Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000423-GPOS-00187

    Group
  • The setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.

    The server message block (SMB) protocol provides the basis for many network operations. Digitally signed SMB packets aid in preventing man-in-the-middle attacks. If this policy is enabled, the SMB ...
    Rule Medium Severity
  • SRG-OS-000423-GPOS-00187

    Group
  • The setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.

    The server message block (SMB) protocol provides the basis for many network operations. Digitally signed SMB packets aid in preventing man-in-the-middle attacks. If this policy is enabled, the SMB ...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • Anonymous SID/Name translation must not be allowed.

    Allowing anonymous SID/Name translation can provide sensitive information for accessing a system. Only authorized users must be able to perform such translations.
    Rule High Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • Anonymous enumeration of Security Account Manager (SAM) accounts must not be allowed.

    Anonymous enumeration of SAM accounts allows anonymous logon users (null session connections) to list all accounts names, thus providing a list of potential points to attack the system.
    Rule High Severity
  • SRG-OS-000138-GPOS-00069

    Group
  • Anonymous enumeration of shares must not be allowed.

    Allowing anonymous logon users (null session connections) to list all account names and enumerate all shared resources can provide a map of potential points to attack the system.
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules