1.1.2.36 Set 'Audit Policy: Logon-Logoff: Other Logon/Logoff Events' to 'No Auditing'

Information

This subcategory reports other logon/logoff-related events, such as Terminal Services session disconnects
and reconnects, using RunAs to run processes under a different account, and locking and unlocking a workstation.

Solution

Make sure 'Logon-Logoff: Other Logon/Logoff Events' is set to no auditing.

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c., CSCv6|16.1

Plugin: Windows

Control ID: f11b859007ff7e55a96f6953c0f5a26f1786940aae596e20a62c46dde286440b