Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000480-GPOS-00227

    Group
  • Enhanced anti-spoofing for facial recognition must be enabled on Windows 11.

    Enhanced anti-spoofing provides additional protections when using facial recognition with devices that support it.
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    Group
  • Microsoft consumer experiences must be turned off.

    Microsoft consumer experiences provides suggestions and notifications to users, which may include the installation of Windows Store apps. Organizations may control the execution of applications thr...
    Rule Low Severity
  • SRG-OS-000134-GPOS-00068

    Group
  • Administrator accounts must not be enumerated during elevation.

    Enumeration of administrator accounts when elevating can provide part of the logon information to an unauthorized user. This setting configures the system to always require users to type in a usern...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • Enhanced diagnostic data must be limited to the minimum required to support Windows Analytics.

    Some features may communicate with the vendor, sending system information or downloading data or components for the feature. Limiting this capability will prevent potentially sensitive information ...
    Rule Medium Severity
  • SRG-OS-000205-GPOS-00083

    Group
  • Windows Telemetry must not be configured to Full.

    Some features may communicate with the vendor, sending system information or downloading data or components for the feature. Limiting this capability will prevent potentially sensitive information ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules