UCF STIG Viewer Logo

System pagefile is cleared upon shutdown.


Overview

Finding ID Version Rule ID IA Controls Severity
V-1084 3.003 SV-28975r1_rule Low
Description
This check verifies that Windows is not configured to wipe clean the system page file during a controlled system shutdown.
STIG Date
Windows Vista Security Technical Implementation Guide 2017-01-30

Details

Check Text ( C-41r1_chk )
Analyze the system using the Security Configuration and Analysis snap-in.
Expand the Security Configuration and Analysis tree view.
Navigate to Local Policies -> Security Options.

If the value for “Shutdown: Clear virtual memory pagefile” is not set to “Disabled”, then this is a finding.

The policy referenced configures the following registry value:

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Control\Session Manager\Memory Management\

Value Name: ClearPageFileAtShutdown

Value Type: REG_DWORD
Value: 0

Fix Text (F-6897r1_fix)
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “Shutdown: Clear virtual memory pagefile” to “Disabled”.