Level II Assessment Forms

The following forms, as shown in Tables B.5, B.6, and B.7, can be used when assessing servers and during system demonstrations.

Table B.5. Password Controls
Password ActionRecommended ValueActual Value
Enforce password history10 days 
Maximum password age30 days 
Minimum password age1 day 
Minimum password length7 characters 
Passwords must meet complexityEnabled 
Account lockout thresholdAfter 3 attempts 

Table B.6. Audit Controls
AuditingRecommended ValueActual Value
Audit system eventsSuccess and failure 
Audit process trackingNone 
Audit privilege useFailure 
Audit account logon eventsFailure 
Audit account managementSuccess and failure 
Audit directory service accessNone 
Audit logon eventsFailure 
Audit object accessSuccess 
Audit policy changeFailure 

Table B.7. Access Options and Controls
Access OptionsRecommended ValueActual Value
Rename administrator accountRename 
Audit the use of backup and restore privilegeEnabled 
Shut down system immediately if unable to log security auditsEnabled 
Do not display last usernameEnabled 
Display message text for users attempting to log onEnabled 
Message title for users attempting to log onEnabled 
Prompt user to change password before expiration1 week 
Network access: Do not allow anonymous enumeration of SAM accountsEnabled 
Can shares be accessed anonymouslyNo 
Force logoff when logon hours expireEnabled 
Suspend session time30 minutes 
Do not display last usernameEnabled 
Restrict floppy, CD-ROM, and USB portsEnabled 

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset