CCE-3379-5Platform: vista | Date: (C)2012-03-13 (M)2017-07-31 |
The "Do not allow storage of credentials or .NET Passports" policy should be set correctly.
Parameter:
(1) enabled/disabled
Technical Mechanism:
(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\DisableDomainCreds
(2) defined by Local or Group Policy
References:
Resource Id | Reference |
---|
Old v4 CCE ID | CCE-542 |
NIST SCAP Windows Vista XCCDF (SCAP-WinVista-XCCDF.xml rev 2007-02-06) | do-not-allow-storage-credentials-net-passports-network-authn |
NIST SCAP Windows Vista OVAL (SCAP-WinVista-OVAL.xml rev 2007-02-06) | oval:com.secure-elements.oval:def:6072 |
FDCC Windows Vista XCCDF (fdcc-accepted-content-20080110\fdcc-winvista-xccdf.xml) | do-not-allow-storage-credentials-net-passports-network-authn |
FDCC Windows Vista OVAL (fdcc-accepted-content-20080110\fdcc-winvista-oval.xml) | oval:gov.nist.fdcc.vista:def:6072 |
SCAP Repo OVAL Definition | oval:gov.nist.usgcb.vista:def:6072 |
BITS Shared Assessments SIG v6.0 | BITS Shared Assessments SIG v6.0 |
Jericho Forum | Jericho Forum |
HIPAA/HITECH Act | HIPAA/HITECH Act |
FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- |
ISO/IEC 27001-2005 | ISO/IEC 27001-2005 |
COBIT 4.1 | COBIT 4.1 |
GAPP (Aug 2009) | GAPP (Aug 2009) |
NERC CIP | NERC CIP |
NIST SP800-53 R3 | NIST SP800-53 R3 AC-3 |
NIST SP800-53 R3 | NIST SP800-53 R3 CM-6 |
NIST SP800-53 R3 | NIST SP800-53 R3 CM-7 |
NIST SP800-53 R3 | NIST SP800-53 R3 SC-5 |
PCIDSS v2.0 | PCIDSS v2.0 |
FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- |
BITS Shared Assessments AUP v5.0 | BITS Shared Assessments AUP v5.0 |