DISA Windows Server 2012 and 2012 R2 DC STIG v3r1

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA Windows Server 2012 and 2012 R2 DC STIG v3r1

Updated: 11/4/2021

Authority: DISA STIG

Plugin: Windows

Revision: 1.8

Estimated Item Count: 402

Audit Changelog

 
Revision 1.8

Nov 4, 2021

Functional Update
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
  • WN12-PK-000004 - The US DoD CCEB Interoperability Root CA cross-certificates must be installed into the Untrusted Certificates Store on unclassified systems.
Revision 1.7

Oct 1, 2021

Functional Update
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.6

Sep 10, 2021

Functional Update
  • WN12-00-000007 - Windows 2012/2012 R2 password for the built-in Administrator account must be changed at least annually or when a member of the administrative team leaves the organization.
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
  • WN12-GE-000020 - Software certificate installation files must be removed from Windows 2012/2012 R2.
  • WN12-PK-000001 - The DoD Root CA certificates must be installed in the Trusted Root Store - Root CA 2
  • WN12-PK-000001 - The DoD Root CA certificates must be installed in the Trusted Root Store - Root CA 3
  • WN12-PK-000001 - The DoD Root CA certificates must be installed in the Trusted Root Store - Root CA 4
  • WN12-PK-000001 - The DoD Root CA certificates must be installed in the Trusted Root Store - Root CA 5
  • WN12-PK-000003 - The DoD Interoperability Root CA cross-certificates must be installed into the Untrusted Certificates Store on unclassified systems - DoD Root CA 2
  • WN12-PK-000003 - The DoD Interoperability Root CA cross-certificates must be installed into the Untrusted Certificates Store on unclassified systems - DoD Root CA 3
  • WN12-PK-000004 - The US DoD CCEB Interoperability Root CA cross-certificates must be installed into the Untrusted Certificates Store on unclassified systems.
  • WN12-SO-000013 - Outgoing secure channel traffic must be encrypted when possible.
  • WN12-SO-000014 - Outgoing secure channel traffic must be signed when possible.
  • WN12-SO-000046 - The system must be configured to have password protection take effect within a limited time frame when the screen saver becomes active.
  • WN12-UC-000009 - Zone information must be preserved when saving attachments.
  • WN12-UC-000010 - Mechanisms for removing zone information from file attachments must be hidden.
  • WN12-UC-000011 - The system must notify antivirus when file attachments are opened.
Informational Update
  • WN12-GE-000020 - Software certificate installation files must be removed from Windows 2012/2012 R2.
Miscellaneous
  • References updated.
Added
  • WN12-GE-000007 - Permissions for program file directories must conform to minimum requirements - C:\Program Files (x86)
Removed
  • WN12-GE-000007 - Permissions for program file directories must conform to minimum requirements - Program Files (x86)
Revision 1.5

Jul 30, 2021

Functional Update
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.4

Jun 17, 2021

Functional Update
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.3

May 14, 2021

Functional Update
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
  • WN12-AU-000206 - Permissions for the System event log must prevent access by nonprivileged accounts.
Miscellaneous
  • Platform check updated.
Revision 1.2

Apr 2, 2021

Functional Update
  • WN12-00-000210 - PowerShell script block logging must be enabled on Windows 2012/2012 R2 - Patch
  • WN12-AC-000001 - Windows 2012 account lockout duration must be configured to 15 minutes or greater.
  • WN12-AU-000204 - Permissions for the Application event log must prevent access by nonprivileged accounts.