Shared user accounts are permitted on the system. Details Shared accounts do not provide individual accountability for system access and resource usage. Solution Remove any shared accounts that...
Standard user accounts must only have Read permissions to the Winlogon registry key. Details Permissions on the Winlogon registry key must only allow privileged accounts to change registry values. If standard users have...
System Information backups are not created, updated, and protected according to DISA requirements. Details Recovery of a damaged or compromised system in a timely basis is difficult without a system information backup. A...
System pagefile is cleared upon shutdown. Details This check verifies that Windows is not configured to wipe clean the system page file during a controlled system...
Systems must be at supported service packs (SP) or releases levels. Details Systems at unsupported service packs or releases will not receive security updates for new vulnerabilities and leaves them subject...
the built-in Windows password complexity Policy must be enabled. Details The use of complex passwords increases their strength against attack. The built-in Windows password complexity policy requires passwords to...
the computer account password is prevented from being reset. Details As a part of Windows security, computer account passwords are changed automatically. Enabling this policy to disable automatic password...
the default permissions of Global System objects are not increased. Details Windows system maintains a global list of shared system resources such as DOS device names, mutexes, and semaphores. Each...
the Recovery console option is Set to permit Automatic logon to the system. Details This is a Category 1 finding because if this option is set, the Recovery Console does not require you...
the Recovery console Set command must be Disabled. Details The Recovery Console SET command allows environment variables to be set in the Recovery Console. This permits access to...