Audit Policy: Audit system eventsID: oval:org.secpod.oval:def:18963 | Date: (C)2014-05-29 (M)2021-06-02 |
Class: COMPLIANCE | Family: windows |
Auditing of Audit system events on success should be enabled or disabled as appropriate.
This security setting determines whether to audit when a user restarts or shuts down the computer or when an event occurs that affects either the system security or the security log. If you define this policy setting, you can specify whether to audit successes, audit failures, or not audit the event type at all. Success audits generate an audit entry when a system event is executed successfully. Failure audits generate an audit entry when a system event is attempted unsuccessfully.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit system events
(2) REG: NO INFO
Platform: |
Microsoft Windows Server 2008 R2 |