Check: 5.225
Windows Server 2008 R2 Domain Controller STIG:
5.225
(in versions v1 r34 through v1 r21)
Title
The user will be prompted for a password on resume from sleep (Plugged In). (Applicable on Server 2008 R2 if the system is configured to sleep.) (Cat II impact)
Discussion
This check verifies that the user is prompted for a password on resume from sleep (Plugged In).
Check Content
If the following registry value doesn’t exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51\ Value Name: ACSettingIndex Type: REG_DWORD Value: 1 Applicable on Server 2008 R2 if the system is configured to sleep.
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Power Management -> Sleep Settings “Require a Password When a Computer Wakes (Plugged In)” to “Enabled”.
Additional Identifiers
Rule ID: SV-32428r1_rule
Vulnerability ID: V-15706
Group Title: Power Mgmt – Password Wake When Plugged In
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-002038 |
The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. |
Controls
| Number | Title |
|---|---|
| IA-11 |
Re-authentication |