resources:os:windows_server_2022:baseline
差别
这里会显示出您选择的修订版和当前版本之间的差别。
后一修订版 | 前一修订版 | ||
resources:os:windows_server_2022:baseline [2024/11/19 13:45] – 创建 jackiez | resources:os:windows_server_2022:baseline [2024/11/19 22:12] (当前版本) – jackiez | ||
---|---|---|---|
行 5: | 行 5: | ||
共分为19个大类,每大类又划分为若干小类,下面分别来介绍。 | 共分为19个大类,每大类又划分为若干小类,下面分别来介绍。 | ||
- | #1.Account Policies | + | #1. Account Policies |
+ | ## | ||
+ | 1.1.1 Ensure ' | ||
+ | 1.1.2 Ensure ' | ||
+ | 1.1.3 Ensure ' | ||
+ | 1.1.4 Ensure ' | ||
+ | 1.1.5 Ensure ' | ||
+ | 1.1.6 Ensure 'Relax minimum password length limits' | ||
+ | 1.1.7 Ensure 'Store passwords using reversible encryption' | ||
+ | ## | ||
+ | 1.2.1 Ensure ' | ||
+ | 1.2.2 Ensure ' | ||
+ | 1.2.3 Ensure 'Allow Administrator account lockout' | ||
+ | 1.2. Ensure 'Reset account lockout counter after' is set to '15 or more minute(s)' | ||
#2.Local Policies | #2.Local Policies | ||
+ | #2.1 Audit Policy | ||
+ | NA | ||
+ | #2.2 User Rights Assignment | ||
+ | 2.2.1 Ensure ' | ||
+ | 2.2.2 Ensure ' | ||
+ | 2.2.3 Ensure ' | ||
+ | 2.2.4 Ensure 'Act as part of the operating system' | ||
+ | 2.2.5 Ensure 'Add workstations to domain' | ||
+ | 2.2.6 Ensure ' | ||
+ | 2.2.7 Ensure 'Allow log on locally' | ||
+ | 2.2.8 Ensure 'Allow log on locally' | ||
+ | 2.2.9 Ensure 'Allow log on through Remote Desktop Services' | ||
+ | 2.2.10 Ensure 'Allow log on through Remote Desktop Services' | ||
+ | 2.2.11 Ensure 'Back up files and directories' | ||
+ | 2.2.12 Ensure ' | ||
+ | 2.2.13 Ensure ' | ||
+ | 2.2.14 Ensure ' | ||
+ | 2.2.15 Ensure ' | ||
+ | 2.2.16 Ensure ' | ||
+ | 2.2.17 Ensure ' | ||
+ | 2.2.18 Ensure ' | ||
+ | 2.2.19 Ensure ' | ||
+ | 2.2.20 Ensure 'Debug programs' | ||
+ | 2.2.21 Ensure 'Deny access to this computer from the network' | ||
+ | 2.2.22 Ensure 'Deny access to this computer from the network' | ||
+ | 2.2.23 Ensure 'Deny log on as a batch job' to include ' | ||
+ | 2.2.24 Ensure 'Deny log on as a service' | ||
+ | 2.2.25 Ensure 'Deny log on locally' | ||
+ | 2.2.26 Ensure 'Deny log on through Remote Desktop Services' | ||
+ | 2.2.27 Ensure 'Deny log on through Remote Desktop Services' | ||
+ | 2.2.28 Ensure ' | ||
+ | 2.2.29 Ensure ' | ||
+ | 2.2.30 Ensure 'Force shutdown from a remote system' | ||
+ | 2.2.31 Ensure ' | ||
+ | 2.2.32 Ensure ' | ||
+ | 2.2.33 Ensure ' | ||
+ | 2.2.34 Ensure ' | ||
+ | 2.2.35 Ensure 'Load and unload device drivers' | ||
+ | 2.2.36 Ensure 'Lock pages in memory' | ||
+ | 2.2.37 (L2) Ensure 'Log on as a batch job' is set to ' | ||
+ | 2.2.38 Ensure ' | ||
+ | 2.2.39 Ensure ' | ||
+ | 2.2.40 Ensure ' | ||
+ | 2.2.41 Ensure ' | ||
+ | 2.2.42 Ensure ' | ||
+ | 2.2.43 Ensure ' | ||
+ | 2.2.44 Ensure ' | ||
+ | 2.2.45 Ensure ' | ||
+ | 2.2.46 Ensure ' | ||
+ | 2.2.47 Ensure 'Shut down the system' | ||
+ | 2.2.48 Ensure ' | ||
+ | 2.2.49 Ensure 'Take ownership of files or other objects' | ||
+ | #2.3 Security Options | ||
+ | ##2.3.1 Account | ||
+ | 2.3.1.1 Ensure ' | ||
+ | 2.3.1.2 Ensure ' | ||
+ | 2.3.1.3 Ensure ' | ||
+ | 2.3.1.4 Configure ' | ||
+ | 2.3.1.5 Configure ' | ||
+ | s | ||
+ | ##2.3.2 Audit | ||
+ | 2.3.2.1 Ensure ' | ||
+ | 2.3.2.2 Ensure ' | ||
+ | ##2.3.3 DCOM | ||
+ | NA | ||
+ | ##2.3.4 Devices | ||
+ | 2.3.4.1 Ensure ' | ||
+ | ##2.3.5 Domain controller | ||
+ | 2.3.5.1 Ensure ' | ||
+ | 2.3.5.2 Ensure ' | ||
+ | 2.3.5.3 Ensure ' | ||
+ | 2.3.5.4 Ensure ' | ||
+ | 2.3.5.5 Ensure ' | ||
+ | ##2.3.6 Domain member | ||
+ | 2.3.6.1 Ensure ' | ||
+ | 2.3.6.2 Ensure ' | ||
+ | 2.3.6.3 Ensure ' | ||
+ | 2.3.6.4 Ensure ' | ||
+ | 2.3.6.5 Ensure ' | ||
+ | 2.3.6.6 Ensure ' | ||
+ | ##2.3.7 Interactive logon | ||
+ | 2.3.7.1 Ensure ' | ||
+ | 2.3.7.2 Ensure ' | ||
+ | 2.3.7.3 Ensure ' | ||
+ | 2.3.7.4 Configure ' | ||
+ | 2.3.7.5 Configure ' | ||
+ | 2.3.7.6 (L2) Ensure ' | ||
+ | 2.3.7.7 Ensure ' | ||
+ | 2.3.7.8 Ensure ' | ||
+ | 2.3.7.9 Ensure ' | ||
+ | ##2.3.8 Microsoft network client | ||
+ | 2.3.8.1 Ensure ' | ||
+ | 2.3.8.2 Ensure ' | ||
+ | 2.3.8.3 Ensure ' | ||
+ | ##2.3.9 Microsoft network server | ||
+ | 2.3.9.1 Ensure ' | ||
+ | 2.3.9.2 Ensure ' | ||
+ | 2.3.9.3 Ensure ' | ||
+ | 2.3.9.4 Ensure ' | ||
+ | 2.3.9.5 Ensure ' | ||
+ | ##2.3.10 Network access | ||
+ | 2.3.10.1 Ensure ' | ||
+ | 2.3.10.2 Ensure ' | ||
+ | 2.3.10.3 Ensure ' | ||
+ | 2.3.10.4 Ensure ' | ||
+ | 2.3.10.5 Ensure ' | ||
+ | 2.3.10.6 Configure ' | ||
+ | 2.3.10.7 Configure ' | ||
+ | 2.3.10.8 Configure ' | ||
+ | 2.3.10.9 Configure ' | ||
+ | 2.3.10.10 Ensure ' | ||
+ | 2.3.10.11 Ensure ' | ||
+ | 2.3.10.12 Ensure ' | ||
+ | 2.3.10.13 Ensure ' | ||
+ | ##2.3.11 Network security | ||
+ | 2.3.11.1 Ensure ' | ||
+ | 2.3.11.2 Ensure ' | ||
+ | 2.3.11.3 Ensure ' | ||
+ | 2.3.11.4 Ensure ' | ||
+ | 2.3.11.5 Ensure ' | ||
+ | 2.3.11.6 Ensure ' | ||
+ | 2.3.11.7 Ensure ' | ||
+ | 2.3.11.8 Ensure ' | ||
+ | 2.3.11.9 Ensure ' | ||
+ | 2.3.11.10 Ensure ' | ||
+ | 2.3.11.11 Ensure ' | ||
+ | 2.3.11.12 Ensure ' | ||
+ | 2.3.11.13 Ensure ' | ||
+ | ##2.3.12 Recovery console | ||
+ | NA | ||
+ | ##2.3.13 Shutdown | ||
+ | 2.3.13.1 Ensure ' | ||
+ | ##2.3.14 System cryptography | ||
+ | NA | ||
+ | ##2.3.15 System objects | ||
+ | 2.3.15.1 Ensure ' | ||
+ | 2.3.15.2 Ensure ' | ||
+ | ##2.3.16 System settings | ||
+ | NA | ||
+ | ##2.3.17 User Account Control | ||
+ | 2.3.17.1 Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' | ||
+ | 2.3.17.2 Ensure 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' is set to ' | ||
+ | 2.3.17.3 Ensure 'User Account Control: Behavior of the elevation prompt for standard users' is set to ' | ||
+ | 2.3.17.4 Ensure 'User Account Control: Detect application installations and prompt for elevation' | ||
+ | 2.3.17.5 Ensure 'User Account Control: Only elevate UIAccess applications that are installed in secure locations' | ||
+ | 2.3.17.6 Ensure 'User Account Control: Run all administrators in Admin Approval Mode' is set to ' | ||
+ | 2.3.17.7 Ensure 'User Account Control: Switch to the secure desktop when prompting for elevation' | ||
+ | 2.3.17.8 Ensure 'User Account Control: Virtualize file and registry write failures to per-user locations' | ||
#3.Event Log | #3.Event Log | ||
+ | NA | ||
# | # | ||
+ | NA | ||
#5.System Services | #5.System Services | ||
+ | #5.1 Ensure 'Print Spooler (Spooler)' | ||
+ | #5.2 Ensure 'Print Spooler (Spooler)' | ||
#6.Registry | #6.Registry | ||
+ | NA | ||
#7.File System | #7.File System | ||
+ | NA | ||
#8.Wired Network (IEEE 802.3) Policies | #8.Wired Network (IEEE 802.3) Policies | ||
+ | NA | ||
#9.Windows Defender Firewall with Advanced Security (formerly Windows Firewall with Advanced Security) | #9.Windows Defender Firewall with Advanced Security (formerly Windows Firewall with Advanced Security) | ||
+ | ##9.1 Domain Profile | ||
+ | 9.1.1 Ensure ' | ||
+ | 9.1.2 Ensure ' | ||
+ | 9.1.3 Ensure ' | ||
+ | 9.1.4 Ensure ' | ||
+ | 9.1.5 Ensure ' | ||
+ | 9.1.6 Ensure ' | ||
+ | 9.1.7 Ensure ' | ||
+ | ##9.2 Private Profile | ||
+ | 9.2.1 Ensure ' | ||
+ | 9.2.2 Ensure ' | ||
+ | 9.2.3 Ensure ' | ||
+ | 9.2.4 Ensure ' | ||
+ | 9.2.5 Ensure ' | ||
+ | 9.2.6 Ensure ' | ||
+ | 9.2.7 Ensure ' | ||
+ | ##9.3 Public Profile | ||
+ | 9.3.1 Ensure ' | ||
+ | 9.3.2 Ensure ' | ||
+ | 9.3.3 Ensure ' | ||
+ | 9.3.4 Ensure ' | ||
+ | 9.3.5 Ensure ' | ||
+ | 9.3.6 Ensure ' | ||
+ | 9.3.7 Ensure ' | ||
+ | 9.3.8 Ensure ' | ||
+ | 9.3.9 Ensure ' | ||
#10.Network List Manager Policies | #10.Network List Manager Policies | ||
+ | NA | ||
# | # | ||
+ | NA | ||
#12.Public Key Policies | #12.Public Key Policies | ||
+ | NA | ||
# | # | ||
+ | NA | ||
#14.Network Access Protection NAP Client Configuration | #14.Network Access Protection NAP Client Configuration | ||
+ | NA | ||
# | # | ||
+ | NA | ||
#16.IP Security Policies | #16.IP Security Policies | ||
+ | NA | ||
# | # | ||
+ | ##17.1 Account Logon | ||
+ | 17.1.1 Ensure 'Audit Credential Validation' | ||
+ | 17.1.2 Ensure 'Audit Kerberos Authentication Service' | ||
+ | 17.1.3 Ensure 'Audit Kerberos Service Ticket Operations' | ||
+ | ##17.2 Account Management | ||
+ | 17.2.1 Ensure 'Audit Application Group Management' | ||
+ | 17.2.2 Ensure 'Audit Computer Account Management' | ||
+ | 17.2.3 Ensure 'Audit Distribution Group Management' | ||
+ | 17.2.4 Ensure 'Audit Other Account Management Events' | ||
+ | 17.2.5 Ensure 'Audit Security Group Management' | ||
+ | 17.2.6 Ensure 'Audit User Account Management' | ||
+ | ##17.3 Detailed Tracking | ||
+ | 17.3.1 Ensure 'Audit PNP Activity' | ||
+ | 17.3.2 Ensure 'Audit Process Creation' | ||
+ | ##17.4 DS Access | ||
+ | 17.4.1 Ensure 'Audit Directory Service Access' | ||
+ | 17.4.2 Ensure 'Audit Directory Service Changes' | ||
+ | ##17.5 Logon/ | ||
+ | 17.5.1 Ensure 'Audit Account Lockout' | ||
+ | 17.5.2 Ensure 'Audit Group Membership' | ||
+ | 17.5.3 Ensure 'Audit Logoff' | ||
+ | 17.5.4 Ensure 'Audit Logon' is set to ' | ||
+ | 17.5.5 Ensure 'Audit Other Logon/ | ||
+ | 17.5.6 Ensure 'Audit Special Logon' is set to include ' | ||
+ | ##17.6 Object Access | ||
+ | 17.6.1 Ensure 'Audit Detailed File Share' is set to include ' | ||
+ | 17.6.2 Ensure 'Audit File Share' is set to ' | ||
+ | 17.6.3 Ensure 'Audit Other Object Access Events' | ||
+ | 17.6.4 Ensure 'Audit Removable Storage' | ||
+ | ##17.7 Policy Change | ||
+ | 17.7.1 Ensure 'Audit Audit Policy Change' | ||
+ | 17.7.2 Ensure 'Audit Authentication Policy Change' | ||
+ | 17.7.3 Ensure 'Audit Authorization Policy Change' | ||
+ | 17.7.4 Ensure 'Audit MPSSVC Rule-Level Policy Change' | ||
+ | 17.7.5 Ensure 'Audit Other Policy Change Events' | ||
+ | ##17.8 Privilege Use | ||
+ | 17.8.1 Ensure 'Audit Sensitive Privilege Use' is set to ' | ||
+ | ##17.9 System | ||
+ | 17.9.1 Ensure 'Audit IPsec Driver' | ||
+ | 17.9.2 Ensure 'Audit Other System Events' | ||
+ | 17.9.3 Ensure 'Audit Security State Change' | ||
+ | 17.9.4 Ensure 'Audit Security System Extension' | ||
+ | 17.9.5 Ensure 'Audit System Integrity' | ||
# | # | ||
+ | ##18.1 Control Panel | ||
+ | ###18.1.1 Personalization | ||
+ | 18.1.1.1 Ensure ' | ||
+ | 18.1.1.2 Ensure ' | ||
+ | ###18.1.2 Regional and Language Options | ||
+ | 18.1.2.1 Handwriting personalization | ||
+ | 18.1.2.2 Ensure 'Allow users to enable online speech recognition services' | ||
+ | ###18.1.3 Ensure 'Allow Online Tips' is set to ' | ||
+ | ##18.2 Desktop | ||
+ | NA | ||
+ | ##18.3 LAPS(legacy) | ||
+ | NA | ||
+ | ##18.4 MS Security Guide | ||
+ | 18.4.1 Ensure 'Apply UAC restrictions to local accounts on network logons' | ||
+ | 18.4.2 Ensure ' | ||
+ | 18.4.3 Ensure ' | ||
+ | 18.4.4 Ensure ' | ||
+ | 18.4.5 Ensure ' | ||
+ | 18.4.6 Ensure ' | ||
+ | 18.4.7 Ensure 'NetBT NodeType configuration' | ||
+ | 18.4.8 Ensure ' | ||
+ | ##18.5 MSS(Legacy) | ||
+ | 18.5.1 Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon' is set to ' | ||
+ | 18.5.2 Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level' is set to ' | ||
+ | 18.5.3 Ensure 'MSS: (DisableIPSourceRouting) IP source routing protection level' is set to ' | ||
+ | 18.5.4 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' | ||
+ | 18.5.5 (L2) Ensure 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' | ||
+ | 18.5.6 Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' | ||
+ | 18.5.7 (L2) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' | ||
+ | 18.5.8 Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode' is set to ' | ||
+ | 18.5.9 Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires' | ||
+ | 18.5.10 (L2) Ensure 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted' | ||
+ | 18.5.11 (L2) Ensure 'MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted' | ||
+ | 18.5.12 Ensure 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' | ||
+ | ##18.6 Network | ||
+ | |||
+ | ##18.7 Printers | ||
+ | ##18.8 Start Menu and Taskbar | ||
+ | ##18.9 System | ||
+ | ##18.10 Windows Components | ||
# | # | ||
+ | ##19.1 Control Panel | ||
+ | NA | ||
+ | ##19.2 Desktop | ||
+ | NA | ||
+ | ##19.3 Network | ||
+ | NA | ||
+ | ##19.4 Shared Folders | ||
+ | NA | ||
+ | ##19.5 Start Menu and Taskbar | ||
+ | ###19.5.1 Notifications | ||
+ | 19.5.1 Ensure 'Turn off toast notifications on the lock screen' | ||
+ | ##19.6 System | ||
+ | 19.6.1 Ctrl+Alt+Del Options | ||
+ | 19.6.2 Display | ||
+ | 19.6.3 Driver Installation | ||
+ | 19.6.4 Folder Redirection | ||
+ | 19.6.5 Group Policy | ||
+ | 19.6.6 Internet Communication Management | ||
+ | 19.6.6.1 Internet Communication settings | ||
+ | ##19.7 Windows Components | ||
+ | ###19.7.1 Account Notifications | ||
+ | NA | ||
+ | ###19.7.2 Add features to Windows 8 / 8.1 / 10 (formerly Windows Anytime Upgrade) | ||
+ | NA | ||
+ | ###19.7.3 App runtime | ||
+ | ###19.7.4 Application Compatibility | ||
+ | ###19.7.5 Attachment Manager | ||
+ | 19.7.5.1 Ensure 'Do not preserve zone information in file attachments' | ||
+ | 19.7.5.2 Ensure ' | ||
+ | ###19.7.6 AutoPlay Policies | ||
+ | NA | ||
+ | ###19.7.7 Calculator | ||
+ | NA | ||
+ | ###19.7.8 Cloud Content | ||
+ | 19.7.8.1 Ensure ' | ||
+ | 19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' | ||
+ | 19.7.8.3 Ensure 'Do not use diagnostic data for tailored experiences' | ||
+ | 19.7.8.4 Ensure 'Turn off all Windows spotlight features' | ||
+ | 19.7.8.5 Ensure 'Turn off Spotlight collection on Desktop' | ||
+ | ###19.7.9 Credential User Interface | ||
+ | NA | ||
+ | ###19.7.10 Data Collection and Preview Builds | ||
+ | NA | ||
+ | ###19.7.11 Desktop Gadgets | ||
+ | NA | ||
+ | ###19.7.12 Desktop Window Manager | ||
+ | NA | ||
+ | ###19.7.13 Digital Locker | ||
+ | NA | ||
+ | ###19.7.14 Edge UI | ||
+ | NA | ||
+ | ###19.7.15 File Explorer (formerly Windows Explorer) | ||
+ | NA | ||
+ | ###19.7.16 File Revocation | ||
+ | NA | ||
+ | ###19.7.17 IME | ||
+ | NA | ||
+ | ###19.7.18 Instant Search | ||
+ | NA | ||
+ | ###19.7.19 Internet Explorer | ||
+ | NA | ||
+ | ###19.7.20 Location and Sensors | ||
+ | NA | ||
+ | ###19.7.21 Microsoft Edge | ||
+ | NA | ||
+ | ###19.7.22 Microsoft Management Console | ||
+ | NA | ||
+ | ###19.7.23 Microsoft User Experience Virtualization | ||
+ | NA | ||
+ | ###19.7.24 Multitasking | ||
+ | NA | ||
+ | ###19.7.25 NetMeeting | ||
+ | NA | ||
+ | ###19.7.26 Network Sharing | ||
+ | 19.7.26.1 Ensure ' | ||
+ | ###19.7.27 OOBE | ||
+ | NA | ||
+ | ### | ||
+ | NA | ||
+ | ###19.7.29 Remote Desktop Services (formerly Terminal Services) | ||
+ | NA | ||
+ | ###19.7.30 RSS Feeds | ||
+ | NA | ||
+ | ###19.7.31 Search | ||
+ | NA | ||
+ | ###19.7.32 Sound Recorder | ||
+ | NA | ||
+ | ###19.7.33 Store | ||
+ | NA | ||
+ | ###19.7.34 Tablet PC | ||
+ | NA | ||
+ | ###19.7.35 Task Scheduler | ||
+ | NA | ||
+ | ###19.7.36 Windows Calendar | ||
+ | NA | ||
+ | ###19.7.37 Windows Color System | ||
+ | NA | ||
+ | ###19.7.38 Windows Copilot | ||
+ | NA | ||
+ | ###19.7.39 Windows Defender SmartScreen | ||
+ | NA | ||
+ | ###19.7.40 Windows Error Reporting | ||
+ | NA | ||
+ | ###19.7.41 Windows Hello for Business (formerly Microsoft Passport for Work) | ||
+ | NA | ||
+ | ###19.7.42 Windows Installer | ||
+ | 19.7.42.1 Ensure ' | ||
+ | ###19.7.43 Windows Logon Options | ||
+ | NA | ||
+ | ###19.7.44 Windows Media Player | ||
+ | 19.7.44.1 Networking | ||
+ | 19.7.44.2 Playback | ||
+ | 19.7.44.2.1 Ensure ' |
resources/os/windows_server_2022/baseline.1731991548.txt.gz · 最后更改: 由 jackiez