19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Unclassified ITSG for <strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

4.4 Local Policies<br />

4.4.1 Audit Policy<br />

4.4.1.1 Audit account logon events<br />

AuditAccountLogon = 3<br />

The ‘AuditAccountLogon’ defines types of logon events to audit. The setting ‘3’ audits ‘success’<br />

and ‘fail’ events. ‘Success’ events can determine who accessed the system during an incident.<br />

‘Fail’ events provide insight to password guessing attacks.<br />

4.4.1.2 Audit account management<br />

AuditAccountManage = 3<br />

The ‘AuditAccountManage’ defines types of logon events to audit. The setting ‘3’ audits<br />

‘success’ and ‘fail’ events. ‘Success’ events can be used in investigations, monitoring accounts at<br />

the time of an incident. ‘Fail’ attempts can determine if users are probing the system for<br />

vulnerabilities.<br />

4.4.1.3 Audit directory service access<br />

AuditDSAccess = 3<br />

The ‘AuditDSAccess‘ defines types of logon events to audit. The setting ‘3’ audits ‘success’ and<br />

‘fail’ events. The Directory Service holds crucial information for the Domain. Knowledge of<br />

access during an incident can provide valuable information about Active Directory objects<br />

accessed during an attack.<br />

4.4.1.4 Audit logon events<br />

AuditLogonEvents = 3<br />

The ‘AuditLogonEvents’ defines types of logon events to audit. The setting ‘3’ audits ‘success’<br />

and ‘fail’ events. ‘Success’ events can be used to determine who was accessing the system<br />

during an incident. ‘Fail’ logon attempts can determine if the system is under a password<br />

guessing attack.<br />

4.4.1.5 Audit object access<br />

AuditObjectAccess = 2<br />

The ‘AuditObjectAccess’ defines the type of logon events that will be audited. The setting ‘2’<br />

audits failed events. Failed attempts can be monitored to determine if any users are probing the<br />

system for vulnerabilities.<br />

48 March 2004 <strong>Server</strong> Policy Files

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!