Check: WINER-000003
Windows Vista STIG:
WINER-000003
(in versions v6 r42 through v6 r41)
Title
The system must be configured to save Error Reporting events and messages to the system event log. (Cat II impact)
Discussion
Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. This setting ensures that Error Reporting events will be saved in the system event log.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting\ Value Name: LoggingDisabled Type: REG_DWORD Value: 0
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Error Reporting -> "Disable logging" to "Disabled".
Additional Identifiers
Rule ID: SV-16653r2_rule
Vulnerability ID: V-15714
Group Title: WINER-000003
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |