CCE-3711-9Platform: win2k3 | Date: (C)2010-04-20 (M)2018-04-17 |
The "Named Pipes that can be accessed anonymously" policy should be set correctly.
Parameter:
(1) list of named pipes
Technical Mechanism:
(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\NullSessionPipes
(2) Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Network Access: Named Pipes that can be accessed anonymously
References:
Resource Id | Reference |
---|
Old v4 CCE ID | CCE-136 |
Microsoft Security Guide for Windows Server 2003 | Table 3.89 Network access: Named Pipes that can be accessed anonymously: None (Legacy Client, Enterprise Client, and High Security) |
Center for Internet Security Windows Server 2003 | 3.2.1.42 Network Access: Named pipes that can be accessed anonymously: None |
DISA Stig for Windows 2003 | 5.4.6.56 [MA] Anonymous Access to Named Pipes: Network Access: Named pipes that can be accessed anonymously: COMNAP, COMNODE, SQL\QUERY, SPOOLSS, EPMAPPER, LOCATOR, TrkWks, and TrkSvr |
Microsoft Windows Server 2003 Security Guide, version April 26, 2006 | Table 4.19 Security Options: Network Access Setting Recommendations: Named Pipes that can be accessed anonymously, Not defined (Legacy and Enterprise), COMNAP, COMNODE, SQL\QUERY, SPOOLSS, LLSRPC, netlogon, lsarpc, samr, browser (Specialized Security) |
Microsoft Online Documentation | http://technet.microsoft.com/en-us/library/cc785123.aspx |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:8458 |
BITS Shared Assessments SIG v6.0 | BITS Shared Assessments SIG v6.0 |
Jericho Forum | Jericho Forum |
HIPAA/HITECH Act | HIPAA/HITECH Act |
FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- |
ISO/IEC 27001-2005 | ISO/IEC 27001-2005 |
COBIT 4.1 | COBIT 4.1 |
GAPP (Aug 2009) | GAPP (Aug 2009) |
NERC CIP | NERC CIP |
NIST SP800-53 R3 | NIST SP800-53 R3 AC-3 |
NIST SP800-53 R3 | NIST SP800-53 R3 CM-6 |
NIST SP800-53 R3 | NIST SP800-53 R3 CM-7 |
NIST SP800-53 R3 | NIST SP800-53 R3 SC-5 |
PCIDSS v2.0 | PCIDSS v2.0 |
FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- |
BITS Shared Assessments AUP v5.0 | BITS Shared Assessments AUP v5.0 |