19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

<strong>Recommended</strong> <strong>Baseline</strong> <strong>Security</strong> (ITSG-20)<br />

4.7.6 Variance from Microsoft Guidance<br />

The following table provides a list of settings that differ between the CSE guidance and<br />

Microsoft guidance. The parameter is identified along with the CSE value and Microsoft value.<br />

Table 3 – Variance from Microsoft Member <strong>Server</strong> <strong>Baseline</strong><br />

# Parameter CSE Value Microsoft Value<br />

1 Minimum Password Length 8 12<br />

2 Audit Policy Change Success/Fail Success<br />

3 Audit System Events Success/Fail Success<br />

4 Add Workstations to Domain None Administrators<br />

5 Backup Files and Directories Backup Operators and<br />

Administrators<br />

6 Bypass Traverse Checking Users, Backup<br />

Operators,Administrators and<br />

Authenticated Users<br />

Default<br />

Default<br />

7 Create a Pagefile Administrators Default<br />

8 Create a Token Object None Default<br />

9 Create Global Objects Service and Administrators Default<br />

10 Create Permanent Shared Objects None Default<br />

11 Deny Logon as a Service Guests, Anonymous Logon,<br />

Administrators, Built-in<br />

Administrator,<br />

Support_388945a0 and Guest<br />

12 Deny Logon Locally Guests, Anonymous Logon,<br />

Built-in Administrator,<br />

Support_388945a0 and Guest<br />

Default<br />

Default<br />

13 Force shutdown from remote<br />

system<br />

None<br />

Administrators<br />

14 Lock Pages in Memory None Administrators<br />

15 Logon as a Service Network Service and Local<br />

Service<br />

Default<br />

16 Administrator Account Status Disabled Enabled<br />

17 Interactive logon: Message text for<br />

users attempting to logon<br />

18 Interactive logon: Message title for<br />

users attempting to log on<br />

19 Interactive Logon: Require Smart<br />

Card<br />

Departmental entry<br />

required<br />

Departmental entry<br />

required<br />

Do not require smart card<br />

“This system is restricted….”<br />

“IT IS AN OFFENSE….”<br />

Default<br />

<strong>Server</strong> Policy Files March 2004 111

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!