Attachment_7_-_USGCB-Windows-Settings.xls

XLS spreadsheet 558 KB Posted

Attached to
Automated Palletizing Systems Federal contract opportunity
Solicitation number
BEP-RFP-16-0433
Issued by
Department of the Treasury Office of the Comptroller of the Currency

About this file

Attachment 7 - USGCB-Windows-Settings

View the file

Other files for this federal contract opportunity

Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Table of Contents

USGCB Settings
This spreadsheet captures the USGCB defined configuration settings.
Tab NameTab Description
Revision HistoryTab capturing information relating to the revisions of this spreadsheet.
Windows SettingsTab capturing the USGCB settings for Windows 7, Windows Vista, and Windows XP. These settings are the same for both x86 and x64 architectures.
Internet Explorer SettingsTab capturing the USGCB settings for Internet Explorer 8 and Internet Explorer 7.

Revision History Windows Settings Internet Explorer Settings

Revision History

2010.04.23alpha release
All TabsInitial release of USGCB Content.
2010.05.19Win7 and Win7 Firewall settings and IE8 Settings tabs, enabled text wrapping, resized columns, resorted by Policy Path column
Win7 and Win7 Firewall settings, capitalized 's' in 'settings'
NOTE: 800-53 mappings added to setting tabs, these will be removed once XML versions of mappings are available.
2010.08.27Beta release
All TabsCorrected minor typographical errors.
All TabsAdded a 'Category' column where some settings are specified as being 'pending' or 'conditional.' Pending settings are settings that are currently optional but will become mandatory in the future. Conditional settings are settings that are mandatory in most situations, however under specific conditions agencies may adjust those settings. For example, the IPv6 transitional technologies are disabled in the USGCB, but agencies that are using IPv6 may enable one or more of these transitional technologies if necessary. The current SCAP 1.0 content does not support conditional logic therefor agencies must manually track these as deviations, in the future SCP 1.1 content will support conditional logic.
All TabsFormatted content as a table to facilitate sorting by columns.
CCEPathNameUSGCB Alpha ValueUSGCB Beta ValueComments
Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Inbound RulesCore Networking - Dynamic Host Configuration Protocol (DHCP-In)Enabled - yesTo allow the client to receive DHCP responses that would otherwise be blocked by CCE-9069-6.
Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Inbound RulesCore Networking - Dynamic Host Configuration Protocol (DHCPV6-In)Enabled - yesTo allow the client to receive DHCP responses that would otherwise be blocked by CCE-9069-6.
CCE-8583-7Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsInteractive Logon: message text for users attempting to log onThis system is for the use of authorized users only. Individuals using this computer system without authority or in excess of their authority are subject to having all their activities on this system monitored and recorded by system personnel. Anyone using this system expressly consents to such monitoring and is advised that if such monitoring reveals possible evidence of criminal activity system personal may provide the evidence of such monitoring to law enforcement officials.This system is for the use of authorized users only. Individuals using this computer system without authority or in excess of their authority are subject to having all their activities on this system monitored and recorded by system personnel. Anyone using this system expressly consents to such monitoring and is advised that if such monitoring reveals possible evidence of criminal activity system personal may provide the evidence of such monitoring to law enforcement officials.Fix mis-spelling in spreadsheet.

Add language to the spreadsheet to allow flexibility for settings such as this.

CCE-8583-7Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights AssignmentDebug programs(None)AdministratorsAdd 'Administrators' group in order to allow the use of legitimate management tools.
CCE-10658-3User Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication SettingsTurn off handwriting personalization data sharingEnabledNot ConfiguredChange to the machine setting, CCE-10645-0.
CCE-10645-0Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication SettingsTurn off handwriting personalization data sharingNot ConfiguredEnabled
CCE-8813-8Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsUser Account Control: Behavior of the elevation prompt for standard usersPrompt for credentialsPrompt for credentials on the secure desktopTo reduce the risk of malware tricking an administrator into entering their credentials at a false UAC prompt.
CCE-10266-5Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition Technologies6to4 StateEnabled: Disabled StateConditionalIf they use IPv6 and require this transitional technology
CCE-10764-9Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition TechnologiesIP-HTTPS StateEnabled: Disabled StateConditionalIf they use IPv6 and require this transitional technology
CCE-10130-3Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition TechnologiesISATAP StateEnabled: Disabled StateConditionalIf they use IPv6 and require this transitional technology
CCE-10011-5Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition TechnologiesTeredo StateEnabled: Disabled StateConditionalIf they use IPv6 and require this transitional technology
CCE-10441-4Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Windows Error ReportingEnabledConditionalAllow for internal error collection. Deny for Microsoft error collection.
CCE-9960-6Computer Configuration\Administrative Templates\System\Remote AssistanceOffer Remote AssistanceDisabledConditionalIf RDS is used by help desk, then allow. The end user shouldn't be able to do this.
CCE-9506-7Computer Configuration\Administrative Templates\System\Remote AssistanceSolicited Remote AssistanceDisabledConditionalIf RDS is used by help desk, then allow. The end user shouldn't be able to do this.
CCE-9985-3Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\ConnectionsAllow users to connect remotely using Remote Desktop ServicesDisabledConditionalApplicable to those using RDS
CCE-10608-8Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Session Time LimitsSet time limit for active but idle Remote Desktop Services sessionsEnabled: 15 minutesConditionalThis setting is mandated by SP 800-53 requirements for network timeouts. Agencies should only adjust it on systems that require a longer timeout
CCE-9403-7Computer Configuration\Administrative Templates\Windows Components\Windows UpdateConfigure Automatic UpdatesEnabled: 3 - Auto download and notify for installConditionalAdd language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management.
CCE-9464-9Computer Configuration\Administrative Templates\Windows Components\Windows UpdateDo not display 'Install Updates and Shut Down' option in Shut Down Windows dialog boxDisabledConditionalSoftware distribution should be centrally managed, only administrators and enterprise management tools should be able to install updates. However, Add language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management.
CCE-9672-7Computer Configuration\Administrative Templates\Windows Components\Windows UpdateNo auto-restart with logged on users for scheduled automatic updates installationsDisabledConditionalAdd language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management.
CCE-10205-3Computer Configuration\Administrative Templates\Windows Components\Windows UpdateReschedule Automatic Updates scheduled installationsEnabledConditionalSoftware distribution should be centrally managed, only administrators and enterprise management tools should be able to determine when updates are installed. However, Add language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management.
CCE-9301-3Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsUser Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktopDisabledConditionalIf agencies use remote assistance then they can reconfigure this setting. This setting was added to Windows Vista SP1 specifically to enable Remote Assistance. It allows certain applications stored in secure folders, such as system32, to bypass the secure desktop so that they can function as designed. Enabling this setting will lower security slightly but enable Remote Assistance. For more information see http://technet.microsoft.com/en-us/library/dd835564(WS.10).aspx.
CCE-9253-6Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights AssignmentAccess this computer from the networkAdministratorsConditionalAdd information to the settings spreadsheet explaining how IPsec including many VPN solutions are impacted and that agencies can grant this user right to the built-in 'Users' group or they could implement a more precise solution by creating a group for IPsec and adding the affected accounts to it.

DoD: won't change

CCE-10661-7Computer Configuration\Windows Settings\Security Settings\System ServicesBluetooth Support ServiceDisabledConditionalOrganizations can enable this service if they want to allow the use of Bluetooth devices.
CCE-9419-3Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights AssignmentProfile system performanceAdministrators, NT SERVICE\WdiServiceHostAdministrators, NT SERVICE\WdiServiceHostAdded reference to KB article KB974639 to the spreadsheet, this includes a patch for win7 to address the problem raised by some agencies.
Computer Configuration\Administrative Templates\System\Power Management\Sleep SettingsSpecify the System Hibernate Timeout (On Battery)Not specifiedPending, 3600 secondsIn support of administration efforts to reduce the use of electricity by inactive computers. This setting may impact the ability of enterprise management tools to push patches and configuration changes to managed computers therefor organizations should research the power management features of Windows and the capabilities of their management tools to leverage Wake-on-LAN and other features to remotely administer computers.
Computer Configuration\Administrative Templates\System\Power Management\Sleep SettingsSpecify the System Hibernate Timeout (Plugged In)Not specifiedPending, 3600 secondsIn support of administration efforts to reduce the use of electricity by inactive computers. This setting may impact the ability of enterprise management tools to push patches and configuration changes to managed computers therefor organizations should research the power management features of Windows and the capabilities of their management tools to leverage Wake-on-LAN and other features to remotely administer computers.
Computer Configuration\Administrative Templates\System\Power Management\Video and Display SettingsTurn off the Display (On Battery)Not specifiedPending, 1200 secondsIn support of administration efforts to reduce the use of electricity by inactive computers.
Computer Configuration\Administrative Templates\System\Power Management\Video and Display SettingsTurn off the Display (Plugged In)Not specifiedPending, 1200 secondsIn support of administration efforts to reduce the use of electricity by inactive computers.
CCE-10092-5Computer Configuration\Administrative Templates\Windows Components\Credential User InterfaceRequire trusted path for credential entryEnabledRemoveThis adds 2 additional steps for each elevation prompt, the threats related to this setting are mitigated by the value now required by the "User Account Control: Behavior of the elevation prompt for standard users" the USGCB will prompt for credentials on the secure desktop for standard users but not for admins.
CCE-10694-8Computer Configuration\Administrative Templates\System\Driver InstallationTurn off Windows Update device driver search promptEnabledRemoveAllow organizations to define this policy setting.
CCE-10681-5Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Automatic Root Certificates UpdateEnabledRemoveAllow organizations to define this policy setting.
CCE-10093-3Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Windows Update device driver searchingEnabledRemoveAllow organizations to define this policy setting.
CCE-9983-8Computer Configuration\Administrative Templates\System\LogonDo not process the legacy run listEnabledRemoveThis setting will be added in the future, application developers are encouraged to find alternative methods for automatically launching components during the boot and logon processes.
CCE-10540-3Computer Configuration\Administrative Templates\Windows Components\Internet ExplorerTurn off Managing Phishing filterEnabled:OffRemoveNot applicable to IE8.
CCE-9987-9Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Automatic Install of Internet Explorer componentsEnabledRemoveNot applicable to IE8.
CCE-10634-4Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Periodic Check for Internet Explorer software updatesEnabledRemoveNot applicable to IE8.
CCE-10632-8Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable showing the splash screenEnabledRemoveNot applicable to IE8.
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites ZoneAllow status bar updates via scriptDisabledRemoveAllow organizations to define this policy setting.
CCE-10007-3Computer Configuration\Administrative Templates\Windows Components\RSS FeedsTurn on Basic feed authentication over HTTPEnabledRemoveRequired setting less secure than default
CCE-8868-2Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsDevices: Allowed to format and eject removable mediaAdministrators, Interactive UsersRemoveThe current requires the weakest configuration so there's no reason to include it.
CCE-8784-1Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsMSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames (recommended)EnabledRemoveRemoved due to application compatibility issues
CCE-10844-9Computer Configuration\Windows Settings\Security Settings\System ServicesWLAN AutoConfigDisabledRemoveAllow organizations to define this policy setting.
CCE-10207-9Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Outbound RulesIPv6 Block of Protocols 41General: Enabled and Block the connections; Programs and Services: All programs that meet the specified conditions; Protocols and Ports: Protocols type IPv6; Scope: Any IP addresses; Advanced: All profilesRemoveRedundant
CCE-10488-5Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Outbound RulesIPv6 Block of UDP 3544General: Enabled and Block the connections; Programs and Services: All programs that meet the specified conditions; Protocols and Ports: Protocols type UDP, Local port 3544, Remote port All Ports ; Scope: Any IP addresses; Advanced: All profilesRemoveRedundant
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip6\Parameters\DisableComponentsDisable ISATAP, Teredo, and 6to4 tunneling protocolsEnabledRemoveNot applicable
User Configuration\Administrative Templates\Windows Components\Internet ExplorerConfigure Outlook ExpressNot definedRemoveNot applicable to IE8.
User Configuration\Administrative Templates\Windows Components\Internet ExplorerDisable the Reset Web Settings featureNot definedRemoveNot applicable to IE8.
User Configuration\Administrative Templates\Windows Components\Internet ExplorerTurn on the Internet Connection Wizard Auto DetectDisabledRemoveNot applicable to IE8.
Computer Configuration\Administrative Templates\Network\Network ConnectionsProhibit use of Internet Connection Firewall on your DNS domain networkEnabledRemoveNot applicable
CCE-9797-2Computer Configuration\Administrative Templates\Network\Network ConnectionsProhibit use of Internet Connection Sharing on your DNS domain networkEnabledRemoveNot applicable
User Configuration\Administrative Templates\System\Power ManagementPrompt for password on resume from hibernate / suspendEnabledRemoveNot applicable
2010.09.271.0 Release
Corrected policy path for features that should not be installed, since these are not controlled through group policy the path now points to the location within Control Panel.
Control Panel\Programs and Features\Turn Windows features on or offInternet Information ServicesNot installedUpdated registry info to HKLM\SYSTEM\CurrentControlSet\Services\W3Svc\DisplayName
Control Panel\Programs and Features\Turn Windows features on or offSimple TCP ServicesNot installedUpdated registry info to HKLM\SYSTEM\CurrentControlSet\Services\SimpTCP\DisplayName
Computer Configuration\Administrative Templates\System\Power Management\Sleep SettingsSpecify the System Hibernate Timeout (On Battery)Enabled:3600Removed pending category
Computer Configuration\Administrative Templates\System\Power Management\Sleep SettingsSpecify the System Hibernate Timeout (Plugged In)Enabled:3600Removed pending category
Computer Configuration\Administrative Templates\System\Power Management\Video and Display SettingsTurn off the Display (On Battery)Enabled:1200Removed pending category
Computer Configuration\Administrative Templates\System\Power Management\Video and Display SettingsTurn off the Display (Plugged In)Enabled:1200Removed pending category
2010.11.161.0 Release
Win7 and Win7 Firewall settings tabCorrected minor typographical errors.
2011.1.311.1 Release
IE8 settings tabCorrected minor typographical errors and updated the following CCE IDs.
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime HandlingCCE-10138-6
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety FeatureCCE-10635-1
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security RestrictionCCE-10265-7
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone ElevationCCE-10574-2
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX InstallCCE-10405-9
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File DownloadCCE-10578-3
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security RestrictionsCCE-10604-7
Computer Configuration\Administrative Templates\Windows Components\Internet ExplorerMake proxy settings per-machine (rather than per-user)CCE-9870-7
Win7 and Win7 Firewall settings tabCorrected minor typographical errors and updated the following CCE IDs.
Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Global Object Access AuditingAudit File SystemCCE-9811-1_CCE-9217-1.
Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Global Object Access AuditingAudit RegistryCCE-10078-4_CCE-9737-8.
Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Logon/LogoffAudit IPsec Main ModeCCE-9715-4_CCE-8956-5
CCE-10658-3Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off handwriting personalization data sharingEnabledAdded this setting that was mistakenly deleted during the Beta review period
2011.6.211.2 Beta Release
IE settings tabFDCC settings that have not been carried forward to the USGCB baselines.
User Configuration\Administrative Templates\Windows Components\Internet ExplorerConfigure Outlook ExpressCCE-3275-5CCE-3275-5Not applicable to IE7 or later.
User Configuration\Administrative Templates\Windows Components\Internet ExplorerDisable the Reset Web Settings featureCCE-4226-7CCE-4226-7Not applicable to IE7 or later.
User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced Settings\Internet Connection Wizard SettingsTurn on the Internet Connection Wizard Auto DetectCCE-4036-0CCE-4036-0Not applicable to IE, nor Windows Vista or later.
Computer Configuration\Administrative Templates\Windows Components\Internet ExplorerDisable Automatic Install of Internet Explorer componentsCCE-3518-8CCE-3518-8Not applicable to IE7 or later.
Computer Configuration\Administrative Templates\Windows Components\Internet ExplorerDisable Periodic Check for Internet Explorer software updatesCCE-3576-6CCE-3576-6Not applicable to IE7 or later.
Computer Configuration\Administrative Templates\Windows Components\Internet ExplorerDisable showing the splash screenCCE-3706-9CCE-3706-9Not applicable to IE7 or later.
Computer Configuration\Administrative Templates\Windows Components\Internet ExplorerDisable software update shell notifications on program launchCCE-4118-6CCE-4118-6Not applicable to IE7 or later.
Added columns to document the Internet Explorer setting values and CCE-IDs.
Added a comment column to provide information about changes made in order to better align the settings across each version of Internet Explorer.
Windows settings tabFDCC settings that have not been carried forward to the USGCB baselines.
Computer Configuration\Administrative Templates\Windows Components\Internet Information ServicesPrevent IIS installationCCE-3288-8CCE-4262-2Only applicable to Windows Server 2003.
Computer Configuration\Administrative Templates\Windows Components\Online AssistanceTurn off Untrusted ContentCCE-3046-0(Not Applicable)Its not present in the Windows 7 baseline and it is not applicable to XP.
Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Device and Resource RedirectionDo not allow drive redirectionCCE-2874-6(Not Applicable)Its not present in the Windows 7 baseline.
Computer Configuration\Administrative Templates\Windows Components\Windows Meeting SpaceTurn off Windows Meeting SpaceCCE-2557-7(Not Applicable)Its not present in the Windows 7 baseline.
Computer Configuration\Administrative Templates\Windows Components\Windows MessengerDo not allow Windows Messenger to be run(Not Applicable)CCE-2684-9Its not present in the Windows 7 baseline.
Computer Configuration\Administrative Templates\Windows Components\Windows MessengerDo not automatically start Windows Messenger initiallyCCE-4797-7CCE-2455-4Its not present in the Windows 7 baseline.
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsAudit: Shut down system immediately if unable to log security auditsCCE-3001-5CCE-2851-4Its not present in the Windows 7 baseline.
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsDevices: Allowed to format and eject removable mediaCCE-3225-0CCE-3111-2Its not present in the Windows 7 baseline.
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security OptionsMSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames (recommended)CCE-3244-1CCE-2683-1Its not present in the Windows 7 baseline.
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights AssignmentSynchronize directory service dataCCE-4970-0CCE-2810-0Its not applicable to any of the client operating systems, only domain controllers.
Computer Configuration\Windows Settings\Security Settings\System ServicesWLAN AutoConfigIts not present in the Windows 7 baseline.
User Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication SettingsTurn off Help Experience Improvement ProgramCCE-5239-9(Not Applicable)Its not present in the Windows 7 baseline.
User Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Help RatingsCCE-4851-2(Not Applicable)Its not present in the Windows 7 baseline.
User Configuration\Administrative Templates\System\Power ManagementPrompt for password on resume from hibernate / suspendCCE-3169-0CCE-4390-1Only applicable to Windows XP.
Computer Configuration\Administrative Templates\SystemTurn off Windows Update device driver search promptCCE-3278-9CCE-5014-6Its not present in the win7 baseline or the Microsoft baselines for either win7 or Vista.
Computer Configuration\Administrative Templates\System\Error ReportingDisplay Error Notification(Not Applicable)CCE-5136-7It was removed from Windows in Vista. Also, the USGCB settings were changed to allow agencies to use Error Reporting internally.
Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Automatic Root Certificates UpdateCCE-3454-6CCE-5054-2Previously removed from the USGCB.
Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Windows Movie Maker automatic codec downloadsCCE-3403-3CCE-4242-4This was never included in the USGCB, and it appears that it was removed from Windows 7.
Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Windows Movie Maker online Web linksCCE-3297-9CCE-4732-4This was never included in the USGCB, and it appears that it was removed from Windows 7.
Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Windows Movie Maker saving to online video hosting providerCCE-3385-2CCE-4997-3This was never included in the USGCB, and it appears that it was removed from Windows 7.
Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settingsTurn off Windows Update device driver searchingCCE-3278-9CCE-5014-6Previously removed from the USGCB.
Computer Configuration\Administrative Templates\System\LogonDon't display the Getting Started welcome screen at logonCCE-2781-3CCE-5160-7This only applied to Windows 2000.
Added columns to document the Windows XP and Windows Vista setting values and CCE-IDs.
Added a comment column to provide information about changes made in order to better align the settings across each version of Windows.
2011.8.261.2 / 2.0 Beta 2 release
Windows settings tabAdded CCE IDs for several settingsVista CCE IDXP CCE ID
Control Panel\Programs and Features\Turn Windows features on or offGamesCCE-18891-2CCE-18796-3
Control Panel\Programs and Features\Turn Windows features on or offInternet Information ServicesCCE-18279-0CCE-18870-6
Control Panel\Programs and Features\Turn Windows features on or offSimpleTCP ServicesCCE-18624-7CCE-18307-9
Control Panel\Programs and Features\Turn Windows features on or offTelnet ClientCCE-18129-7(Not Applicable)
Control Panel\Programs and Features\Turn Windows features on or offTelnet ServerCCE-18284-0(Not Applicable)
Control Panel\Programs and Features\Turn Windows features on or offTFTP ClientCCE-18700-5(Not Applicable)
Control Panel\Programs and Features\Turn Windows features on or offWindows Media CenterCCE-18689-0(Not Applicable)
2011.10.171.2 / 2.0 Release
Windows settings tabAdded details under the comments column about how the conditional logic has been implemented in the SCAP 1.2 content
2012.2.101.2 / 2.0 ReleaseWindows 7 CCE IDVista CCE ID
Removed "Security Require authentication" from the Impact statementCCE-14986-4CCE-18320-2
Removed "Security Require authentication" from the Impact statementCCE-14854-4(Not Applicable)
Corrected registry path information for the following settingsCCE-10502-3CCE-3260-7
CCE-10268-1CCE-3414-0
CCE-10022-2CCE-2533-8
CCE-9747-7CCE-3299-5
CCE-10215-2CCE-4597-1
CCE-10611-2CCE-4963-5
CCE-10386-1CCE-4206-9
CCE-10250-9CCE-4207-7
CCE-9749-3CCE-4507-0
CCE-9753-5CCE-5128-4
CCE-9926-7CCE-4639-1
CCE-10373-9CCE-4278-8
CCE-9540-6CCE-3292-0
CCE-8487-1CCE-2376-2
CCE-9764-2CCE-4866-0
Corrected the value for the IE7 setting "Do not allow users to enable or disable add-ons" so that it matches the value prescribed for IE8CCE-3744-0CCE-3744-0
Corrected the value for the IE7 setting "Automatic prompting for file downloads" so that it matches the value prescribed for IE8CCE-4053-5CCE-4053-5
2012.4.261.2 / 2.0 ReleaseUpdated column B on the Revision History tab to reflect that the current USGCB versions are 1.2 for Windows 7 and Internet Explorer 8 and 2.0 For Windows XP, Windows Vista, and Internet Explorer 7.
Corrected numerous typos in the Registry Info column of the Windows Settings tab, for example, ensured that the registry path and the registry value name are seperated by an exclamation mark, "!," rather than a slash.
2015.02.25WinXP-3.0.3.1-rc1.zip, WinXP-Firewall-2.1.0.1-rc1.zip, WinVista-3.0.5.1-rc1.zip, WinVista-Firewall-2.1.0.1-rc1.zip, Win7-2.0.5.1-rc1.zip, Win7-Firewall-1.3.0.1-rc1.zip, IE7-2.1.3.1-rc1.zip, IE8-1.3.3.1-rc1.zip
Added the following CCEs to spreadsheet:Windows XPIE8
CCE-2777-1CCE-9793-1
CCE-2336-6CCE-9832-7
CCE-3014-8CCE-10425-7
CCE-2810-0
Win 7Vista
CCE-12924-7CCE-18686-6
CCE-12393-5CCE-18303-8
Added two configutation settings for Windows Vista and 7 Energy data streams:
Specify the System Sleep Timeout (On Battery)
Specify the System Sleep Timeout (Plugged In)
Updated the SCAP 1.2 USGCB data streams as described in the change log.
2015.04.20Final Release: WinXP-3.0.3.1.zip, WinXP-Firewall-2.1.0.1.zip, WinVista-3.0.5.1.zip, WinVista-Firewall-2.1.0.1.zip, Win7-2.0.5.1.zip, Win7-Firewall-1.3.0.1.zip, IE7-2.1.3.1.zip, IE8-1.3.3.1.zip
Updated the SCAP 1.2 USGCB data streams as described in the change log.
2015.07.09Corrected a typo for CCE-5146-6, CCE-5036-9, and CCE-4811-6 in the Windows Settings worksheet.
2015.08.13Corrected the USGCB value for the 'Interactive logon: Smart card removal behavior' in the Windows Settings worksheet.

Windows Settings

CCE ID v5 Win7CCE ID v5 Win VistaCCE ID v5 Win XPCCE ID v4Policy PathPolicy Setting NameWindows 7 USGCB 1.2Windows Vista USGCB 2.0Windows XP USGCB 2.0RationaleImpactCategory800-53 MappingRegistry InfoComments
CCE-9783-2CCE-4992-4(Not Applicable)CCE-947Computer Configuration\Administrative Templates\Network\Link-Layer Topology DiscoveryTurn on Mapper I/O (LLTDIO) driverDisabledDisabled(Not Applicable)To prevent network traffic driven by the Link-Layer Topology Discovery feature.The computer will not be able to discover the network topology or make Quality-of-Service requests.CM-6 CM-7HKLM\Software\Policies\Microsoft\Windows\LLTD!EnableLLTDIO, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowLLTDIOOnDomain, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowLLTDIOOnPublicNet, HKLM\Software\Policies\Microsoft\Windows\LLTD!ProhibitLLTDIOOnPrivateNetNot applicable to XP.
CCE-10059-4CCE-4077-4(Not Applicable)CCE-1134Computer Configuration\Administrative Templates\Network\Link-Layer Topology DiscoveryTurn on Responder (RSPNDR) driverDisabledDisabled(Not Applicable)To prevent the computer from responding to Link-Layer Topology Discovery requests.The computer will not be able to support Link-Layer Topology Discovery requests.CM-6 CM-7HKLM\Software\Policies\Microsoft\Windows\LLTD!EnableRspndr, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowRspndrOnDomain, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowRspndrOnPublicNet, HKLM\Software\Policies\Microsoft\Windows\LLTD!ProhibitRspndrOnPrivateNetNot applicable to XP.
CCE-10438-0CCE-3270-6CCE-5194-6CCE-86Computer Configuration\Administrative Templates\Network\Microsoft Peer-to-Peer Networking ServicesTurn Off Microsoft Peer-to-Peer Networking ServicesEnabledEnabledEnabledTo prevent users from utilizing the P2P features included with Windows.Users will not be able to join P2P networks based on the P2P services available in Windows.CM-3 CM-7HKLM\Software\policies\Microsoft\Peernet!Disabled
CCE-9953-1CCE-4152-5CCE-2173-3CCE-896Computer Configuration\Administrative Templates\Network\Network ConnectionsProhibit installation and configuration of Network Bridge on your DNS domain networkEnabledEnabledEnabledTo prevent the computer from forwarding internal traffic to other networks.The computer will not be able to act as a layer 2 network bridge while connected to the corporate network.SC-7 SC-22HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_AllowNetBridge_NLA
(Not Applicable)CCE-5020-3CCE-5022-9CCE-241Computer Configuration\Administrative Templates\Network\Network ConnectionsProhibit use of Internet Connection Firewall on your DNS domain network(Not Applicable)(Not Applicable)EnabledProhibits use of Internet Connection Firewall on your DNS domain network.
Determines whether users can enable the Internet Connection Firewall feature on a connection, and if the Internet Connection Firewall service can run on a computer. Important: This setting is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer.If you enable this setting, Internet Connection Firewall cannot be enabled or configured by users (including administrators), and the Internet Connection Firewall service cannot run on the computer. The option to enable the Internet Connection Firewall through the Advanced tab is removed. In addition, the Internet Connection Firewall is not enabled for remote access connections created through the Make New Connection Wizard. The Network Setup Wizard is disabled.HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_PersonalFirewallConfigPrveviously this was 'enabled' on Vista however the setting is not applicable to Vista.
(Not Applicable)CCE-4078-2CCE-3026-2CCE-672Computer Configuration\Administrative Templates\Network\Network ConnectionsProhibit use of Internet Connection Sharing on your DNS domain network(Not Applicable)(Not Applicable)EnabledDetermines whether administrators can enable and configure the Internet Connection Sharing (ICS) feature of an Internet connection and if the ICS service can run on the computer. Important: This setting is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS domain network other than the one it was connected to when the setting was refreshed, this setting does not apply.If you enable this setting, ICS cannot be enabled or configured by administrators, and the ICS service cannot run on the computer. The Advanced tab in the Properties dialog box for a LAN or remote access connection is removed. The Internet Connection Sharing page is removed from the New Connection Wizard. The Network Setup Wizard is disabled.HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_ShowSharedAccessUIPrveviously this was 'enabled' on Vista however the setting is not applicable to Vista.
CCE-10359-8(Not Applicable)(Not Applicable)(Not Applicable)Computer Configuration\Administrative Templates\Network\Network ConnectionsRequire domain users to elevate when setting a network's locationEnabled(Not Applicable)(Not Applicable)To minimize the risk of users specifying the work location when connected to public networks because the public network is associated with the public firewall profile which has more restrictive settings than the domain firewall profile.Unprivileged users will not be able to change the network location.AC-2HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_StdDomainUserSetLocationNot applicable to Vista or XP.
CCE-10509-8(Not Applicable)(Not Applicable)(Not Applicable)Computer Configuration\Administrative Templates\Network\Network ConnectionsRoute all traffic through the internal networkEnabled: Enabled State(Not Applicable)(Not Applicable)To force all traffic from computers connected to the corporate network via a VPN to traverse the corporate network. This will ensure that the traffic can be managed and monitored.Remote users will have slower response times and possible less available bandwidth when connecting to servers located on the Internet. This setting will also increase the burden on VPN servers.AC-4HKLM\Software\Policies\Microsoft\Windows\TCPIP\v6Transition!Force_TunnelingNot applicable to Vista or XP.
(Not Applicable)CCE-3431-4CCE-3247-4CCE-555Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow file and printer sharing exception(Not Applicable)(Not Applicable)DisabledTo minimize the risk of an attacker using any of the affected protocols to exploit the computer.The ports for file and printer sharing are not opened. The shared files and printers on the computer will not be available from other computers.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint!RemoteAddressesNot applicable to Windows 7 or Vista.
(Not Applicable)(Not Applicable)CCE-3141-9CCE-277Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow ICMP exceptions(Not Applicable)(Not Applicable)Enabled: Allow inbound echo requestsThe Windows Firewall: Allow ICMP exceptions setting allows you to configure specific types of ICMP messages as excepted traffic.When Enabled, the specified unsolicited incoming ICMP traffic is allowed. When you select Enabled, you must also specify the specific types of ICMP messages that are allowed. Selecting Enabled overrides the local ICMP settings of Windows Firewall.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundDestinationUnreachable, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundSourceQuench, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowRedirect, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundEchoRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundRouterRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundTimeExceeded, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundParameterProblem, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundTimestampRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundMaskRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundPacketTooBigNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3180-7CCE-3258-1CCE-370Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow local port exceptions(Not Applicable)(Not Applicable)DisabledTo prevent users with administrative privileges from creating local rules that may lower the security of the firewall.Local administrators cannot add port exceptions.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts!AllowUserPrefMergeNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3405-8CCE-2828-2CCE-502Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow local program exceptions(Not Applicable)(Not Applicable)DisabledTo prevent users with administrative privileges from creating local rules that may lower the security of the firewall.Local administrators cannot add program exceptions.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications!AllowUserPrefMergeNot applicable to Windows 7 or Vista.
(Not Applicable)(Not Applicable)CCE-2965-2, CCE-3090-8, CCE-2923-1, CCE-2958-7CCE-251, CCE-617, CCE-793, CCE-57Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow logging(Not Applicable)(Not Applicable)Enabled: Log dropped packets,Log successful connections,Log file path and name:%systemroot%\domainfw.log,size limit:16384To facilitate determination of the root cause of system problems or to detect unauthorized activities.Logging is enabled with the specified log file settings.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogDroppedPackets, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogSuccessfulConnections, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogFilePath, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogFileSizeNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3158-3CCE-2476-0CCE-771Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow remote administration exception(Not Applicable)(Not Applicable)EnabledTo allow remote administration when the computer is connected to the corporate network.Windows Firewall allows the computer to receive the unsolicited incoming messages associated with remote administration. In Allow unsolicited incoming messages from, type * to specify traffic originating from any source IPv4 address or a comma-separated list of sources. The sources can be LocalSubnet to specify traffic originating from a directly reachable IPv4 address or one or more IPv4 addresses or IPv4 address ranges separated by commas.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings!RemoteAddressesNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3458-7CCE-3304-3CCE-832Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow Remote Desktop exception(Not Applicable)(Not Applicable)EnabledTo allow RDP when the computer is connected to the corporate network.Remote Desktop connections are allowed. TCP port 3389 is opened. In Allow unsolicited incoming messages from, type * to specify Remote Desktop traffic originating from any source IPv4 address or a comma separated list of sources.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop!RemoteAddressesNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-2964-5CCE-3176-5CCE-590Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Allow UPnP framework exception(Not Applicable)(Not Applicable)DisabledTo minimize the risk of an attacker using UPnP traffic to deliver malicious payloads.The ports for UPnP traffic are not opened, which prevents the computer from receiving unsolicited incoming UPnP messages. Local administrators cannot configure the pre-defined UPnP Framework exception.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\UPnPFramework!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\UPnPFramework!RemoteAddressesNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3365-4CCE-3198-9CCE-762Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Prohibit notifications(Not Applicable)(Not Applicable)DisabledTo alert the user of applications that attempt to open inbound network ports.Users will see a notification when a program is blocked from receiving inbound connections in this firewall profile.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile!DisableNotificationsNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3436-3CCE-2972-8CCE-696Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Prohibit unicast response to multicast or broadcast requests(Not Applicable)(Not Applicable)EnabledTo minimize the risk of an attacker using broadcast or multicast traffic to deliver malicious payloads.The unicast response to a multicast or broadcast packet sent by the computer is dropped.
This setting has no effect if the unicast message is a response to a DHCP broadcast message sent by the computer. Windows Firewall always permits DHCP unicast responses.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile!DisableUnicastResponsesToMulticastBroadcastNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3054-4CCE-3154-2CCE-806Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain ProfileWindows Firewall: Protect all network connections(Not Applicable)(Not Applicable)EnabledTo ensure that the firewall is actively protecting the computer from network attacks.Windows Firewall is enabled to protect all network connections and local administrators cannot enable or disable Windows Firewall locally. The Prohibit use of Internet Connection Firewall on your DNS domain network Group Policy setting is ignored.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile!EnableFirewallNot applicable to Windows 7 or Vista.
(Not Applicable)CCE-3369-6CCE-3262-3CCE-626Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard ProfileWindows Firewall: Allow file and printer sharing exception(Not Applicable)(Not Applicable)DisabledTo minimize the risk of an attacker using any of the affected protocols to exploit the computer.The ports for file and printer sharing are not opened. The shared files and printers on the computer will not be available from other computers.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\FileAndPrint!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\FileAndPrint!RemoteAddressesNot applicable to Windows 7 or Vista.
(Not Applicable)(Not Applicable)CCE-3081-7CCE-797Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard ProfileWindows Firewall: Allow ICMP exceptions(Not Applicable)(Not Applicable)DisabledTo minimize the risk of an attacker using the ICMP protocol to exploit the computer.No unsolicited incoming ICMP traffic is allowed. Local administrators cannot define ICMP exceptions.HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundDestinationUnreachable, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundSourceQuench, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowRedirect, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundEchoRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundRouterRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundTimeExceeded, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundParameterProblem, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundTimestampRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundMaskRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundPacketTooBigNot applicable to Windows 7 or Vista.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .