UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The file system must be audited for failed access attempts.


Overview

Finding ID Version Rule ID IA Controls Severity
V-1080 2.007 SV-32247r2_rule ECAR-1 ECAR-3 ECAR-2 Medium
Description
Improper modification of system files can have a significant impact on the security configuration of a system as well as potentially rendering a system inoperable. Failed access attempts may indicate an attack on a system. Auditing for failed access attempts provides an indicator of such attempts and a method of determining responsible parties.
STIG Date
Windows Server 2008 R2 Domain Controller Security Technical Implementation Guide 2014-04-08

Details

Check Text ( None )
None
Fix Text (F-43217r1_fix)
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Global Object Access Auditing -> "File system" to audit the "Everyone" group for all "Failed" categories.