[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit: Audit the use of Backup and Restore privilege

ID: oval:org.secpod.oval:def:28703Date: (C)2015-10-14   (M)2023-07-04
Class: COMPLIANCEFamily: windows




This security setting determines whether to audit the use of all user privileges, including Backup and Restore, when the Audit privilege use policy is in effect. Enabling this option when the Audit privilege use policy is also enabled generates an audit event for every file that is backed up or restored. If you disable this policy, then use of the Backup or Restore privilege is not audited even when Audit privilege use is enabled. Note: On Windows versions prior to Windows Vista configuring this security setting, changes will not take effect until you restart Windows. Enabling this setting can cause a LOT of events, sometimes hundreds per second, during a backup operation. Default: Disabled. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options!Audit: Audit the use of Backup and Restore privilege (2) REG: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa!fullprivilegeauditing

Platform:
Microsoft Windows 8.1
Reference:
CCE-33045-6
CPE    1
cpe:/o:microsoft:windows_8.1
CCE    1
CCE-33045-6
XCCDF    3
xccdf_org.secpod_benchmark_HIPAA_45CFR_164_Windows_8_1
xccdf_org.secpod_benchmark_PCI_3_2_Windows_8_1
xccdf_org.secpod_benchmark_general_Windows_8_1

© SecPod Technologies