Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • Windows Defender Firewall with Advanced Security must log dropped packets when connected to a public network.

    A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of dropped packets for a public network connection will be enabled to main...
    Rule Low Severity
  • SRG-OS-000327-GPOS-00127

    Group
  • Windows Defender Firewall with Advanced Security must log successful connections when connected to a public network.

    A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Logging of successful connections for a public network connection will be enabled ...
    Rule Low Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • Inbound exceptions to the firewall on domain workstations must only allow authorized remote management hosts.

    Allowing inbound access to domain workstations from other systems may allow lateral movement across systems if credentials are compromised. Limiting inbound connections only from authorized remote ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules