating systems usually contain vulnerabilities that have been fixed in later released versions. In addition, most operating system patches contain fixes for recently discovered security vulnerabilities. Due to the highly privileged activities of a PAW, it must be maintained at the highest security posture possible and therefore must have one of the current vendor-supported operating system versions installed.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Install one of the current vendor-supported versions of Windows 10 on site PAWs, including the most recently released patches.

Note: There is no central list in the DoD of ‘approved’ operating system versions. The Microsoft website will list supported versions of Windows 10 and patches. If a STIG is available for one or more of the vendor-supported versions of Windows 10, the version can be considered to be DoD approved. Local AOs usually have implemented a procedure for testing Windows updates before they are deployed. Check with the local AO’s staff to determine the latest approved version of Windows 10.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles