Problems with Windows 7 STIG

Posted on 2014-02-26
Medium Priority
Last Modified: 2014-04-08
Attempting to STIG a Windows 7 laptop.  We loaded the Non-Compliance Report – U_Windows_7_V1R19_STIG_Benchmark in the Security Automation Compliance Checker (SCAP)  First analyzation of the system with no remediation returned a 31% compliancy reading.  We’ve gotten the compliance status up to 87.22% but need to get it to at least 95% to be acceptable.  What is holding us back right now are false positives for the following examples (there are 30 of these):
•Audit - Credential Validation - Success
The system will be configured to audit "Account Logon -> Credential Validation" successes. - (CCE-9725-3) - Error
•Audit - Credential Validation - Failure
The system will be configured to audit "Account Logon -> Credential Validation" failures. - (CCE-9718-8) - Error
•Audit - Computer Account Management - Success
The system will be configured to audit "Account Management -> Computer Account Management" successes. - (CCE-9498-7) - Error
•Audit - Computer Account Management - Failure
The system will be configured to audit "Account Management -> Computer Account Management" failures. - (CCE-9608-1) - Error

Explanation example-When configuring the setting in gpedit under Computer Configuration-Windows Settings-Security Settings-Advanced Audit Policy Configuration-System Audit Policy-Audit Logon, according to the STIG, the key, Audit Credential Validation should be set at ‘Enabled’ with both ‘Success’ and ‘Failure’ checked.  However, enabling the policy and checking both ‘success’ and ‘failure’ returns error messages as shown above and prevents us from achieving the 95% compliance.  Does anyone have a workaround for this issue or have seen this before?
Question by:amiic93769
  • 3
LVL 51

Expert Comment

ID: 39890651
Does it do that when you attempt it manually?

Is the computer joined to the domain?  If so, that policy element might be set on a domain policy and enforced.

Author Comment

ID: 39891208
Yes, we are attempting it manually.  We use the version 1 rev 19 Windows 7 benchmark STIG with SCAP and then complete it with the manual STIG in Stigviewer.

No, the computer is not joined to a domain.  It is a standalone utility laptop.  It will not join a domain at any time.  It will only connect to our out-of-bank network to receive WSUS updates, run Retina scans, etc.

Accepted Solution

amiic93769 earned 0 total points
ID: 39914012
Discovered the solution.  Needed to configure all of the settings using auditpol.  Thanks

Author Closing Comment

ID: 39985501
Auditpol settings worked.

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

The way I use Experts Exchange to assist me in analyzing and diagnosing a problem is I first enter a Verbose Question at Experts Exchange like: Office 2007 will hang when opening and saving files I then launch WordPad (any text editor will do) an…
Many admins will agree: WSUS is is a nice invention but using it on the client side when updating a newly installed computer is still time consuming as you have to do several reboots and furthermore, the procedure of installing updates, rebooting a…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question