Logo
Main site Submit a request Sign in
  1. Help Central | G5 Cyber Security
  2. Security Hardening
  3. DISA Windows Server 2012 and 2012 R2 DC STIG v3r3

DISA Windows Server 2012 and 2012 R2 DC STIG v3r3

Follow New articles New articles and comments
  • WN12-00-000001 - Server systems must be located in a controlled access area, accessible only to authorized personnel.
  • WN12-00-000004 - Users with administrative privilege must be documented.
  • WN12-00-000005 - Users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.
  • WN12-00-000006 - Policy must require that system administrators (SAs) be trained for the operating systems used by systems under their control.
  • WN12-00-000007 - Windows 2012/2012 R2 password for the built-in Administrator account must be changed at least annually or when a member of the administrative team leaves the organization.
  • WN12-00-000008 - Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.
  • WN12-00-000009-01 - Members of the Backup Operators group must be documented.
  • WN12-00-000009-02 - Members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks.
  • WN12-00-000010 - Policy must require application account passwords be at least 15 characters in length.
  • WN12-00-000011 - Windows 2012/2012 R2 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization.
  • WN12-00-000012 - Shared user accounts must not be permitted on the system.
  • WN12-00-000013 - Security configuration tools or equivalent processes must be used to configure and maintain platforms for security compliance.
  • WN12-00-000014 - System-level information must be backed up in accordance with local recovery time and recovery point objectives.
  • WN12-00-000015 - User-level information must be backed up in accordance with local recovery time and recovery point objectives.
  • WN12-00-000016 - Backups of system-level information must be protected.
  • WN12-00-000017 - System-related documentation must be backed up in accordance with local recovery time and recovery point objectives.
  • WN12-00-000018 - The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
  • WN12-00-000019 - Protection methods such as TLS, encrypted VPNs, or IPSEC must be implemented if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process.
  • WN12-00-000020 - Systems requiring data at rest protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest.
  • WN12-00-000100 - The Windows 2012 / 2012 R2 system must use an anti-virus program.
  • WN12-00-000160 - The Server Message Block (SMB) v1 protocol must be disabled on Windows 2012 R2.
  • WN12-00-000170 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB server.
  • WN12-00-000180 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB client - LanManWorkstation
  • WN12-00-000180 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB client - mrxsmb10
  • WN12-00-000190 - Orphaned security identifiers (SIDs) must be removed from user rights on Windows 2012 / 2012 R2.
  • WN12-00-000200 - Windows PowerShell must be updated to a version that supports script block logging on Windows 2012/2012 R2.
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Enabled
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-00-000220 - Windows PowerShell 2.0 must not be installed on Windows 2012/2012 R2.
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
  • 1
  • 2
  • ›
  • »

© Help Central | G5 Cyber Security