22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

18.3.12 (L2) Set 'MSS: (TcpMaxDataRetransmissions) How many times<br />

unacknowledged data is retransmitted' to 'Enabled: 3' (Scored) .................................. 418<br />

18.3.13 (L1) Set 'MSS: (WarningLevel) Percentage threshold for the security event<br />

log at which the system will generate a warning' to 'Enabled: 90% or less' (Scored)<br />

................................................................................................................................................................... 420<br />

18.4 Network ............................................................................................................................................ 422<br />

18.4.8.1 (L2) Set 'Turn on Mapper I/O (LLTDIO) driver' to 'Disabled' (Scored) ...... 424<br />

18.4.8.2 (L2) Set 'Turn on Responder (RSPNDR) driver' to 'Disabled' (Scored) ...... 426<br />

18.4.9.2 (L2) Set 'Turn off <strong>Microsoft</strong> Peer-to-Peer Networking Services' to 'Enabled'<br />

(Scored) ................................................................................................................................................. 428<br />

18.4.<strong>10</strong>.2 (L1) Set 'Prohibit installation and configuration of Network Bridge on your<br />

DNS domain network' to 'Enabled' (Scored) .......................................................................... 430<br />

18.4.<strong>10</strong>.3 (L1) Set 'Require domain users to elevate when setting a network's<br />

location' to 'Enabled' (Scored) ..................................................................................................... 432<br />

18.4.13.1 (L1) Set 'Hardened UNC Paths' to 'Enabled, with "Require Mutual<br />

Authentication" and "Require Integrity" set for all NETLOGON and SYSVOL shares'<br />

(Scored) ................................................................................................................................................. 435<br />

18.4.18.2.1 (L2) Disable IPv6 (Set TCPIP6 Parameter 'DisabledComponents' to '0xff<br />

(255)') (Scored) .................................................................................................................................. 439<br />

18.4.19.1 (L2) Set 'Configuration of wireless settings using <strong>Windows</strong> Connect Now'<br />

to 'Disabled' (Scored) ....................................................................................................................... 441<br />

18.4.19.2 (L2) Set 'Prohibit access of the <strong>Windows</strong> Connect Now wizards' to<br />

'Enabled' (Scored) ............................................................................................................................. 443<br />

18.4.20.1 (L1) Set 'Prohibit connection to non-domain networks when connected to<br />

domain authenticated network' to 'Enabled' (Scored) ....................................................... 445<br />

18.4.22.2.1 (L1) Set 'Allow <strong>Windows</strong> to automatically connect to suggested open<br />

hotspots, to networks shared by contacts, and to hotspots offering paid services' to<br />

'Disabled' (Scored) ............................................................................................................................ 449<br />

18.5 Printers ............................................................................................................................................. 451<br />

18.6 SCM: Pass the Hash Mitigations .............................................................................................. 452<br />

15 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!