UCF STIG Viewer Logo

Win2k8 R2 Audit


Overview

Date Finding Count (45)
2013-06-10 CAT I (High): 0 CAT II (Med): 40 CAT III (Low): 5
STIG Description
The Windows Server 2008 R2 Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements were developed from DoD consensus, as well as the Windows Server 2008 R2 Security Guide and security templates published by Microsoft Corporation. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.letterkenny.FSO.mbx.stig-customer-support-mailbox@mail.mil.

Available Profiles



Findings (MAC Audit and Audit Log Checks)

Finding ID Severity Title
V-26553 Medium The system will be configured to audit "System -> Security State Change" successes.
V-1080 Medium The file system must be audited for failed access attempts.
V-26582 Medium The System event log will be configured to a minimum size requirement.
V-26581 Medium The Setup event log will be configured to a minimum size requirement.
V-26580 Medium The Security event log will be configured to a minimum size requirement.
V-26529 Medium The system will be configured to audit "Account Logon -> Credential Validation" successes.
V-26538 Medium The system will be configured to audit "Account Management -> User Account Management" failures.
V-26539 Medium The system will be configured to audit "Detailed Tracking -> Process Creation" successes.
V-26533 Medium The system will be configured to audit "Account Management -> Other Account Management Events" successes.
V-26530 Medium The system will be configured to audit "Account Logon -> Credential Validation" failures.
V-26531 Medium The system will be configured to audit "Account Management -> Computer Account Management" successes.
V-26536 Medium The system will be configured to audit "Account Management -> Security Group Management" failures.
V-26537 Medium The system will be configured to audit "Account Management -> User Account Management" successes.
V-26534 Medium The system will be configured to audit "Account Management -> Other Account Management Events" failures.
V-26535 Medium The system will be configured to audit "Account Management -> Security Group Management" successes.
V-26532 Medium The system will be configured to audit "Account Management -> Computer Account Management" failures.
V-14230 Medium Audit policy using subcategories will be enabled.
V-26549 Medium The system will be configured to audit "Privilege Use -> Sensitive Privilege Use" successes.
V-26548 Medium The system will be configured to audit "Policy Change -> Authentication Policy Change" successes.
V-26547 Medium The system will be configured to audit "Policy Change -> Audit Policy Change" failures.
V-26546 Medium The system will be configured to audit "Policy Change -> Audit Policy Change" successes.
V-26545 Medium The system will be configured to audit "Object Access -> Registry" failures.
V-26544 Medium The system will be configured to audit "Object Access -> File System" failures.
V-26543 Medium The system will be configured to audit "Logon/Logoff -> Special Logon" successes.
V-26542 Medium The system will be configured to audit "Logon/Logoff -> Logon" failures.
V-26541 Medium The system will be configured to audit "Logon/Logoff -> Logon" successes.
V-26540 Medium The system will be configured to audit "Logon/Logoff -> Logoff" successes.
V-14228 Medium Audit Access to Global System Objects will be turned off.
V-14229 Medium Audit of Backup and Restore Privileges will be turned off.
V-26554 Medium The system will be configured to audit "System -> Security State Change" failures.
V-26556 Medium The system will be configured to audit "System -> Security System Extension" failures.
V-26557 Medium The system will be configured to audit "System -> System Integrity" successes.
V-26550 Medium The system will be configured to audit "Privilege Use -> Sensitive Privilege Use" failures.
V-26551 Medium The system will be configured to audit "System -> IPSec Driver" successes.
V-26552 Medium The system will be configured to audit "System -> IPSec Driver" failures.
V-26579 Medium The Application event log will be configured to a minimum size requirement.
V-26558 Medium The system will be configured to audit "System -> System Integrity" failures.
V-26489 Medium Unauthorized accounts will not have the "Generate security audits" user right.
V-15715 Medium Windows Error Reporting to Microsoft will be disabled.
V-26555 Medium The system will be configured to audit "System -> Security System Extension" successes.
V-4108 Low The system will generate an audit event when the audit log reaches a percent full threshold.
V-15707 Low Remote Assistance log files will be generated.
V-15717 Low Additional data requests in response to Error Reporting will be declined.
V-14232 Low IPSec Exemptions will be limited.
V-15714 Low Error Reporting events will be logged in the system event log.