System: Audit Security State Change
|ID: oval:gov.nist.usgcb.windowsseven:def:202||Date: (C)2012-04-13 (M)2018-02-16|
|Class: COMPLIANCE||Family: windows|
This policy setting allows you to audit events generated by changes in the security state of the computer such as the following events:
Startup and shutdown of the computer.
Change of system time.
Recovering the system from CrashOnAuditFail, which is logged after a system restarts when the security event log is full and the CrashOnAuditFail registry entry is configured.
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\System\Audit Security State Change
(2) REG: INFO NOT AVAILABLE
|Microsoft Windows 7|