Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 38 checks on this page
- Ensure 'Access Credential Manager as a trusted caller' Is Set To No One
- Ensure 'Access this computer from the network' Is Set To 'Administrators, Remote Desktop Users'
- Ensure 'Act as part of the operating system' Is Set To No One
- Ensure 'Adjust memory quotas for a process' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE'
- Ensure 'Allow log on locally' Is Set To 'Administrators, Users'
- Ensure 'Allow log on through Remote Desktop Services' Is Set To 'Administrators, Remote Desktop Users'
- Ensure 'Back up files and directories' Is Set To 'Administrators'
- Ensure 'Change the system time' Is Set To 'Administrators, LOCAL SERVICE'
- Ensure 'Create a pagefile' Is Set To 'Administrators'
- Ensure 'Create a token object' Is Set To No One
- Ensure 'Create global objects' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'
- Ensure 'Create permanent shared objects' Is Set To No One
- Ensure 'Create symbolic links' Is Set To 'Administrators'
- Ensure 'Debug programs' Is Set To 'Administrators'
- Ensure 'Deny access to this computer from the network' Is Set To Include Guests
- Ensure 'Deny log on as a batch job' Is Set To Include Guests
- Ensure 'Deny log on as a service' Is Set To Include Guests
- Ensure 'Deny log on locally' Is Set To Include Guests
- Ensure 'Deny log on through Remote Desktop Services' Is Set To Include Guests
- Ensure 'Enable computer and user accounts to be trusted for delegation' Is Set To No One
- Ensure 'Force shutdown from a remote system' Is Set To 'Administrators'
- Ensure 'Generate security audits' Is Set To 'LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService'
- Ensure 'Impersonate a client after authentication' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'
- Ensure 'Increase scheduling priority' Is Set To 'Administrators, Window Manager\Window Manager Group'
- Ensure 'Load and unload device drivers' Is Set To 'Administrators'
- Ensure 'Lock pages in memory' Is Set To No One
- Ensure 'Log on as a batch job' Is Set To 'Administrators'
- Ensure 'Log on as a service' Is Set To No One
- Ensure 'Manage auditing and security log' Is Set To 'Administrators'
- Ensure 'Modify an object label' Is Set To No One
- Ensure 'Modify firmware environment values' Is Set To 'Administrators'
- Ensure 'Perform volume maintenance tasks' Is Set To 'Administrators'
- Ensure 'Profile single process' Is Set To 'Administrators'
- Ensure 'Profile system performance' Is Set To 'Administrators, NT SERVICE\WdiServiceHost'
- Ensure 'Replace a process level token' Is Set To 'LOCAL SERVICE, NETWORK SERVICE'
- Ensure 'Restore files and directories' Is Set To 'Administrators'
- Ensure 'Shut down the system' Is Set To 'Administrators, Users'
- Ensure 'Take ownership of files or other objects' Is Set To 'Administrators'
Ensure 'Access Credential Manager as a trusted caller' Is Set To No One
Finding: 'Access Credential Manager as a trusted caller' is assigned to one or more accounts.
Checks which accounts hold the right used by Credential Manager during backup and restore.
This rule fails when seTrustedCredManAccessPrivilege is assigned to any account.
Rationale: Only Winlogon needs this right; granting it lets an account retrieve another user's saved credentials.
Impact: None; no account requires this right by default.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Access Credential Manager as a trusted caller' to No One.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure 'Access this computer from the network' Is Set To 'Administrators, Remote Desktop Users'
Finding: 'Access this computer from the network' is not restricted to Administrators, Remote Desktop Users.
Checks which accounts may connect to this computer over the network.
This rule fails when the accounts assigned to seNetworkLogonRight are not exactly Administrators, Remote Desktop Users.
Rationale: Accounts able to reach the machine over the network can access resources they are permitted to; the set should be limited to administrators and remote desktop users.
Impact: Only the listed groups can access the computer across the network.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Access this computer from the network' to Administrators, Remote Desktop Users.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure 'Act as part of the operating system' Is Set To No One
Finding: 'Act as part of the operating system' is assigned to one or more accounts.
Checks which accounts may act as part of the operating system.
This rule fails when seTcbPrivilege is assigned to any account.
Rationale: This right lets a process assume any user identity and take complete control of the computer.
Impact: None; the right is rarely required by any legitimate account.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Act as part of the operating system' to No One.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Adjust memory quotas for a process' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE'
Finding: 'Adjust memory quotas for a process' is not restricted to Administrators, LOCAL SERVICE, NETWORK SERVICE.
Checks which accounts may adjust the memory quota available to a process.
This rule fails when the accounts assigned to seIncreaseQuotaPrivilege are not exactly Administrators, LOCAL SERVICE, NETWORK SERVICE.
Rationale: An account with this right can starve processes of memory and disrupt business-critical applications.
Impact: Only the listed principals can adjust process memory quotas.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Adjust memory quotas for a process' to Administrators, LOCAL SERVICE, NETWORK SERVICE.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Allow log on locally' Is Set To 'Administrators, Users'
Finding: 'Allow log on locally' is not restricted to Administrators, Users.
Checks which accounts may log on interactively at the console.
This rule fails when the accounts assigned to seInteractiveLogonRight are not exactly Administrators, Users.
Rationale: Restricting local logon prevents unauthorized users from signing in at the machine's console.
Impact: Only administrators and standard users can log on locally.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Allow log on locally' to Administrators, Users.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure 'Allow log on through Remote Desktop Services' Is Set To 'Administrators, Remote Desktop Users'
Finding: 'Allow log on through Remote Desktop Services' is not restricted to Administrators, Remote Desktop Users.
Checks which accounts may log on through Remote Desktop Services.
This rule fails when the accounts assigned to seRemoteInteractiveLogonRight are not exactly Administrators, Remote Desktop Users.
Rationale: Limiting RDP logon to administrators and remote desktop users reduces the remote attack surface.
Impact: Only the listed groups can sign in over Remote Desktop.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Allow log on through Remote Desktop Services' to Administrators, Remote Desktop Users.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure 'Back up files and directories' Is Set To 'Administrators'
Finding: 'Back up files and directories' is not restricted to Administrators.
Checks which accounts may bypass file and directory permissions to perform backups.
This rule fails when the accounts assigned to seBackupPrivilege are not exactly Administrators.
Rationale: This right bypasses ACLs; a non-administrator could copy protected data off the system.
Impact: Only administrators can back up files and directories.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Back up files and directories' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure 'Change the system time' Is Set To 'Administrators, LOCAL SERVICE'
Finding: 'Change the system time' is not restricted to Administrators, LOCAL SERVICE.
Checks which accounts may change the system clock.
This rule fails when the accounts assigned to seSystemtimePrivilege are not exactly Administrators, LOCAL SERVICE.
Rationale: Altering the clock can invalidate event-log and file timestamps and disrupt time-based authentication.
Impact: Only administrators and LOCAL SERVICE can change the system time.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Change the system time' to Administrators, LOCAL SERVICE.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure 'Create a pagefile' Is Set To 'Administrators'
Finding: 'Create a pagefile' is not restricted to Administrators.
Checks which accounts may create or resize the pagefile.
This rule fails when the accounts assigned to seCreatePagefilePrivilege are not exactly Administrators.
Rationale: Mis-sizing or relocating the pagefile can degrade system performance.
Impact: Only administrators can create a pagefile.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Create a pagefile' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Create a token object' Is Set To No One
Finding: 'Create a token object' is assigned to one or more accounts.
Checks which accounts may create access tokens.
This rule fails when seCreateTokenPrivilege is assigned to any account.
Rationale: An account with this right can craft tokens granting itself elevated access and fully compromise the host.
Impact: None; no account requires this right by default.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Create a token object' to No One.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Create global objects' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'
Finding: 'Create global objects' is not restricted to Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE.
Checks which accounts may create global objects available to all sessions.
This rule fails when the accounts assigned to seCreateGlobalPrivilege are not exactly Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE.
Rationale: Global objects can interfere with services and processes running under other accounts.
Impact: Only the listed principals can create global objects.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Create global objects' to Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Create symbolic links' Is Set To 'Administrators'
Finding: 'Create symbolic links' is not restricted to Administrators.
Checks which accounts may create symbolic links.
This rule fails when the accounts assigned to seCreateSymbolicLinkPrivilege are not exactly Administrators.
Rationale: Symbolic-link creation can be abused for link-following attacks that redirect operations to other targets.
Impact: Only administrators can create symbolic links.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Create symbolic links' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Debug programs' Is Set To 'Administrators'
Finding: 'Debug programs' is not restricted to Administrators.
Checks which accounts may attach a debugger to any process or the kernel.
This rule fails when the accounts assigned to seDebugPrivilege are not exactly Administrators.
Rationale: Debug rights grant full access to process and kernel memory and are used to extract credentials and code.
Impact: Only administrators can debug programs.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Debug programs' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure 'Deny access to this computer from the network' Is Set To Include Guests
Finding: 'Deny access to this computer from the network' does not include the Guests group.
Checks that network logon is denied to the Guests group.
This rule fails when seDenyNetworkLogonRight does not include the Guests group.
Rationale: Blocking guest network logon prevents anonymous enumeration and access to shared resources.
Impact: Guests can no longer access the computer over the network.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Deny access to this computer from the network' to Guests.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure 'Deny log on as a batch job' Is Set To Include Guests
Finding: 'Deny log on as a batch job' does not include the Guests group.
Checks that batch-job logon is denied to the Guests group.
This rule fails when seDenyBatchLogonRight does not include the Guests group.
Rationale: Guests with batch logon could schedule resource-consuming or malicious jobs.
Impact: Guests can no longer log on as a batch job.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Deny log on as a batch job' to Guests.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Deny log on as a service' Is Set To Include Guests
Finding: 'Deny log on as a service' does not include the Guests group.
Checks that service logon is denied to the Guests group.
This rule fails when seDenyServiceLogonRight does not include the Guests group.
Rationale: Guests able to log on as a service could register unauthorized or malicious services.
Impact: Guests can no longer log on as a service.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Deny log on as a service' to Guests.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Deny log on locally' Is Set To Include Guests
Finding: 'Deny log on locally' does not include the Guests group.
Checks that local logon is denied to the Guests group.
This rule fails when seDenyInteractiveLogonRight does not include the Guests group.
Rationale: Guests able to log on locally could access the console and installed data.
Impact: Guests can no longer log on at the console.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Deny log on locally' to Guests.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure 'Deny log on through Remote Desktop Services' Is Set To Include Guests
Finding: 'Deny log on through Remote Desktop Services' does not include the Guests group.
Checks that Remote Desktop logon is denied to the Guests group.
This rule fails when seDenyRemoteInteractiveLogonRight does not include the Guests group.
Rationale: Guests able to log on over Remote Desktop could reach the remote console of the machine.
Impact: Guests can no longer sign in over Remote Desktop.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Deny log on through Remote Desktop Services' to Guests.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure 'Enable computer and user accounts to be trusted for delegation' Is Set To No One
Finding: 'Enable computer and user accounts to be trusted for delegation' is assigned to one or more accounts.
Checks which accounts may mark computer and user accounts as trusted for delegation.
This rule fails when seEnableDelegationPrivilege is assigned to any account.
Rationale: Misuse allows impersonation of other users and access to network resources under their identity.
Impact: None; this right is not required on a standalone workstation.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Enable computer and user accounts to be trusted for delegation' to No One.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure 'Force shutdown from a remote system' Is Set To 'Administrators'
Finding: 'Force shutdown from a remote system' is not restricted to Administrators.
Checks which accounts may shut the computer down remotely.
This rule fails when the accounts assigned to seRemoteShutdownPrivilege are not exactly Administrators.
Rationale: Anyone with this right could trigger a denial of service by shutting the machine down.
Impact: Only administrators can force a remote shutdown.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Force shutdown from a remote system' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Generate security audits' Is Set To 'LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService'
Finding: 'Generate security audits' is not restricted to LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService.
Checks which accounts may write records to the Security event log.
This rule fails when the accounts assigned to seAuditPrivilege are not exactly LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService.
Rationale: An account with this right could flood the Security log to hide malicious activity.
Impact: Only the listed service principals can generate security audit events.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Generate security audits' to LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure 'Impersonate a client after authentication' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'
Finding: 'Impersonate a client after authentication' is not restricted to Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService.
Checks which accounts may impersonate a client after authentication.
This rule fails when the accounts assigned to seImpersonatePrivilege are not exactly Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService.
Rationale: An account with this right could trick a client into connecting and then impersonate it.
Impact: Only the listed principals can impersonate an authenticated client.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Impersonate a client after authentication' to Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Increase scheduling priority' Is Set To 'Administrators, Window Manager\Window Manager Group'
Finding: 'Increase scheduling priority' is not restricted to Administrators, Window Manager\Window Manager Group.
Checks which accounts may raise the scheduling priority of a process.
This rule fails when the accounts assigned to seIncreaseBasePriorityPrivilege are not exactly Administrators, Window Manager\Window Manager Group.
Rationale: Raising a process to real-time priority can starve all other processes and cause a denial of service.
Impact: Only administrators and the Window Manager group can raise scheduling priority.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Increase scheduling priority' to Administrators, Window Manager\Window Manager Group.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Load and unload device drivers' Is Set To 'Administrators'
Finding: 'Load and unload device drivers' is not restricted to Administrators.
Checks which accounts may load and unload device drivers.
This rule fails when the accounts assigned to seLoadDriverPrivilege are not exactly Administrators.
Rationale: Drivers run as privileged kernel code; this right could be used to load malicious code into the kernel.
Impact: Only administrators can load and unload device drivers.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Load and unload device drivers' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Lock pages in memory' Is Set To No One
Finding: 'Lock pages in memory' is assigned to one or more accounts.
Checks which accounts may lock pages in physical memory.
This rule fails when seLockMemoryPrivilege is assigned to any account.
Rationale: Locking large amounts of memory can starve other processes and cause a denial of service.
Impact: None; no account requires this right by default.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Lock pages in memory' to No One.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Log on as a batch job' Is Set To 'Administrators'
Finding: 'Log on as a batch job' is not restricted to Administrators.
Checks which accounts may log on using the task scheduler service.
This rule fails when the accounts assigned to seBatchLogonRight are not exactly Administrators.
Rationale: Limiting batch logon reduces the ways scheduled tasks can be abused to run code.
Impact: Only administrators can log on as a batch job.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Log on as a batch job' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Log on as a service' Is Set To No One
Finding: 'Log on as a service' is assigned to one or more accounts.
Checks which accounts may register a process as a service.
This rule fails when seServiceLogonRight is assigned to any account.
Rationale: Service logon lets code run continuously even when no one is signed in and should be tightly controlled.
Impact: None; assign the right only to specific service accounts if a component requires it.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Log on as a service' to No One.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Persistence (TA0003)
Ensure 'Manage auditing and security log' Is Set To 'Administrators'
Finding: 'Manage auditing and security log' is not restricted to Administrators.
Checks which accounts may configure object auditing and clear the Security log.
This rule fails when the accounts assigned to seSecurityPrivilege are not exactly Administrators.
Rationale: This right allows clearing the Security log to erase evidence of an attack.
Impact: Only administrators can manage auditing and the Security log.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Manage auditing and security log' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure 'Modify an object label' Is Set To No One
Finding: 'Modify an object label' is assigned to one or more accounts.
Checks which accounts may change the integrity label of objects owned by others.
This rule fails when seRelabelPrivilege is assigned to any account.
Rationale: Changing an object's integrity label could cause code to run at a higher privilege than intended.
Impact: None; no account requires this right by default.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Modify an object label' to No One.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Modify firmware environment values' Is Set To 'Administrators'
Finding: 'Modify firmware environment values' is not restricted to Administrators.
Checks which accounts may modify system firmware environment values.
This rule fails when the accounts assigned to seSystemEnvironmentPrivilege are not exactly Administrators.
Rationale: Altering firmware values could misconfigure hardware and cause data corruption or failure.
Impact: Only administrators can modify firmware environment values.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Modify firmware environment values' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Perform volume maintenance tasks' Is Set To 'Administrators'
Finding: 'Perform volume maintenance tasks' is not restricted to Administrators.
Checks which accounts may perform volume and disk maintenance tasks.
This rule fails when the accounts assigned to seManageVolumePrivilege are not exactly Administrators.
Rationale: This right could be used to delete a volume, causing data loss or a denial of service.
Impact: Only administrators can perform volume maintenance tasks.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Perform volume maintenance tasks' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Profile single process' Is Set To 'Administrators'
Finding: 'Profile single process' is not restricted to Administrators.
Checks which accounts may profile the performance of individual processes.
This rule fails when the accounts assigned to seProfileSingleProcessPrivilege are not exactly Administrators.
Rationale: Process profiling could help an attacker identify critical processes to target.
Impact: Only administrators can profile a single process.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Profile single process' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure 'Profile system performance' Is Set To 'Administrators, NT SERVICE\WdiServiceHost'
Finding: 'Profile system performance' is not restricted to Administrators, NT SERVICE\WdiServiceHost.
Checks which accounts may profile overall system performance.
This rule fails when the accounts assigned to seSystemProfilePrivilege are not exactly Administrators, NT SERVICE\WdiServiceHost.
Rationale: System profiling could reveal critical processes an attacker may wish to target.
Impact: Only administrators and the diagnostics service host can profile system performance.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Profile system performance' to Administrators, NT SERVICE\WdiServiceHost.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure 'Replace a process level token' Is Set To 'LOCAL SERVICE, NETWORK SERVICE'
Finding: 'Replace a process level token' is not restricted to LOCAL SERVICE, NETWORK SERVICE.
Checks which accounts may replace the token of a process.
This rule fails when the accounts assigned to seAssignPrimaryTokenPrivilege are not exactly LOCAL SERVICE, NETWORK SERVICE.
Rationale: This right lets a caller start processes under other users' credentials, hiding unauthorized activity.
Impact: Only LOCAL SERVICE and NETWORK SERVICE can replace a process-level token.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Replace a process level token' to LOCAL SERVICE, NETWORK SERVICE.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Restore files and directories' Is Set To 'Administrators'
Finding: 'Restore files and directories' is not restricted to Administrators.
Checks which accounts may bypass permissions to restore files and directories.
This rule fails when the accounts assigned to seRestorePrivilege are not exactly Administrators.
Rationale: This right bypasses ACLs and could overwrite newer data or restore malicious files.
Impact: Only administrators can restore files and directories.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Restore files and directories' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure 'Shut down the system' Is Set To 'Administrators, Users'
Finding: 'Shut down the system' is not restricted to Administrators, Users.
Checks which accounts logged on locally may shut the system down.
This rule fails when the accounts assigned to seShutdownPrivilege are not exactly Administrators, Users.
Rationale: Shutdown should be available to authorized users but not to guests or unauthorized accounts.
Impact: Only administrators and standard users can shut down the system.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Shut down the system' to Administrators, Users.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure 'Take ownership of files or other objects' Is Set To 'Administrators'
Finding: 'Take ownership of files or other objects' is not restricted to Administrators.
Checks which accounts may take ownership of files and other objects.
This rule fails when the accounts assigned to seTakeOwnershipPrivilege are not exactly Administrators.
Rationale: Taking ownership bypasses any permissions and lets the holder gain control of any object.
Impact: Only administrators can take ownership of files or other objects.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment and set 'Take ownership of files or other objects' to Administrators.
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)