erds:local_system_settings
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revision | |||
erds:local_system_settings [2019/01/15 19:17] – administrator | erds:local_system_settings [2019/01/16 22:29] (current) – removed administrator | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | Path: Control Panel\Administrative Tools\Local Security Policy\Account Policies\Password Policy | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | Enforce password history | 5 | | ||
- | | Maximum password age | 30 | | ||
- | | Minimum password age | 1 | | ||
- | | Minimum password length | 8 | | ||
- | | Password must meet complexity requirements | Enabled | | ||
- | | Store passwords using reversible encryption | Disabled | | ||
- | |||
- | |||
- | Path: Control Panel\Administrative Tools\Local Security Policy\Account Policies\Account Lockout Policy | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | Account lockout duration | 60 mins | | ||
- | | Account lockout threshold | 3 invalid logon attempts | | ||
- | | Reset account lockout counter after | 60 mins | | ||
- | |||
- | |||
- | Path: Control Panel\Administrative Tools\Local Security Policy\Local Policies\Audit Policy | ||
- | |||
- | |||
- | * Select all items for audit of success and failure. | ||
- | |||
- | |||
- | Path: Control Panel\Administrative Tools\Local Security Policy\Local Policies\Security Options | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | Accounts: | ||
- | | Accounts: | ||
- | | Accounts: | ||
- | |||
- | |||
- | Path (Win10): Control Panel\System and Security\Windows Defender Firewall\Customize Settings | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | Private network settings | Turn on Windows Defender Firewall | | ||
- | | Public network settings | Turn on Windows Defender Firewall | | ||
- | |||
- | |||
- | Path (Win7): Control Panel\System and Security\Windows Firewall\Customize Settings | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | Private network settings | Turn on Windows Firewall | | ||
- | | Public network settings | Turn on Windows Firewall | | ||
- | |||
- | |||
- | **Note:** CeRTNA does not require any custom firewall rules to be applied. The only requirement is that a local workstation based firewall is enabled with the default settings. Organizations that have a product like Symantec Endpoint Protection will use the Symantec Endpoint Protection firewall, which will disable the Windows Firewall. Regardless of the local firewall that is used, you will need to show the auditor that the firewall for private and public networks is enabled. | ||
- | |||
- | |||
- | Path (Win10): | ||
- | |||
- | |||
- | By default Windows 10 Updates are enabled. | ||
- | Verify the Windows Update History to show that the updates are being applied. | ||
- | |||
- | |||
- | Path (Win7): | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | Install updates automatically | Selected | | ||
- | | Install new updates every day | Selected | | ||
- | | Allow all users to install updates on this computer | Selected | | ||
- | |||
- | |||
- | Control Panel\All Control Panel Items\Power Options\System Settings | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | Require a password on wakeup | Selected | | ||
- | |||
- | |||
- | Path (Win10): | ||
- | |||
- | |||
- | {{tablelayout? | ||
- | ^ Setting ^ Value ^ | ||
- | | On resume, display logon screen | Enabled | | ||
- | |||
erds/local_system_settings.1547579878.txt.gz · Last modified: by administrator