<?xml version="1.0" encoding="UTF-8" standalone="no"?><!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook V4.1//EN" "http://www.oasis-open.org/docbook/xml/4.1/docbookx.dtd">
<book>
<bookinfo>
<title>NT4 Generic Security Standard</title>
<titleabbrev>LCZ-NT4-GSS</titleabbrev>
<edition>1.1</edition>
<pubdate>16 May 2009</pubdate>
<abstract>
<para>This document specifies generic technical security policy for implementations of <trademark>Microsoft</trademark> <trademark>Windows</trademark> NT4.0, and applies to workstation, server and domain controller implementations of NT4.0, whether standalone 
or part of a domain.
</para>
<para>This standard contains 36 baseline controls, and 3 above baseline controls, for a total of 39 controls.</para></abstract>
<revhistory>
<revision>
<revnumber>1.1</revnumber>
<date>16 May 2009</date>
<authorinitials>FOD</authorinitials>
<revremark>Revised for re-release</revremark>
</revision>
<revision>
<revnumber>1.0</revnumber>
<date>04 February 2003</date>
<authorinitials>LCZ</authorinitials>
<revremark>Initial Draft for public release</revremark>
</revision>
</revhistory>
<copyright>
<year>2001</year><year>2002</year><year>2003</year><year>2009</year>
<holder>Frank O'Dwyer</holder>
</copyright>
<legalnotice><important><para>All of these Security Standards and Security Policies are copyrighted. THEY ARE NOT IN THE
PUBLIC DOMAIN. They are however distributed under a liberal open-source license, 
see <link linkend="publishing">Publishing these Security Standards and Policies</link>.</para></important></legalnotice><publisher><publishername>Frank O'Dwyer</publishername></publisher></bookinfo>
<chapter><title>Introduction</title>
<section><title>Objectives</title><para>The objectives of this document are:</para><itemizedlist>
<listitem><para>To specify a baseline configuration for implementations of &lt;trademark&gt;Microsoft&lt;/trademark&gt; &lt;trademark&gt;Windows&lt;/trademark&gt; NT4.0. 
</para></listitem>
<listitem><para>To provide guidance to administators, developers and security personnel in securely implementing &lt;trademark&gt;Microsoft&lt;/trademark&gt; &lt;trademark&gt;Windows&lt;/trademark&gt; NT4.0. 
</para></listitem>
</itemizedlist></section>
<section><title>Scope</title>
<para>Controls specified in this document apply to workstation, server, and domain controller implementations of NT4.0, whether used standalone or part of a domain.
</para>
<para>All of the organisation's NT4.0 information systems
will be subject to the policies specified within
this generic security standard. The policies will
be applied to new and existing installations.
</para>
</section>
<section><title>Not In Scope</title>
<para>Compliance with this standard will not provide <quote>in depth</quote> security architecture or intelligent security design guidance
to projects. As a consequence, for high impact or safety-critical business applications, additional guidance will still need to be 
sought from the Information Security team consultancy function.  
</para>
<para>This is a generic standard. Controls specific to workstation, server, or domain controller implementations are not 
defined here but will be the subject of additional standards.
</para>
<para>Compliance with this standard does not negate the need for an overall security review 
of a proposed application. Contact the Information Security team if you are in doubt.
</para>
</section>
<section><title>Giving Feedback</title><para>Your feedback to improve this document is welcome. Please let me know of your experiences in applying the controls and 
	guidance in this standard. Are the controls effective, easy to implement, too onerous, clear, unclear, something missing? Does an exceptional case 
need to be covered? Let me know. Please 
send your comments to frankodwyer AT netscape.net. Your comments will be 
used to produce better free security standards for the IT community.</para><para>I also request that you give feedback where you think the controls and guidance is 
correct. This will let us gauge whether or not specific controls are controversial or 
broadly acceptable to the community, and will help us to resolve cases where we have 
conflicting feedback on particular content.</para></section><section id="publishing"><title>Publishing these Security Standards and Policies</title><para>This document may be reproduced and distributed in whole or in part, free of charge, subject to the following conditions:</para><itemizedlist><listitem><para>All copyright and trademark notices, and this permission notice must be preserved complete on all complete or partial copies.</para></listitem><listitem><para>Any translation or derivative work of this document must be approved by Frank O'Dwyer in writing before distribution.</para></listitem><listitem><para>If you distribute this guide in part, instructions for obtaining the complete version of this manual must be included, and a means for obtaining a complete version provided.</para></listitem><listitem><para>Small portions may be reproduced as illustrations for reviews or quotes in other works without this permission notice if proper citation is given.</para></listitem><listitem><para>Neither Frank O'Dwyer's name nor the names of any contributors may be used to endorse or promote products derived from this document without specific prior written permission.</para></listitem></itemizedlist><para>THIS DOCUMENT IS PROVIDED BY FRANK O'DWYER AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY 
AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL FRANK O'DWYER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF 
LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.</para><para>I would like to be informed of any plans to publish or distribute these documents, just so I know how they're being used and where they are becoming available. 
	If you are publishing or distributing or planning to publish or distribute any of these documents, please send mail to frankodwyer AT netscape.net</para></section>
<section><title>Related Documents</title><para>This document should be read and applied in conjunction with the technology specific security standards that are available from the frankodwyer.com  
web site. Please note that some of the documents below are currently under development and as such may not as yet be available. Check back frequently for updates
to this document and those documents listed below.</para><section><title>Generic Security Standards</title><para><emphasis>Generic Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para><para><emphasis>Data Protection European Union Security Standard</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para><para><emphasis>Application Service Provider Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#generic">http://www.frankodwyer.com/standards/index.html#generic</ulink></para></section><section><title>Operating System Security Standards</title><para><emphasis>Generic Unix Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Generic Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Workstation Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Server Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para><para><emphasis>Windows NT4.0 Domain Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#os">http://www.frankodwyer.com/standards/index.html#os</ulink></para></section><section><title>Database Security Standards</title><para><emphasis>Oracle Security Standards</emphasis></para><para><ulink url="http://www.frankodwyer.com/standards/index.html#db">http://www.frankodwyer.com/standards/index.html#db</ulink></para></section></section>
<section><title>Definitions</title>

<para>An <quote>Information Asset</quote> equates to any computerised information system 
or component thereof and thus includes an application, an item of off the shelf software, hardware, media, 
a data item, a data item repository and associated communications networks.</para>
<para>The specification of 
the Information Asset in question will usually be given so that this document is unambiguous, except
where a control relates to any <quote>Information Asset</quote>. </para>


<para>The use of <quote>must</quote> or <quote>will</quote> indicates what the author considers to be a mandatory control.</para>
<para>However, whether the controls listed here are mandatory for your organisation is entirely at your organisation's discretion and
thus they should be interpreted as representing the strongest recommendation of the author.</para>


<para>The use of <quote>should</quote> or <quote>recommended</quote> or <quote>ought</quote> indicates
that the author believes that the controls in question are worthwhile and should be implemented unless such
an implementation is impossible, onerous or impractical. Again, the implementation of controls so recommended
in this document is entirely at your organisation's discretion.</para>

</section>
</chapter>




<chapter><title>User Configuration</title>
<section><title>User Administration</title>
<section><title>Restrict access to login scripts and profiles</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-UC-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Login scripts and profiles must be accessible only by their user and administrators.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure the ACLs for login scripts and profiles grant access only to their user and administrators.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Users will be able to run programs using the privileges of other users.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
<section><title>Default Accounts</title>
<section><title>Rename the administrator account</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-DA-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Rename the administrator to an attributable account name and assign a new password.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Rename the administrator account to an individuals name</para></listitem>
<listitem><para>Assign a new password</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>As the admin account is certain to exist on every system it is a priority for attack</para></listitem>
<listitem><para>Changing the password from the default helps prevent unauthorised access</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Disable Guest Account</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-DA-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The guest account must be disabled.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Select account disabled on the main account window.</para></listitem>
<listitem><para>Give the guest account a long random password that is not retained by anyone.</para></listitem>
<listitem><para>Set its login hours to none.</para></listitem>
<listitem><para>Set its expiration date to a date past.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Unauthorised network access to the NT system may be possible.</para></listitem>
<listitem><para>Unauthorised access to NT objects may result</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>

<section><title>Privileges</title>
<section><title>The advanced user right to load and unload device drivers must not be assigned to any users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-13</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to load and unload device drivers must not be assigned to any users</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Replacing a device driver may be used to gain unauthorised access</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to create a page file must not be assigned to any users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-7</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to create a page file must not be assigned to any users</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to bypass traverse checking must not be assigned to any users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-6</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to bypass traverse checking must not be assigned to any users</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>This right permits access control on an object path to be disregarded and may result in unintended access being obtained</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to profile single process must be assigned only to administrators.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-16</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to profile single process must be assigned only to administrators</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The ability to profile single processes may result in unauthorised disclosure of security sensitive information</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to repace a system level process token must be assigned to no user</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-19</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to repace a system level process token must be assigned to no user</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Such access may be used to subvert the security controls on the system</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to create permanent shared objects must not be assigned to any users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-9</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to create permanent shared objects must not be assigned to any users</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to generate security audits must not be assigned to any users other than administrators or security teams</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-11</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to generate security audits must not be assigned to any users other than administrators or security teams</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it where appropriate</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The security audit will contain disclosure sensitive information</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to debug programs must be assigned only to adminisrators and developers</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-10</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to debug programs must be assigned only to adminisrators and developers</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Security sensitive information may be obtained such as passwords</para></listitem>
<listitem><para>Unauthorised access may be obtained</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The user right to shutdown the system should be assigned to local groups and not to individual users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-4</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The user right to shutdown the system should be assigned to local groups and not to individual users</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Assign the right to a local group</para></listitem>
<listitem><para>Assign users to the group</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Adnministration should be performed using roles supported through membership of groups</para></listitem>
<listitem><para>Complex individual admin often leads to unauthorised access</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to profile system performance must be assigned only to administrators.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-17</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to profile system performance must be assigned only to administrators.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The ability to profile system performance may result in a denial of service</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to receive unsolicited device input must be assigned to no users.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-18</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to receive unsolicited device inpurt must be assigned to no users.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>This right can be used to obtain unauthorised access</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The user right to force shutdown from a remote system should be assigned to local groups and not to individual users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The user right to force shutdown from a remote system should be assigned to local groups and not to individual users</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Assign the right to a local group</para></listitem>
<listitem><para>Assign users to the group</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Security administration is simplified by the use of roles</para></listitem>
<listitem><para>This privilege may allow a denial of service to be executed</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to increase scheduling priority must  be assigned only to administrators</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-12</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to increase scheduling priority must  be assigned only to administrators</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The ability to increase scheduling priority can be used to hog system resource</para></listitem>
<listitem><para>This privilege may allow an enterprise wide denial of service</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to modify firmware environment variables must only be assigned to administrators.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-15</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to modify firmware environment variables must be assigned only to administrators.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Modification of such variables may result in abnormal or unauthorised function</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to act as part of the operating system must be assigned to no one.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-5</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to act as part of the operating system must be assigned to no one.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Acting as part of the operating permits privileged action to be undertaken</para></listitem>
<listitem><para>Privileged action may be used to subvert operating system controls</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to create a token object must not be assigned to any users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-8</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to create a token object must not be assigned to any users</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The ability to create a token object may undermine the authentication system</para></listitem>
<listitem><para>Unauthorised access may be obtained</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The user right to logon locally should be assigned to local groups and not to individual users</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-3</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The user right to logon locally should be assigned to local groups and not to individual users.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Assign the right to a local group</para></listitem>
<listitem><para>Assign users to the group</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Managing access rights by role simplfiies administration</para></listitem>
<listitem><para>Complex administration often results in unauthorised access.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The user right to change the system time should be assigned to local groups and not to individual user</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The user right to change the system time should be assigned to local groups and not to individual users.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Assign the right to a local group</para></listitem>
<listitem><para>Assign users to the group</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Reconstructing a set of events requires coinfidence in time sequencing</para></listitem>
<listitem><para>Certain elements of security infrastructure are sensitive to time</para></listitem>
<listitem><para>Changing the system time nay mask unauthorised activity</para></listitem>
<listitem><para>Changing the system time may result in unauthorised access</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The advanced user right to logon as a service must be assigned only to administrators</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-PRIV-14</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The advanced user right to logon as a service must be assigned only to administrators</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Identify all users who hold this right and revoke it.</para></listitem>
<listitem><para>Identify all applications who hold this right and determine why they need it and revoke it for all those where this requirement is clearly spurious</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The ability to create processes as a services can be used to subvert the security controls and gain unauthorised access</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>

</chapter>
<chapter><title>Security Compliance</title>

<section><title>Security Management</title>
<section><title>Antivirus software must be installed and maintained current on all machines</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-VIRUS-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ant-virus software must be installed and maintained on all mahines.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Install anti-virus software on all machines.</para></listitem>
<listitem><para>Ensure that the virus engine and signature data files are maintained up to date</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Virus infections can often subvert system security controls</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Ensure that a legal notice appropriate to your jurisdiction is displayed in the legal notice placeholded for display prior to logon</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-LEGAL-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Ensure that a legal notice appropriate to your jurisdiction is displayed in the legal notice placeholded for display prior to logon</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Determine the most appropriate legal noice to implement for your jurisdiction</para></listitem>
<listitem><para>Populate the legal notice placeholder with this message for display prior to logon</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Legal action following a subjected breach may prove problematic</para></listitem>
<listitem><para>Monitoring of authorised use may prove problematic</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
</chapter>

<chapter><title>Network Security Configuration</title>
<section><title>Network Interface Considerations</title>
<section><title>FTP should not be installed or if part of the default image it should be disabled</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-NETW-1</para></entry><entry><para>1.0</para></entry><entry><para>above baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>FTP should not be installed or if part of the default image it should be disabled</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Build a server, w/s or domain controller image that does not include ftp by default</para></listitem>
<listitem><para>Alternatively, disable ftp on w/s, servers and controllers where not needed</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>

</chapter>




<chapter><title>Configuration</title>
<section><title>Files and File Permissions</title>
<section><title>Use encryption for sensitive data files</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-FILE-1</para></entry><entry><para>1.0</para></entry><entry><para>above baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Sensitive data files must be encrypted.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Use an encryption tool or an encrypted file system to store sensitive data files. </para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Sensitive data files will be accessible using non-standard tools when the NT operating system does not have control.</para></listitem>
<listitem><para>Sensitive data files which have been deleted may be accessible using non-standard tools when the NT operating system does not have control.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
<section><title>Administration</title>
<section><title>Clear Page File at Shutdown</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-ADM-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Enable clearing of the system page file at shutdown.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SessionManager\Memory Management\ClearPageFileAtShutdown to 1.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Sensitive information, including local and remote passwords and business information, may remain in the pagefile after shutdown. This may be recoverable by an attacker who has physical access to the machine.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>

</chapter>

<chapter><title>Installation</title>
<section><title>Setup Choices</title>
<section><title>Do not use dual-boot</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-SETUP-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>NT must be the only operating system installed. The system must not be set up to dual-boot other operating systems.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Remove other operating systems by formatting partitions to NTFS prior to installation.</para></listitem>
<listitem><para>Ensure that boot.ini automatically boots NT, and that it lists no other operating systems.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Filesystems will not be protected by NT ACLs.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Restrict access to alternate boot mechanisms</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-SETUP-3</para></entry><entry><para>1.0</para></entry><entry><para>above baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Only authorised users must be able to boot the system from alternative media (CD, floppy disk).</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure that the BIOS boot order boots from the hard disk before CD, floppy, or other bootable devices.</para></listitem>
<listitem><para>Assign a BIOS password to prevent changes to the boot order, and restrict access to the BIOS password to authorised personnel.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>NT ACLs may be bypassed by booting an alternative operating system.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Delete $WinNT$.inf files</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-SETUP-4</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>For unattended setups the $WinNT$.inf file should be deleted.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Ensure any $WinNT$.inf files are removed after an unattended installation.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>The username and password of the user used to add the machine to the domain may be exposed.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Installation disk image duplication</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-SETUP-5</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Do not install by duplicating a previous disk image, unless the disk image copy tool used is NT-aware and capable of assigning a unique machine SID after duplication.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Do not install using a disk image duplication.</para></listitem>
<listitem><para>Or, if using disk image duplication, ensure that the disk image duplication tool is NT-aware and able to assign unique machine SIDs after duplication.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Machines and user accounts will have duplicate SIDs, undermining the security enforcement of NT.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Format all disk partitions with NTFS</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-SETUP-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>All filesystem partitions must be formatted prior to installation as NTFS.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Choose Format as NTFS from setup menus.</para></listitem>
<listitem><para>Do not use FAT partitions during installation, format as NTFS during installation.</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Filesystems will not be protected by NT ACLs.</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Do not use HPFS or FAT file structures. Always use NTFS.</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-SETUP-6</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Do not use HPFS or FAT file structures. Always use NTFS.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Opt for using NTFS alone during system commissioning</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Other file structures do not consistently support windows NT access control</para></listitem>
<listitem><para>The use of other file structures may be used to subvert security controls</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
</chapter>
<chapter><title>Auditing and Monitoring</title>

<section><title>Audit log destination and format</title>
<section><title>Security event logging must be enabled and not set to overwrite events</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-AUDIT-4</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Security event logging must be enabled and not set to overwrite events</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Switch security event logging on</para></listitem>
<listitem><para>Configure event logging so as not to overwrite events</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Reconstruction of a sequence of a sequence of events requires events to be recorded</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
<section><title>Events to be audited</title>
<section><title>Set up file auditing for group everyone</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-AUDIT-3</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>File auditing for group everyone should be set up to record failed attempts for read, write, execute and success and failure for delete, change permissions and take ownership.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up file auditing for group everyone as follows;</para></listitem>
<listitem><para>Read - Audit failed attempts</para></listitem>
<listitem><para>Write - Audit failed  attempts</para></listitem>
<listitem><para>Execute - Audit failed attempts</para></listitem>
<listitem><para>Delete - Audit failure and success</para></listitem>
<listitem><para>Change Permissions - Audit failure and success</para></listitem>
<listitem><para>Take Ownership - Audit failure and success</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Reconstructing a sequence of events requires certain events to be recorded</para></listitem>
<listitem><para>Failing to record certain events may allow a breach or a failure to go undetected</para></listitem>
<listitem><para>Failing to record certain events may prevent successful recovery from a breach or a failure</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Set up directory auditing for group everyone</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-AUDIT-2</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Set up directory auditing for group everyone such that failed attempts are recorded for read, write, execute and failed and successful attempts are recorded for delete, change permissions and take ownership.</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up directory auditing for group everyone as follows;</para></listitem>
<listitem><para>Read - Audit failed attempts</para></listitem>
<listitem><para>Write - Audit failed attempts</para></listitem>
<listitem><para>Execute - Audit failed attempts</para></listitem>
<listitem><para>Delete - Audit failure and success</para></listitem>
<listitem><para>Change Permissions - Audit failure and success</para></listitem>
<listitem><para>Take Ownership - Audit failure and success</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Without an audit trail of activity reconstructing misuse cannot be achieved</para></listitem>
<listitem><para>A loss of accountability may occur</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Network alerts must be enabled for excessive login failures</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-AUDIT-5</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Network alerts must be enabled for excessive login failures</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Configure network alerts for excessive login failures</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Non-interactive/network login failures may be indicative of an attack</para></listitem>
<listitem><para>Non-interactive/network login failures may be indicative of a failed service</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>The audit policy must be set up to record failure and success for Logon and Logoff, User and Group Management, Security Policy Changes, Restart, Shutdown and System and failure for File and Object Access</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NT4GEN-AUDIT-1</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>mandatory</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>The audit policy must be set up to record failure and success for Logon and Logoff, User and Group Management, Security Policy Changes, Restart, Shutdown and System and failure for File and Object Access</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up audit policy as follows;</para></listitem>
<listitem><para>Logon and Logoff	Audit failure and success</para></listitem>
<listitem><para>File and Object Access	Audit failure</para></listitem>
<listitem><para>User and Group Management	Audit failure and success</para></listitem>
<listitem><para>Security Policy Changes	Audit failure and success</para></listitem>
<listitem><para>Restart, Shutdown and System	Audit failure and success</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Capturing events allows an audit trail of activity to be created</para></listitem>
<listitem><para>A failure to capture events prevents abnormal activity from being identified</para></listitem>
<listitem><para>This allows an attackers behviour to go unnoticed.</para></listitem>
<listitem><para>Failing to record security events may result in a loss of accountability</para></listitem>
<listitem><para>A loss of accountability makes it difficult to determine the nature of a breach</para></listitem>
<listitem><para>This may result in regulatory compliance breaches</para></listitem>
<listitem><para>This may make legal action problematic to pursue</para></listitem>
<listitem><para>This may make reconstructing the system securely difficult to achieve</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
<section><title>Set up registry key auditing for group everyone</title><informaltable><tgroup cols="4" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="1*" colname="c2"/><colspec colwidth="1*" colname="c3"/><colspec colwidth="1*" colname="c4"/><thead><row><entry><para>ID</para></entry><entry><para>Version</para></entry><entry><para>Level</para></entry><entry><para>Enforcement</para></entry></row></thead><tbody><row><entry><para>NTGEN-AUDIT-4</para></entry><entry><para>1.0</para></entry><entry><para>baseline</para></entry><entry><para>recommended</para></entry></row></tbody></tgroup></informaltable><section><title>Standard</title><para>Registry key auditing should be set up to not audit query value, create subkey, read control, to audit successful attempts to set value, enumerate subkeys, notify, create link, delete and to audit successful and unsucessful attempts to write DAC</para></section><section><title>Detailed Steps</title><itemizedlist>
<listitem><para>Set up registry key auditing as follows;</para></listitem>
<listitem><para>Query Value - Not audited</para></listitem>
<listitem><para>Set Value - Audit successful attempts</para></listitem>
<listitem><para>Create Subkey - Not audited</para></listitem>
<listitem><para>Enumerate Subkeys - Audit successful attempts</para></listitem>
<listitem><para>Notify - Audit successful attempts</para></listitem>
<listitem><para>Create Link - Audit successful attempts</para></listitem>
<listitem><para>Delete - Audit successful attempts</para></listitem>
<listitem><para>Write DAC - Audit successful and unsuccessful attempts</para></listitem>
<listitem><para>Read Control - Not audited</para></listitem>
</itemizedlist></section><section><title>Risks Addressed</title><para>Where this control is not applied, the following residual risks exist:</para><itemizedlist>
<listitem><para>Reconstructing a sequence of evnts requires events to be recorded</para></listitem>
<listitem><para>Business information may be accidentally or maliciously altered.</para></listitem>
<listitem><para>Business information may be disclosed.</para></listitem>
<listitem><para>Business information and applications may be unavailable.</para></listitem>
</itemizedlist></section></section>
</section>
</chapter>

<chapter><title>Checklist</title><informaltable><tgroup cols="3" colsep="1" rowsep="1"><colspec colwidth="1*" colname="c1"/><colspec colwidth="5*" colname="c2"/><colspec colwidth="1*" colname="c3"/><spanspec align="left" nameend="c3" namest="c1" spanname="hspan"/><tbody><row><entry align="center" spanname="hspan"><para><emphasis>User Configuration</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>User Administration</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-UC-1</entry><entry>Is access to login scripts and profiles restricted only to their user and administrators?
</entry><entry><para/></entry></row><row><entry spanname="hspan"><para><emphasis>Default Accounts</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-DA-2</entry><entry>Has the administrator account been renamed to an attributable account name and the password changed?</entry><entry><para/></entry></row><row><entry>NT4GEN-DA-1</entry><entry>Has the guest account been disabled?
</entry><entry><para/></entry></row><row><entry spanname="hspan"><para><emphasis>Privileges</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-PRIV-13</entry><entry>Is the advanced user right to load and unload device drivers assigned to any users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-7</entry><entry>Is the advanced user right to create a page file assigned to any users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-6</entry><entry>Is the advanced user right to bypass traverse checking assigned to any users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-16</entry><entry>Is the advanced user right to profile single process assigned only to administrators?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-19</entry><entry>Is the advanced user right to repace a system level process token assigned to any user?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-9</entry><entry>Is the advanced user right to create permanent shared objects assigned to any users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-11</entry><entry>Is the advanced user right to generate security audits assigned to any users other than the administrators or security users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-10</entry><entry>Is the advanced user right to debug programs assigned only to adminisrators and developers?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-4</entry><entry>Is the user right to shutdown the system assigned to local groups and not to individual users</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-17</entry><entry>Is the advanced user right to profile system performance assigned only to administrators?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-18</entry><entry>Is the advanced user right to receive unsolicited device input assigned to no users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-2</entry><entry>Is the user right to force shutdown from a remote system assigned to local groups and not to individual users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-12</entry><entry>Is the advanced user right to increase scheduling priority assigned only to administrators?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-15</entry><entry>Is the advanced user right to modify firmware environment variables assigned only to administrators?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-5</entry><entry>Is the advanced user right to act as part of the operating system assigned to any one?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-8</entry><entry>Is the advanced user right to create a token object assigned to any users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-3</entry><entry>Is the user right to logon locally assigned to local groups and not to individual users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-1</entry><entry>Is the user right to change the system time assigned to local groups and not to individual users?</entry><entry><para/></entry></row><row><entry>NT4GEN-PRIV-14</entry><entry>Is the advanced user right to logon as a service assigned only to administrators?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Security Compliance</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Security Management</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-VIRUS-1</entry><entry>Is ant-virus software installed and maintained on all machines?</entry><entry><para/></entry></row><row><entry>NT4GEN-LEGAL-1</entry><entry>Ensure that a legal notice appropriate to your jurisdiction is displayed in the legal notice placeholded for display prior to logon</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Network Security Configuration</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Network Interface Considerations</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-NETW-1</entry><entry>Is FTP installed or if part of the default image is it disabled?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Configuration</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Files and File Permissions</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-FILE-1</entry><entry>Are sensitive data files encrypted?
</entry><entry><para/></entry></row><row><entry spanname="hspan"><para><emphasis>Administration</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-ADM-1</entry><entry>Has clearing of the system page file at shutdown been enabled?
</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Installation</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Setup Choices</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-SETUP-2</entry><entry>Is NT the only operating system installed?
</entry><entry><para/></entry></row><row><entry>NT4GEN-SETUP-3</entry><entry>Has access to alternative boot mechanisms been physically and/OR BIOS password restricted?
</entry><entry><para/></entry></row><row><entry>NT4GEN-SETUP-4</entry><entry>For unattended setups, has the $WinNT$.inf file been deleted after installation?
</entry><entry><para/></entry></row><row><entry>NT4GEN-SETUP-5</entry><entry>For installations using disk image duplication, has the machine been assigned a unique SID?
</entry><entry><para/></entry></row><row><entry>NT4GEN-SETUP-1</entry><entry>Are all partitions formatted as NTFS?
</entry><entry><para/></entry></row><row><entry>NT4GEN-SETUP-6</entry><entry>Are there any FAT or HPFS partitions on the system?</entry><entry><para/></entry></row><row><entry align="center" spanname="hspan"><para><emphasis>Auditing and Monitoring</emphasis></para></entry></row><row><entry spanname="hspan"><para><emphasis>Audit log destination and format</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-AUDIT-4</entry><entry>Is security event logging enabled and set so as not to overwrite events?</entry><entry><para/></entry></row><row><entry spanname="hspan"><para><emphasis>Events to be audited</emphasis></para></entry></row><row><entry><para><emphasis>Control ID</emphasis></para></entry><entry><para><emphasis>Checklist Question</emphasis></para></entry><entry><para><emphasis>Your Answer</emphasis></para></entry></row><row><entry>NT4GEN-AUDIT-3</entry><entry>Has file auditing been set up for group everyone?</entry><entry><para/></entry></row><row><entry>NT4GEN-AUDIT-2</entry><entry>Has directory auditing for group everyone been set up in accordance with policy?</entry><entry><para/></entry></row><row><entry>NT4GEN-AUDIT-5</entry><entry>Are network alerts enabled for excessive login failures?</entry><entry><para/></entry></row><row><entry>NT4GEN-AUDIT-1</entry><entry>Has the audit policy been set up to record the events defined in the audit policy?</entry><entry><para/></entry></row><row><entry>NTGEN-AUDIT-4</entry><entry>Has registry key auditing been set up in accordance with policy?</entry><entry><para/></entry></row></tbody></tgroup></informaltable></chapter></book>
