Site Tools


guides:local_system_settings

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
guides:local_system_settings [2019/01/16 22:28] – created administratorguides:local_system_settings [2023/07/11 01:24] (current) brett.zamora
Line 1: Line 1:
-Path: Control Panel\Administrative Tools\Local Security Policy\Account Policies\Password Policy+Please Note: The following settings are just recommendations from CeRTNA. If your organizational policy uses slightly different settings, the security auditor will accept your settings as long as they are deemed to be reasonable and secure. 
 + 
 +**Path (Windows 10):** Control Panel\Administrative Tools\Local Security Policy\Account Policies\Password Policy \\ 
 +**Path (Windows 11):** Control Panel\Windows Tools\Local Security Policy\Account Policies\Password Policy
  
  
Line 12: Line 15:
  
  
-Path: Control Panel\Administrative Tools\Local Security Policy\Account Policies\Account Lockout Policy+**Path (Windows 10):** Control Panel\Administrative Tools\Local Security Policy\Account Policies\Account Lockout Policy \\  
 +**Path (Windows 11):** Control Panel\Windows Tools\Local Security Policy\Account Policies\Account Lockout Policy
  
  
Line 22: Line 26:
  
  
-Path: Control Panel\Administrative Tools\Local Security Policy\Local Policies\Audit Policy+**Path (Windows 10):** Control Panel\Administrative Tools\Local Security Policy\Local Policies\Audit Policy \\  
 +**Path (Windows 11):** Control Panel\Windows Tools\Local Security Policy\Local Policies\Audit Policy
  
  
Line 28: Line 33:
  
  
-Path: Control Panel\Administrative Tools\Local Security Policy\Local Policies\Security Options  (s=+**Path (Windows 10):** Control Panel\Administrative Tools\Local Security Policy\Local Policies\Security Options \\  
 +**Path (Windows 11):** Control Panel\Windows Tools\Local Security Policy\Local Policies\Security Options
  
  
Line 38: Line 44:
  
  
-Path (Win10): Control Panel\System and Security\Windows Defender Firewall\Customize Settings  (See note) +**Path (Win10):** Control Panel\System and Security\Windows Defender Firewall\Customize Settings  (See note) \\  
 +**Path (Win11):** Control Panel\System\Privacy & security\Windows Security
  
 {{tablelayout?colwidth="300px,300px"&rowsFixed=1&rowsVisible=10&float=center}} {{tablelayout?colwidth="300px,300px"&rowsFixed=1&rowsVisible=10&float=center}}
Line 45: Line 51:
 | Private network settings | Turn on Windows Defender Firewall | | Private network settings | Turn on Windows Defender Firewall |
 | Public network settings | Turn on Windows Defender Firewall | | Public network settings | Turn on Windows Defender Firewall |
- 
- 
-Path (Win7): Control Panel\System and Security\Windows Firewall\Customize Settings  (See note) 
  
  
Line 58: Line 61:
 **Note:** CeRTNA does not require any custom firewall rules to be applied. The only requirement is that a local workstation based firewall is enabled with the default settings. Organizations that have a product like Symantec Endpoint Protection will use the Symantec Endpoint Protection firewall, which will disable the Windows Firewall. Regardless of the local firewall that is used, you will need to show the auditor that the firewall for private and public networks is enabled. **Note:** CeRTNA does not require any custom firewall rules to be applied. The only requirement is that a local workstation based firewall is enabled with the default settings. Organizations that have a product like Symantec Endpoint Protection will use the Symantec Endpoint Protection firewall, which will disable the Windows Firewall. Regardless of the local firewall that is used, you will need to show the auditor that the firewall for private and public networks is enabled.
  
 +**Path (Windows 10):** Control Panel\System\Windows Update \\ 
 +**Path (Windows 11):** Control Panel\System\Windows Update
  
-Path (Win10):System\Windows Update +By default Windows 10/11 Updates are enabled.
- +
- +
-By default Windows 10 Updates are enabled.+
 Verify the Windows Update History to show that the updates are being applied. Verify the Windows Update History to show that the updates are being applied.
- 
- 
-Path (Win7):System\Windows Update 
- 
- 
-{{tablelayout?colwidth="300px,300px"&rowsFixed=1&rowsVisible=10&float=center}} 
-^ Setting ^ Value ^ 
-| Install updates automatically | Selected | 
-| Install new updates every day | Selected | 
-| Allow all users to install updates on this computer | Selected | 
  
  
Line 84: Line 76:
  
  
-Path (Win10):Settings\Lock Screen\Screen saver settings+**Path (Windows 10):** Control Panel\Settings\Lock Screen\Screen saver settings \\  
 +**Path (Windows 11):** Control Panel\System\Personalization\Lock Screen
  
  
guides/local_system_settings.1547677686.txt.gz · Last modified: by administrator