22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2.3.7.5 (L1) Configure 'Interactive logon: Message text for users<br />

attempting to log on' (Scored)<br />

Profile Applicability:<br />

Level 1<br />

Level 1 + BitLocker<br />

Description:<br />

This policy setting specifies a text message that displays to users when they log on. Set the<br />

following group policy to a value that is consistent with the security and operational<br />

requirements of your organization.<br />

Rationale:<br />

Displaying a warning message before logon may help prevent an attack by warning the<br />

attacker about the consequences of their misconduct before it happens. It may also help to<br />

reinforce corporate policy by notifying employees of the appropriate policy during the<br />

logon process. This text is often used for legal reasons—for example, to warn users about<br />

the ramifications of misusing company information or to warn them that their actions may<br />

be audited.<br />

Note: Any warning that you display should first be approved by your organization's legal<br />

and human resources representatives.<br />

Audit:<br />

Navigate to the UI Path articulated in the Remediation section and confirm it is set as<br />

prescribed. This group policy setting is backed by the following registry location:<br />

HKEY_LOCAL_MACHINE\Software\<strong>Microsoft</strong>\<strong>Windows</strong>\CurrentVersion\Policies\System:LegalNoti<br />

ceText<br />

Remediation:<br />

To establish the recommended configuration via GP, configure the following UI path to a<br />

value that is consistent with the security and operational requirements of your<br />

organization:<br />

Computer Configuration\Policies\<strong>Windows</strong> Settings\Security Settings\Local<br />

Policies\Security Options\Interactive logon: Message text for users attempting to log<br />

on<br />

160 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!