Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36663 | WN12-00-000002-01 | SV-51573r1_rule | ECLP-1 | Medium |
Description |
---|
A system's BIOS or system controller handles the initial startup of a system, and its configuration must be protected from unauthorized modification. When the BIOS or system controller supports the creation of user accounts or passwords, such protections must be used and accounts/passwords only assigned to system administrators. Failure to protect BIOS or system controller settings could result in Denial of Service or compromise of the system resulting from unauthorized configuration changes. |
STIG | Date |
---|---|
Windows Server 2012 Member Server Security Technical Implementation Guide | 2014-01-07 |
Check Text ( C-46836r3_chk ) |
---|
Verify a supervisor or administrator password is set in the BIOS or system controller. If a password is not configured, this is a finding. |
Fix Text (F-44702r3_fix) |
---|
Access the system's BIOS or system controller. Configure a supervisor/administrator password. |