Check: WINER-000011
Windows Vista STIG:
WINER-000011
(in versions v6 r42 through v6 r41)
Title
The system must be configured to store all data in the error report archive. (Cat II impact)
Discussion
The error reporting archive is stored locally on the system and is created after an error report has been sent to the local collector or DOD-wide collector (if defined). Storing all data, including memory contents, adds data that is very helpful in analyzing the errors.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting\ Value Name: ConfigureArchive Type: REG_DWORD Value: 0x00000002 (2)
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Error Reporting -> Advanced Error Reporting Settings -> "Configure Report Archive" to "Enabled" with "Store All" selected for "Archive behavior:".
Additional Identifiers
Rule ID: SV-71901r1_rule
Vulnerability ID: V-57465
Group Title: WINER-000011
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |