Microsoft Windows Defender Firewall with Advanced Security Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must be enabled when connected to a private network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. This setti...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must be enabled when connected to a public network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. This setti...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a domain.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Unsolicite...Rule High Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must allow outbound connections, unless a rule explicitly blocks the connection when connected to a domain.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Outbound c...Rule Medium Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security log size must be configured for domain connections.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. The firewa...Rule Low Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must log dropped packets when connected to a domain.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of...Rule Low Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must log successful connections when connected to a domain.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of...Rule Low Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a private network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Unsolicite...Rule High Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must allow outbound connections, unless a rule explicitly blocks the connection when connected to a private network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Outbound c...Rule Medium Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security log size must be configured for private network connections.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. The firewa...Rule Low Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must log dropped packets when connected to a private network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of...Rule Low Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must log successful connections when connected to a private network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of...Rule Low Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a public network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Unsolicite...Rule High Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must allow outbound connections, unless a rule explicitly blocks the connection when connected to a public network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Outbound c...Rule Medium Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security local firewall rules must not be merged with Group Policy settings when connected to a public network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Local fire...Rule Medium Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security local connection rules must not be merged with Group Policy settings when connected to a public network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Local conn...Rule Medium Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security log size must be configured for public network connections.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. The firewa...Rule Low Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must log dropped packets when connected to a public network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of...Rule Low Severity -
SRG-OS-000327-GPOS-00127
<GroupDescription></GroupDescription>Group -
Windows Defender Firewall with Advanced Security must log successful connections when connected to a public network.
<VulnDiscussion>A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of...Rule Low Severity -
SRG-OS-000480-GPOS-00227
<GroupDescription></GroupDescription>Group -
Inbound exceptions to the firewall on domain workstations must only allow authorized remote management hosts.
<VulnDiscussion>Allowing inbound access to domain workstations from other systems may allow lateral movement across systems if credentials ar...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.