[Forgot Password]
Login  Register Subscribe

23631

 
 

119105

 
 

98250

 
 

909

 
 

79281

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit Policy: System: Other System Events

ID: oval:org.secpod.oval:def:23014Date: (C)2015-01-07   (M)2017-10-31
Class: COMPLIANCEFamily: windows




This subcategory reports on other system events. Events for this subcategory include: ? 5024 : The Windows Firewall Service has started successfully. ? 5025 : The Windows Firewall Service has been stopped. ? 5027 : The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy. ? 5028 : The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy. ? 5029: The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy. ? 5030: The Windows Firewall Service failed to start. ? 5032: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network. ? 5033 : The Windows Firewall Driver has started successfully. ? 5034 : The Windows Firewall Driver has been stopped. ? 5035 : The Windows Firewall Driver failed to start. ? 5037 : The Windows Firewall Driver detected critical runtime error. Terminating. ? 5058: Key file operation. ? 5059: Key migration operation. Refer to the Microsoft Knowledgebase article ?Description of security events in Windows Vista and in Windows Server 2008? for the most recent information about this setting: http://support.microsoft.com/default.aspx/kb/947226. This policy setting in the System audit category determines whether to audit Other System events on computers that are running Windows Vista or later versions of Windows. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\System!Audit Policy: System: Other System Events (2) REG: NO REGISTRY INFO

Platform:
Microsoft Windows Server 2012 R2
Reference:
CCE-38030-3
CPE    1
cpe:/o:microsoft:windows_server_2012::r2:x64
CCE    1
CCE-38030-3
XCCDF    6
xccdf_org.secpod_benchmark_NIST_800_171_R1_Windows_Server_2012_R2
xccdf_org.secpod_benchmark_general_Windows_2012_R2
xccdf_org.secpod_benchmark_NIST_800_53_r4_Windows_2012_R2
xccdf_org.secpod_benchmark_PCI_Windows_2012_R2
...

© 2013 SecPod Technologies