UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Anonymous access to the event logs is not restricted.


Overview

Finding ID Version Rule ID IA Controls Severity
V-1095 3.021 SV-29635r1_rule ECTP-1 Medium
Description
By default, the Windows event logs may be viewed over the network by an anonymous user. This method of access over the network is communicating through the Server service which has SYSTEM access to the actual log files.
STIG Date
Windows 2003 Domain Controller Security Technical Implementation Guide 2015-03-09

Details

Check Text ( C-72r1_chk )
Analyze the system using the Security Configuration and Analysis snap-in.
Expand the Security Configuration and Analysis tree view.
Navigate to Event Logs -> Settings for Event Logs.

If the value for “Prevent local guests group from accessing application log” is not set to “Enabled”, then this is a finding.

If the value for “Prevent local guests group from accessing security log” is not set to “Enabled”, then this is a finding.

If the value for “Prevent local guests group from accessing system log” is not set to “Enabled”, then this is a finding.

Fix Text (F-84r1_fix)
Configure the system to prevent guest access to the Event logs.