Check: 5.206
Windows 2008 Domain Controller STIG:
5.206
(in versions v6 r47 through v6 r35)
Title
Network – Windows Connect Now Wireless Configuration (Cat II impact)
Discussion
This check verifies that the configuration of wireless devices using Windows Connect Now is disabled.
Check Content
If the following registry values don’t exist or are not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows\WCN\Registrars\ Value Name: DisableFlashConfigRegistrar Value Name: DisableInBand802DOT11Registrar Value Name: DisableUPnPRegistrar Value Name: DisableWPDRegistrar Value Name: EnableRegistrars Type: REG_Dword Value: 0
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Windows Connect Now “Configuration of wireless settings using Windows Connect Now” to “Disabled”.
Additional Identifiers
Rule ID: SV-29759r1_rule
Vulnerability ID: V-15698
Group Title: Network – WCN Wireless Configuration
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |