Check: 1.016
Windows Vista STIG:
1.016
(in versions v6 r42 through v6 r41)
Title
Security configuration tools or equivalent processes must be used to configure and maintain platforms for security compliance. (Cat III impact)
Discussion
Security configuration tools such as Group Policies and Security Templates allow system administrators to consolidate security-related system settings into a single configuration file. These settings can then be applied consistently to any number of Windows systems.
Check Content
Verify security configuration tools or equivalent processes are being used to configure Windows systems to meet security requirements. If security configuration tools or equivalent processes are not used, this is a finding. Security configuration tools that are integrated into Windows, such as Group Policies and Security Templates, may be used to configure platforms for security compliance. If an alternate method is used to configure a system (e.g., manually using the DISA Windows Security STIGs, etc.) and the same configured result is achieved, this is acceptable.
Fix Text
Implement a process using security configuration tools or the equivalent to configure Windows systems to meet security requirements.
Additional Identifiers
Rule ID: SV-29668r2_rule
Vulnerability ID: V-1128
Group Title: Security Configuration Tools
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |