[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit Policy: Audit process tracking

ID: oval:org.secpod.oval:def:18738Date: (C)2014-05-29   (M)2021-06-02
Class: COMPLIANCEFamily: windows




Auditing of Audit process tracking events on success should be enabled or disabled as appropriate. Determines whether to audit detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access. By default, this value is set to No auditing in the Default Domain Controller Group Policy object (GPO) and in the local policies of workstations and servers. If you define this policy setting, you can specify whether to audit successes, audit failures, or not to audit the event type at all. Success audits generate an audit entry when the process being tracked is a success. Failure audits generate an audit entry when the process being tracked fails. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit process tracking (2) REG: NO INFO

Platform:
Microsoft Windows Server 2008 R2
Reference:
CCE-10060-2
CPE    1
cpe:/o:microsoft:windows_server_2008:r2
CCE    1
CCE-10060-2

© SecPod Technologies