Attachment_7_-_USGCB-Windows-Settings.xls
XLS spreadsheet 558 KB Posted
- Attached to
- Automated Palletizing Systems Federal contract opportunity
- Solicitation number
- BEP-RFP-16-0433
About this file
Attachment 7 - USGCB-Windows-Settings
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| BEP-RFP-16-0433_A0001.pdf | ||
| Attachment_4_-_Brick_Drawing_of_4000_Notes.pdf | ||
| Attachment_3_-_Skid_Drawing.pdf | ||
| Attachment_6_-_Brick_Stacking_Sequence.pdf | ||
| Attachment_5_-_COPE-Pak_Discharge_Conveyor_Drawing.pdf | ||
| BEP-RFP-16-0433.pdf | ||
| Attachment_9_-_NIST.SP.800-53r4.pdf | ||
| Attachment_1_-_Nondisclosure_Agreement.docx | DOCX document | |
| Attachment_8_-_FIPS-PUB-199-final.pdf | ||
| Attachment_10_-_DOJ_Reference_Mapping_PIVCard_Certificates.pdf | ||
| Attachment_11_-_Wage_Determination_2015-4281_Rev_3.pdf | ||
| Attachment_2_-_75D-07.0-06_EHS_Requirements_for_Large_Equipment_Purchases.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Table of Contents
| USGCB Settings | |
| This spreadsheet captures the USGCB defined configuration settings. | |
| Tab Name | Tab Description |
| Revision History | Tab capturing information relating to the revisions of this spreadsheet. |
| Windows Settings | Tab capturing the USGCB settings for Windows 7, Windows Vista, and Windows XP. These settings are the same for both x86 and x64 architectures. |
| Internet Explorer Settings | Tab capturing the USGCB settings for Internet Explorer 8 and Internet Explorer 7. |
Revision History Windows Settings Internet Explorer Settings
Revision History
| 2010.04.23 | alpha release | |||||
| All Tabs | Initial release of USGCB Content. | |||||
| 2010.05.19 | Win7 and Win7 Firewall settings and IE8 Settings tabs, enabled text wrapping, resized columns, resorted by Policy Path column | |||||
| Win7 and Win7 Firewall settings, capitalized 's' in 'settings' | ||||||
| NOTE: 800-53 mappings added to setting tabs, these will be removed once XML versions of mappings are available. | ||||||
| 2010.08.27 | Beta release | |||||
| All Tabs | Corrected minor typographical errors. | |||||
| All Tabs | Added a 'Category' column where some settings are specified as being 'pending' or 'conditional.' Pending settings are settings that are currently optional but will become mandatory in the future. Conditional settings are settings that are mandatory in most situations, however under specific conditions agencies may adjust those settings. For example, the IPv6 transitional technologies are disabled in the USGCB, but agencies that are using IPv6 may enable one or more of these transitional technologies if necessary. The current SCAP 1.0 content does not support conditional logic therefor agencies must manually track these as deviations, in the future SCP 1.1 content will support conditional logic. | |||||
| All Tabs | Formatted content as a table to facilitate sorting by columns. | |||||
| CCE | Path | Name | USGCB Alpha Value | USGCB Beta Value | Comments | |
| Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Inbound Rules | Core Networking - Dynamic Host Configuration Protocol (DHCP-In) | Enabled - yes | To allow the client to receive DHCP responses that would otherwise be blocked by CCE-9069-6. | |||
| Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Inbound Rules | Core Networking - Dynamic Host Configuration Protocol (DHCPV6-In) | Enabled - yes | To allow the client to receive DHCP responses that would otherwise be blocked by CCE-9069-6. | |||
| CCE-8583-7 | Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | Interactive Logon: message text for users attempting to log on | This system is for the use of authorized users only. Individuals using this computer system without authority or in excess of their authority are subject to having all their activities on this system monitored and recorded by system personnel. Anyone using this system expressly consents to such monitoring and is advised that if such monitoring reveals possible evidence of criminal activity system personal may provide the evidence of such monitoring to law enforcement officials. | This system is for the use of authorized users only. Individuals using this computer system without authority or in excess of their authority are subject to having all their activities on this system monitored and recorded by system personnel. Anyone using this system expressly consents to such monitoring and is advised that if such monitoring reveals possible evidence of criminal activity system personal may provide the evidence of such monitoring to law enforcement officials. | Fix mis-spelling in spreadsheet. |
Add language to the spreadsheet to allow flexibility for settings such as this.
| CCE-8583-7 | Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment | Debug programs | (None) | Administrators | Add 'Administrators' group in order to allow the use of legitimate management tools. |
| CCE-10658-3 | User Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication Settings | Turn off handwriting personalization data sharing | Enabled | Not Configured | Change to the machine setting, CCE-10645-0. |
| CCE-10645-0 | Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication Settings | Turn off handwriting personalization data sharing | Not Configured | Enabled | |
| CCE-8813-8 | Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | User Account Control: Behavior of the elevation prompt for standard users | Prompt for credentials | Prompt for credentials on the secure desktop | To reduce the risk of malware tricking an administrator into entering their credentials at a false UAC prompt. |
| CCE-10266-5 | Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition Technologies | 6to4 State | Enabled: Disabled State | Conditional | If they use IPv6 and require this transitional technology |
| CCE-10764-9 | Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition Technologies | IP-HTTPS State | Enabled: Disabled State | Conditional | If they use IPv6 and require this transitional technology |
| CCE-10130-3 | Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition Technologies | ISATAP State | Enabled: Disabled State | Conditional | If they use IPv6 and require this transitional technology |
| CCE-10011-5 | Computer Configuration\Administrative Templates\Network\TCPIP Settings\IPv6 Transition Technologies | Teredo State | Enabled: Disabled State | Conditional | If they use IPv6 and require this transitional technology |
| CCE-10441-4 | Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Windows Error Reporting | Enabled | Conditional | Allow for internal error collection. Deny for Microsoft error collection. |
| CCE-9960-6 | Computer Configuration\Administrative Templates\System\Remote Assistance | Offer Remote Assistance | Disabled | Conditional | If RDS is used by help desk, then allow. The end user shouldn't be able to do this. |
| CCE-9506-7 | Computer Configuration\Administrative Templates\System\Remote Assistance | Solicited Remote Assistance | Disabled | Conditional | If RDS is used by help desk, then allow. The end user shouldn't be able to do this. |
| CCE-9985-3 | Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Connections | Allow users to connect remotely using Remote Desktop Services | Disabled | Conditional | Applicable to those using RDS |
| CCE-10608-8 | Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Session Time Limits | Set time limit for active but idle Remote Desktop Services sessions | Enabled: 15 minutes | Conditional | This setting is mandated by SP 800-53 requirements for network timeouts. Agencies should only adjust it on systems that require a longer timeout |
| CCE-9403-7 | Computer Configuration\Administrative Templates\Windows Components\Windows Update | Configure Automatic Updates | Enabled: 3 - Auto download and notify for install | Conditional | Add language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management. |
| CCE-9464-9 | Computer Configuration\Administrative Templates\Windows Components\Windows Update | Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box | Disabled | Conditional | Software distribution should be centrally managed, only administrators and enterprise management tools should be able to install updates. However, Add language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management. |
| CCE-9672-7 | Computer Configuration\Administrative Templates\Windows Components\Windows Update | No auto-restart with logged on users for scheduled automatic updates installations | Disabled | Conditional | Add language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management. |
| CCE-10205-3 | Computer Configuration\Administrative Templates\Windows Components\Windows Update | Reschedule Automatic Updates scheduled installations | Enabled | Conditional | Software distribution should be centrally managed, only administrators and enterprise management tools should be able to determine when updates are installed. However, Add language to the spreadsheet to allow flexibility for settings such as this when agencies are using an enterprise solution for patch management. |
| CCE-9301-3 | Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop | Disabled | Conditional | If agencies use remote assistance then they can reconfigure this setting. This setting was added to Windows Vista SP1 specifically to enable Remote Assistance. It allows certain applications stored in secure folders, such as system32, to bypass the secure desktop so that they can function as designed. Enabling this setting will lower security slightly but enable Remote Assistance. For more information see http://technet.microsoft.com/en-us/library/dd835564(WS.10).aspx. |
| CCE-9253-6 | Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment | Access this computer from the network | Administrators | Conditional | Add information to the settings spreadsheet explaining how IPsec including many VPN solutions are impacted and that agencies can grant this user right to the built-in 'Users' group or they could implement a more precise solution by creating a group for IPsec and adding the affected accounts to it. |
DoD: won't change
| CCE-10661-7 | Computer Configuration\Windows Settings\Security Settings\System Services | Bluetooth Support Service | Disabled | Conditional | Organizations can enable this service if they want to allow the use of Bluetooth devices. | |
| CCE-9419-3 | Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment | Profile system performance | Administrators, NT SERVICE\WdiServiceHost | Administrators, NT SERVICE\WdiServiceHost | Added reference to KB article KB974639 to the spreadsheet, this includes a patch for win7 to address the problem raised by some agencies. | |
| Computer Configuration\Administrative Templates\System\Power Management\Sleep Settings | Specify the System Hibernate Timeout (On Battery) | Not specified | Pending, 3600 seconds | In support of administration efforts to reduce the use of electricity by inactive computers. This setting may impact the ability of enterprise management tools to push patches and configuration changes to managed computers therefor organizations should research the power management features of Windows and the capabilities of their management tools to leverage Wake-on-LAN and other features to remotely administer computers. | ||
| Computer Configuration\Administrative Templates\System\Power Management\Sleep Settings | Specify the System Hibernate Timeout (Plugged In) | Not specified | Pending, 3600 seconds | In support of administration efforts to reduce the use of electricity by inactive computers. This setting may impact the ability of enterprise management tools to push patches and configuration changes to managed computers therefor organizations should research the power management features of Windows and the capabilities of their management tools to leverage Wake-on-LAN and other features to remotely administer computers. | ||
| Computer Configuration\Administrative Templates\System\Power Management\Video and Display Settings | Turn off the Display (On Battery) | Not specified | Pending, 1200 seconds | In support of administration efforts to reduce the use of electricity by inactive computers. | ||
| Computer Configuration\Administrative Templates\System\Power Management\Video and Display Settings | Turn off the Display (Plugged In) | Not specified | Pending, 1200 seconds | In support of administration efforts to reduce the use of electricity by inactive computers. | ||
| CCE-10092-5 | Computer Configuration\Administrative Templates\Windows Components\Credential User Interface | Require trusted path for credential entry | Enabled | Remove | This adds 2 additional steps for each elevation prompt, the threats related to this setting are mitigated by the value now required by the "User Account Control: Behavior of the elevation prompt for standard users" the USGCB will prompt for credentials on the secure desktop for standard users but not for admins. | |
| CCE-10694-8 | Computer Configuration\Administrative Templates\System\Driver Installation | Turn off Windows Update device driver search prompt | Enabled | Remove | Allow organizations to define this policy setting. | |
| CCE-10681-5 | Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Automatic Root Certificates Update | Enabled | Remove | Allow organizations to define this policy setting. | |
| CCE-10093-3 | Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Windows Update device driver searching | Enabled | Remove | Allow organizations to define this policy setting. | |
| CCE-9983-8 | Computer Configuration\Administrative Templates\System\Logon | Do not process the legacy run list | Enabled | Remove | This setting will be added in the future, application developers are encouraged to find alternative methods for automatically launching components during the boot and logon processes. | |
| CCE-10540-3 | Computer Configuration\Administrative Templates\Windows Components\Internet Explorer | Turn off Managing Phishing filter | Enabled:Off | Remove | Not applicable to IE8. | |
| CCE-9987-9 | Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\ | Disable Automatic Install of Internet Explorer components | Enabled | Remove | Not applicable to IE8. | |
| CCE-10634-4 | Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\ | Disable Periodic Check for Internet Explorer software updates | Enabled | Remove | Not applicable to IE8. | |
| CCE-10632-8 | Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\ | Disable showing the splash screen | Enabled | Remove | Not applicable to IE8. | |
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone | Allow status bar updates via script | Disabled | Remove | Allow organizations to define this policy setting. | ||
| CCE-10007-3 | Computer Configuration\Administrative Templates\Windows Components\RSS Feeds | Turn on Basic feed authentication over HTTP | Enabled | Remove | Required setting less secure than default | |
| CCE-8868-2 | Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | Devices: Allowed to format and eject removable media | Administrators, Interactive Users | Remove | The current requires the weakest configuration so there's no reason to include it. | |
| CCE-8784-1 | Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames (recommended) | Enabled | Remove | Removed due to application compatibility issues | |
| CCE-10844-9 | Computer Configuration\Windows Settings\Security Settings\System Services | WLAN AutoConfig | Disabled | Remove | Allow organizations to define this policy setting. | |
| CCE-10207-9 | Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Outbound Rules | IPv6 Block of Protocols 41 | General: Enabled and Block the connections; Programs and Services: All programs that meet the specified conditions; Protocols and Ports: Protocols type IPv6; Scope: Any IP addresses; Advanced: All profiles | Remove | Redundant | |
| CCE-10488-5 | Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Outbound Rules | IPv6 Block of UDP 3544 | General: Enabled and Block the connections; Programs and Services: All programs that meet the specified conditions; Protocols and Ports: Protocols type UDP, Local port 3544, Remote port All Ports ; Scope: Any IP addresses; Advanced: All profiles | Remove | Redundant | |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip6\Parameters\DisableComponents | Disable ISATAP, Teredo, and 6to4 tunneling protocols | Enabled | Remove | Not applicable | ||
| User Configuration\Administrative Templates\Windows Components\Internet Explorer | Configure Outlook Express | Not defined | Remove | Not applicable to IE8. | ||
| User Configuration\Administrative Templates\Windows Components\Internet Explorer | Disable the Reset Web Settings feature | Not defined | Remove | Not applicable to IE8. | ||
| User Configuration\Administrative Templates\Windows Components\Internet Explorer | Turn on the Internet Connection Wizard Auto Detect | Disabled | Remove | Not applicable to IE8. | ||
| Computer Configuration\Administrative Templates\Network\Network Connections | Prohibit use of Internet Connection Firewall on your DNS domain network | Enabled | Remove | Not applicable | ||
| CCE-9797-2 | Computer Configuration\Administrative Templates\Network\Network Connections | Prohibit use of Internet Connection Sharing on your DNS domain network | Enabled | Remove | Not applicable | |
| User Configuration\Administrative Templates\System\Power Management | Prompt for password on resume from hibernate / suspend | Enabled | Remove | Not applicable | ||
| 2010.09.27 | 1.0 Release | |||||
| Corrected policy path for features that should not be installed, since these are not controlled through group policy the path now points to the location within Control Panel. | ||||||
| Control Panel\Programs and Features\Turn Windows features on or off | Internet Information Services | Not installed | Updated registry info to HKLM\SYSTEM\CurrentControlSet\Services\W3Svc\DisplayName | |||
| Control Panel\Programs and Features\Turn Windows features on or off | Simple TCP Services | Not installed | Updated registry info to HKLM\SYSTEM\CurrentControlSet\Services\SimpTCP\DisplayName | |||
| Computer Configuration\Administrative Templates\System\Power Management\Sleep Settings | Specify the System Hibernate Timeout (On Battery) | Enabled:3600 | Removed pending category | |||
| Computer Configuration\Administrative Templates\System\Power Management\Sleep Settings | Specify the System Hibernate Timeout (Plugged In) | Enabled:3600 | Removed pending category | |||
| Computer Configuration\Administrative Templates\System\Power Management\Video and Display Settings | Turn off the Display (On Battery) | Enabled:1200 | Removed pending category | |||
| Computer Configuration\Administrative Templates\System\Power Management\Video and Display Settings | Turn off the Display (Plugged In) | Enabled:1200 | Removed pending category | |||
| 2010.11.16 | 1.0 Release | |||||
| Win7 and Win7 Firewall settings tab | Corrected minor typographical errors. | |||||
| 2011.1.31 | 1.1 Release | |||||
| IE8 settings tab | Corrected minor typographical errors and updated the following CCE IDs. | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling | CCE-10138-6 | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature | CCE-10635-1 | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction | CCE-10265-7 | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation | CCE-10574-2 | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install | CCE-10405-9 | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download | CCE-10578-3 | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions | CCE-10604-7 | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer | Make proxy settings per-machine (rather than per-user) | CCE-9870-7 | ||||
| Win7 and Win7 Firewall settings tab | Corrected minor typographical errors and updated the following CCE IDs. | |||||
| Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Global Object Access Auditing | Audit File System | CCE-9811-1_CCE-9217-1. | ||||
| Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Global Object Access Auditing | Audit Registry | CCE-10078-4_CCE-9737-8. | ||||
| Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Logon/Logoff | Audit IPsec Main Mode | CCE-9715-4_CCE-8956-5 | ||||
| CCE-10658-3 | Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off handwriting personalization data sharing | Enabled | Added this setting that was mistakenly deleted during the Beta review period | ||
| 2011.6.21 | 1.2 Beta Release | |||||
| IE settings tab | FDCC settings that have not been carried forward to the USGCB baselines. | |||||
| User Configuration\Administrative Templates\Windows Components\Internet Explorer | Configure Outlook Express | CCE-3275-5 | CCE-3275-5 | Not applicable to IE7 or later. | ||
| User Configuration\Administrative Templates\Windows Components\Internet Explorer | Disable the Reset Web Settings feature | CCE-4226-7 | CCE-4226-7 | Not applicable to IE7 or later. | ||
| User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced Settings\Internet Connection Wizard Settings | Turn on the Internet Connection Wizard Auto Detect | CCE-4036-0 | CCE-4036-0 | Not applicable to IE, nor Windows Vista or later. | ||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer | Disable Automatic Install of Internet Explorer components | CCE-3518-8 | CCE-3518-8 | Not applicable to IE7 or later. | ||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer | Disable Periodic Check for Internet Explorer software updates | CCE-3576-6 | CCE-3576-6 | Not applicable to IE7 or later. | ||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer | Disable showing the splash screen | CCE-3706-9 | CCE-3706-9 | Not applicable to IE7 or later. | ||
| Computer Configuration\Administrative Templates\Windows Components\Internet Explorer | Disable software update shell notifications on program launch | CCE-4118-6 | CCE-4118-6 | Not applicable to IE7 or later. | ||
| Added columns to document the Internet Explorer setting values and CCE-IDs. | ||||||
| Added a comment column to provide information about changes made in order to better align the settings across each version of Internet Explorer. | ||||||
| Windows settings tab | FDCC settings that have not been carried forward to the USGCB baselines. | |||||
| Computer Configuration\Administrative Templates\Windows Components\Internet Information Services | Prevent IIS installation | CCE-3288-8 | CCE-4262-2 | Only applicable to Windows Server 2003. | ||
| Computer Configuration\Administrative Templates\Windows Components\Online Assistance | Turn off Untrusted Content | CCE-3046-0 | (Not Applicable) | Its not present in the Windows 7 baseline and it is not applicable to XP. | ||
| Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Device and Resource Redirection | Do not allow drive redirection | CCE-2874-6 | (Not Applicable) | Its not present in the Windows 7 baseline. | ||
| Computer Configuration\Administrative Templates\Windows Components\Windows Meeting Space | Turn off Windows Meeting Space | CCE-2557-7 | (Not Applicable) | Its not present in the Windows 7 baseline. | ||
| Computer Configuration\Administrative Templates\Windows Components\Windows Messenger | Do not allow Windows Messenger to be run | (Not Applicable) | CCE-2684-9 | Its not present in the Windows 7 baseline. | ||
| Computer Configuration\Administrative Templates\Windows Components\Windows Messenger | Do not automatically start Windows Messenger initially | CCE-4797-7 | CCE-2455-4 | Its not present in the Windows 7 baseline. | ||
| Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | Audit: Shut down system immediately if unable to log security audits | CCE-3001-5 | CCE-2851-4 | Its not present in the Windows 7 baseline. | ||
| Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | Devices: Allowed to format and eject removable media | CCE-3225-0 | CCE-3111-2 | Its not present in the Windows 7 baseline. | ||
| Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options | MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames (recommended) | CCE-3244-1 | CCE-2683-1 | Its not present in the Windows 7 baseline. | ||
| Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment | Synchronize directory service data | CCE-4970-0 | CCE-2810-0 | Its not applicable to any of the client operating systems, only domain controllers. | ||
| Computer Configuration\Windows Settings\Security Settings\System Services | WLAN AutoConfig | Its not present in the Windows 7 baseline. | ||||
| User Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication Settings | Turn off Help Experience Improvement Program | CCE-5239-9 | (Not Applicable) | Its not present in the Windows 7 baseline. | ||
| User Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Help Ratings | CCE-4851-2 | (Not Applicable) | Its not present in the Windows 7 baseline. | ||
| User Configuration\Administrative Templates\System\Power Management | Prompt for password on resume from hibernate / suspend | CCE-3169-0 | CCE-4390-1 | Only applicable to Windows XP. | ||
| Computer Configuration\Administrative Templates\System | Turn off Windows Update device driver search prompt | CCE-3278-9 | CCE-5014-6 | Its not present in the win7 baseline or the Microsoft baselines for either win7 or Vista. | ||
| Computer Configuration\Administrative Templates\System\Error Reporting | Display Error Notification | (Not Applicable) | CCE-5136-7 | It was removed from Windows in Vista. Also, the USGCB settings were changed to allow agencies to use Error Reporting internally. | ||
| Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Automatic Root Certificates Update | CCE-3454-6 | CCE-5054-2 | Previously removed from the USGCB. | ||
| Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Windows Movie Maker automatic codec downloads | CCE-3403-3 | CCE-4242-4 | This was never included in the USGCB, and it appears that it was removed from Windows 7. | ||
| Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Windows Movie Maker online Web links | CCE-3297-9 | CCE-4732-4 | This was never included in the USGCB, and it appears that it was removed from Windows 7. | ||
| Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Windows Movie Maker saving to online video hosting provider | CCE-3385-2 | CCE-4997-3 | This was never included in the USGCB, and it appears that it was removed from Windows 7. | ||
| Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings | Turn off Windows Update device driver searching | CCE-3278-9 | CCE-5014-6 | Previously removed from the USGCB. | ||
| Computer Configuration\Administrative Templates\System\Logon | Don't display the Getting Started welcome screen at logon | CCE-2781-3 | CCE-5160-7 | This only applied to Windows 2000. | ||
| Added columns to document the Windows XP and Windows Vista setting values and CCE-IDs. | ||||||
| Added a comment column to provide information about changes made in order to better align the settings across each version of Windows. | ||||||
| 2011.8.26 | 1.2 / 2.0 Beta 2 release | |||||
| Windows settings tab | Added CCE IDs for several settings | Vista CCE ID | XP CCE ID | |||
| Control Panel\Programs and Features\Turn Windows features on or off | Games | CCE-18891-2 | CCE-18796-3 | |||
| Control Panel\Programs and Features\Turn Windows features on or off | Internet Information Services | CCE-18279-0 | CCE-18870-6 | |||
| Control Panel\Programs and Features\Turn Windows features on or off | SimpleTCP Services | CCE-18624-7 | CCE-18307-9 | |||
| Control Panel\Programs and Features\Turn Windows features on or off | Telnet Client | CCE-18129-7 | (Not Applicable) | |||
| Control Panel\Programs and Features\Turn Windows features on or off | Telnet Server | CCE-18284-0 | (Not Applicable) | |||
| Control Panel\Programs and Features\Turn Windows features on or off | TFTP Client | CCE-18700-5 | (Not Applicable) | |||
| Control Panel\Programs and Features\Turn Windows features on or off | Windows Media Center | CCE-18689-0 | (Not Applicable) | |||
| 2011.10.17 | 1.2 / 2.0 Release | |||||
| Windows settings tab | Added details under the comments column about how the conditional logic has been implemented in the SCAP 1.2 content | |||||
| 2012.2.10 | 1.2 / 2.0 Release | Windows 7 CCE ID | Vista CCE ID | |||
| Removed "Security Require authentication" from the Impact statement | CCE-14986-4 | CCE-18320-2 | ||||
| Removed "Security Require authentication" from the Impact statement | CCE-14854-4 | (Not Applicable) | ||||
| Corrected registry path information for the following settings | CCE-10502-3 | CCE-3260-7 | ||||
| CCE-10268-1 | CCE-3414-0 | |||||
| CCE-10022-2 | CCE-2533-8 | |||||
| CCE-9747-7 | CCE-3299-5 | |||||
| CCE-10215-2 | CCE-4597-1 | |||||
| CCE-10611-2 | CCE-4963-5 | |||||
| CCE-10386-1 | CCE-4206-9 | |||||
| CCE-10250-9 | CCE-4207-7 | |||||
| CCE-9749-3 | CCE-4507-0 | |||||
| CCE-9753-5 | CCE-5128-4 | |||||
| CCE-9926-7 | CCE-4639-1 | |||||
| CCE-10373-9 | CCE-4278-8 | |||||
| CCE-9540-6 | CCE-3292-0 | |||||
| CCE-8487-1 | CCE-2376-2 | |||||
| CCE-9764-2 | CCE-4866-0 | |||||
| Corrected the value for the IE7 setting "Do not allow users to enable or disable add-ons" so that it matches the value prescribed for IE8 | CCE-3744-0 | CCE-3744-0 | ||||
| Corrected the value for the IE7 setting "Automatic prompting for file downloads" so that it matches the value prescribed for IE8 | CCE-4053-5 | CCE-4053-5 | ||||
| 2012.4.26 | 1.2 / 2.0 Release | Updated column B on the Revision History tab to reflect that the current USGCB versions are 1.2 for Windows 7 and Internet Explorer 8 and 2.0 For Windows XP, Windows Vista, and Internet Explorer 7. | ||||
| Corrected numerous typos in the Registry Info column of the Windows Settings tab, for example, ensured that the registry path and the registry value name are seperated by an exclamation mark, "!," rather than a slash. | ||||||
| 2015.02.25 | WinXP-3.0.3.1-rc1.zip, WinXP-Firewall-2.1.0.1-rc1.zip, WinVista-3.0.5.1-rc1.zip, WinVista-Firewall-2.1.0.1-rc1.zip, Win7-2.0.5.1-rc1.zip, Win7-Firewall-1.3.0.1-rc1.zip, IE7-2.1.3.1-rc1.zip, IE8-1.3.3.1-rc1.zip | |||||
| Added the following CCEs to spreadsheet: | Windows XP | IE8 | ||||
| CCE-2777-1 | CCE-9793-1 | |||||
| CCE-2336-6 | CCE-9832-7 | |||||
| CCE-3014-8 | CCE-10425-7 | |||||
| CCE-2810-0 | ||||||
| Win 7 | Vista | |||||
| CCE-12924-7 | CCE-18686-6 | |||||
| CCE-12393-5 | CCE-18303-8 | |||||
| Added two configutation settings for Windows Vista and 7 Energy data streams: | ||||||
| Specify the System Sleep Timeout (On Battery) | ||||||
| Specify the System Sleep Timeout (Plugged In) | ||||||
| Updated the SCAP 1.2 USGCB data streams as described in the change log. | ||||||
| 2015.04.20 | Final Release: WinXP-3.0.3.1.zip, WinXP-Firewall-2.1.0.1.zip, WinVista-3.0.5.1.zip, WinVista-Firewall-2.1.0.1.zip, Win7-2.0.5.1.zip, Win7-Firewall-1.3.0.1.zip, IE7-2.1.3.1.zip, IE8-1.3.3.1.zip | |||||
| Updated the SCAP 1.2 USGCB data streams as described in the change log. | ||||||
| 2015.07.09 | Corrected a typo for CCE-5146-6, CCE-5036-9, and CCE-4811-6 in the Windows Settings worksheet. | |||||
| 2015.08.13 | Corrected the USGCB value for the 'Interactive logon: Smart card removal behavior' in the Windows Settings worksheet. |
Windows Settings
| CCE ID v5 Win7 | CCE ID v5 Win Vista | CCE ID v5 Win XP | CCE ID v4 | Policy Path | Policy Setting Name | Windows 7 USGCB 1.2 | Windows Vista USGCB 2.0 | Windows XP USGCB 2.0 | Rationale | Impact | Category | 800-53 Mapping | Registry Info | Comments | |
| CCE-9783-2 | CCE-4992-4 | (Not Applicable) | CCE-947 | Computer Configuration\Administrative Templates\Network\Link-Layer Topology Discovery | Turn on Mapper I/O (LLTDIO) driver | Disabled | Disabled | (Not Applicable) | To prevent network traffic driven by the Link-Layer Topology Discovery feature. | The computer will not be able to discover the network topology or make Quality-of-Service requests. | CM-6 CM-7 | HKLM\Software\Policies\Microsoft\Windows\LLTD!EnableLLTDIO, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowLLTDIOOnDomain, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowLLTDIOOnPublicNet, HKLM\Software\Policies\Microsoft\Windows\LLTD!ProhibitLLTDIOOnPrivateNet | Not applicable to XP. | ||
| CCE-10059-4 | CCE-4077-4 | (Not Applicable) | CCE-1134 | Computer Configuration\Administrative Templates\Network\Link-Layer Topology Discovery | Turn on Responder (RSPNDR) driver | Disabled | Disabled | (Not Applicable) | To prevent the computer from responding to Link-Layer Topology Discovery requests. | The computer will not be able to support Link-Layer Topology Discovery requests. | CM-6 CM-7 | HKLM\Software\Policies\Microsoft\Windows\LLTD!EnableRspndr, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowRspndrOnDomain, HKLM\Software\Policies\Microsoft\Windows\LLTD!AllowRspndrOnPublicNet, HKLM\Software\Policies\Microsoft\Windows\LLTD!ProhibitRspndrOnPrivateNet | Not applicable to XP. | ||
| CCE-10438-0 | CCE-3270-6 | CCE-5194-6 | CCE-86 | Computer Configuration\Administrative Templates\Network\Microsoft Peer-to-Peer Networking Services | Turn Off Microsoft Peer-to-Peer Networking Services | Enabled | Enabled | Enabled | To prevent users from utilizing the P2P features included with Windows. | Users will not be able to join P2P networks based on the P2P services available in Windows. | CM-3 CM-7 | HKLM\Software\policies\Microsoft\Peernet!Disabled | |||
| CCE-9953-1 | CCE-4152-5 | CCE-2173-3 | CCE-896 | Computer Configuration\Administrative Templates\Network\Network Connections | Prohibit installation and configuration of Network Bridge on your DNS domain network | Enabled | Enabled | Enabled | To prevent the computer from forwarding internal traffic to other networks. | The computer will not be able to act as a layer 2 network bridge while connected to the corporate network. | SC-7 SC-22 | HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_AllowNetBridge_NLA | |||
| (Not Applicable) | CCE-5020-3 | CCE-5022-9 | CCE-241 | Computer Configuration\Administrative Templates\Network\Network Connections | Prohibit use of Internet Connection Firewall on your DNS domain network | (Not Applicable) | (Not Applicable) | Enabled | Prohibits use of Internet Connection Firewall on your DNS domain network. | ||||||
| Determines whether users can enable the Internet Connection Firewall feature on a connection, and if the Internet Connection Firewall service can run on a computer. Important: This setting is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. | If you enable this setting, Internet Connection Firewall cannot be enabled or configured by users (including administrators), and the Internet Connection Firewall service cannot run on the computer. The option to enable the Internet Connection Firewall through the Advanced tab is removed. In addition, the Internet Connection Firewall is not enabled for remote access connections created through the Make New Connection Wizard. The Network Setup Wizard is disabled. | HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_PersonalFirewallConfig | Prveviously this was 'enabled' on Vista however the setting is not applicable to Vista. | ||||||||||||
| (Not Applicable) | CCE-4078-2 | CCE-3026-2 | CCE-672 | Computer Configuration\Administrative Templates\Network\Network Connections | Prohibit use of Internet Connection Sharing on your DNS domain network | (Not Applicable) | (Not Applicable) | Enabled | Determines whether administrators can enable and configure the Internet Connection Sharing (ICS) feature of an Internet connection and if the ICS service can run on the computer. Important: This setting is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS domain network other than the one it was connected to when the setting was refreshed, this setting does not apply. | If you enable this setting, ICS cannot be enabled or configured by administrators, and the ICS service cannot run on the computer. The Advanced tab in the Properties dialog box for a LAN or remote access connection is removed. The Internet Connection Sharing page is removed from the New Connection Wizard. The Network Setup Wizard is disabled. | HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_ShowSharedAccessUI | Prveviously this was 'enabled' on Vista however the setting is not applicable to Vista. | |||
| CCE-10359-8 | (Not Applicable) | (Not Applicable) | (Not Applicable) | Computer Configuration\Administrative Templates\Network\Network Connections | Require domain users to elevate when setting a network's location | Enabled | (Not Applicable) | (Not Applicable) | To minimize the risk of users specifying the work location when connected to public networks because the public network is associated with the public firewall profile which has more restrictive settings than the domain firewall profile. | Unprivileged users will not be able to change the network location. | AC-2 | HKLM\Software\Policies\Microsoft\Windows\Network Connections!NC_StdDomainUserSetLocation | Not applicable to Vista or XP. | ||
| CCE-10509-8 | (Not Applicable) | (Not Applicable) | (Not Applicable) | Computer Configuration\Administrative Templates\Network\Network Connections | Route all traffic through the internal network | Enabled: Enabled State | (Not Applicable) | (Not Applicable) | To force all traffic from computers connected to the corporate network via a VPN to traverse the corporate network. This will ensure that the traffic can be managed and monitored. | Remote users will have slower response times and possible less available bandwidth when connecting to servers located on the Internet. This setting will also increase the burden on VPN servers. | AC-4 | HKLM\Software\Policies\Microsoft\Windows\TCPIP\v6Transition!Force_Tunneling | Not applicable to Vista or XP. | ||
| (Not Applicable) | CCE-3431-4 | CCE-3247-4 | CCE-555 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow file and printer sharing exception | (Not Applicable) | (Not Applicable) | Disabled | To minimize the risk of an attacker using any of the affected protocols to exploit the computer. | The ports for file and printer sharing are not opened. The shared files and printers on the computer will not be available from other computers. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint!RemoteAddresses | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | (Not Applicable) | CCE-3141-9 | CCE-277 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow ICMP exceptions | (Not Applicable) | (Not Applicable) | Enabled: Allow inbound echo requests | The Windows Firewall: Allow ICMP exceptions setting allows you to configure specific types of ICMP messages as excepted traffic. | When Enabled, the specified unsolicited incoming ICMP traffic is allowed. When you select Enabled, you must also specify the specific types of ICMP messages that are allowed. Selecting Enabled overrides the local ICMP settings of Windows Firewall. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundDestinationUnreachable, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundSourceQuench, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowRedirect, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundEchoRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundRouterRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundTimeExceeded, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundParameterProblem, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundTimestampRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundMaskRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundPacketTooBig | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-3180-7 | CCE-3258-1 | CCE-370 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow local port exceptions | (Not Applicable) | (Not Applicable) | Disabled | To prevent users with administrative privileges from creating local rules that may lower the security of the firewall. | Local administrators cannot add port exceptions. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts!AllowUserPrefMerge | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-3405-8 | CCE-2828-2 | CCE-502 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow local program exceptions | (Not Applicable) | (Not Applicable) | Disabled | To prevent users with administrative privileges from creating local rules that may lower the security of the firewall. | Local administrators cannot add program exceptions. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications!AllowUserPrefMerge | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | (Not Applicable) | CCE-2965-2, CCE-3090-8, CCE-2923-1, CCE-2958-7 | CCE-251, CCE-617, CCE-793, CCE-57 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow logging | (Not Applicable) | (Not Applicable) | Enabled: Log dropped packets,Log successful connections,Log file path and name:%systemroot%\domainfw.log,size limit:16384 | To facilitate determination of the root cause of system problems or to detect unauthorized activities. | Logging is enabled with the specified log file settings. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogDroppedPackets, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogSuccessfulConnections, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogFilePath, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging!LogFileSize | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-3158-3 | CCE-2476-0 | CCE-771 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow remote administration exception | (Not Applicable) | (Not Applicable) | Enabled | To allow remote administration when the computer is connected to the corporate network. | Windows Firewall allows the computer to receive the unsolicited incoming messages associated with remote administration. In Allow unsolicited incoming messages from, type * to specify traffic originating from any source IPv4 address or a comma-separated list of sources. The sources can be LocalSubnet to specify traffic originating from a directly reachable IPv4 address or one or more IPv4 addresses or IPv4 address ranges separated by commas. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings!RemoteAddresses | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-3458-7 | CCE-3304-3 | CCE-832 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow Remote Desktop exception | (Not Applicable) | (Not Applicable) | Enabled | To allow RDP when the computer is connected to the corporate network. | Remote Desktop connections are allowed. TCP port 3389 is opened. In Allow unsolicited incoming messages from, type * to specify Remote Desktop traffic originating from any source IPv4 address or a comma separated list of sources. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop!RemoteAddresses | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-2964-5 | CCE-3176-5 | CCE-590 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Allow UPnP framework exception | (Not Applicable) | (Not Applicable) | Disabled | To minimize the risk of an attacker using UPnP traffic to deliver malicious payloads. | The ports for UPnP traffic are not opened, which prevents the computer from receiving unsolicited incoming UPnP messages. Local administrators cannot configure the pre-defined UPnP Framework exception. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\UPnPFramework!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\UPnPFramework!RemoteAddresses | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-3365-4 | CCE-3198-9 | CCE-762 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Prohibit notifications | (Not Applicable) | (Not Applicable) | Disabled | To alert the user of applications that attempt to open inbound network ports. | Users will see a notification when a program is blocked from receiving inbound connections in this firewall profile. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile!DisableNotifications | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-3436-3 | CCE-2972-8 | CCE-696 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Prohibit unicast response to multicast or broadcast requests | (Not Applicable) | (Not Applicable) | Enabled | To minimize the risk of an attacker using broadcast or multicast traffic to deliver malicious payloads. | The unicast response to a multicast or broadcast packet sent by the computer is dropped. | |||||
| This setting has no effect if the unicast message is a response to a DHCP broadcast message sent by the computer. Windows Firewall always permits DHCP unicast responses. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile!DisableUnicastResponsesToMulticastBroadcast | Not applicable to Windows 7 or Vista. | |||||||||||||
| (Not Applicable) | CCE-3054-4 | CCE-3154-2 | CCE-806 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile | Windows Firewall: Protect all network connections | (Not Applicable) | (Not Applicable) | Enabled | To ensure that the firewall is actively protecting the computer from network attacks. | Windows Firewall is enabled to protect all network connections and local administrators cannot enable or disable Windows Firewall locally. The Prohibit use of Internet Connection Firewall on your DNS domain network Group Policy setting is ignored. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile!EnableFirewall | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | CCE-3369-6 | CCE-3262-3 | CCE-626 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile | Windows Firewall: Allow file and printer sharing exception | (Not Applicable) | (Not Applicable) | Disabled | To minimize the risk of an attacker using any of the affected protocols to exploit the computer. | The ports for file and printer sharing are not opened. The shared files and printers on the computer will not be available from other computers. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\FileAndPrint!Enabled, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\FileAndPrint!RemoteAddresses | Not applicable to Windows 7 or Vista. | |||
| (Not Applicable) | (Not Applicable) | CCE-3081-7 | CCE-797 | Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile | Windows Firewall: Allow ICMP exceptions | (Not Applicable) | (Not Applicable) | Disabled | To minimize the risk of an attacker using the ICMP protocol to exploit the computer. | No unsolicited incoming ICMP traffic is allowed. Local administrators cannot define ICMP exceptions. | HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundDestinationUnreachable, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundSourceQuench, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowRedirect, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundEchoRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundRouterRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundTimeExceeded, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundParameterProblem, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundTimestampRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowInboundMaskRequest, HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings!AllowOutboundPacketTooBig | Not applicable to Windows 7 or Vista. |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .