Check: 2.008
Windows 7 STIG:
2.008
(in versions v1 r32 through v1 r25)
Title
Local volumes must be formatted using NTFS. (Cat I impact)
Discussion
The ability to set access permissions and auditing is critical to maintaining the security and proper access controls of a system. To support this, volumes must be formatted using the NTFS file system.
Check Content
Open the Computer Management Console. Expand "Storage" in the left pane. Select "Disk Management". If the file system column does not indicate "NTFS" as the file system for each local hard drive, this is a finding. Some hardware vendors create a small FAT partition to store troubleshooting and recovery data. No other files must be stored here. This must be documented with the ISSO.
Fix Text
Format all local partitions/drives to use NTFS.
Additional Identifiers
Rule ID: SV-25005r2_rule
Vulnerability ID: V-1081
Group Title: NTFS Requirement
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |