1.2.1.1.1.2.3 Configure 'Windows Firewall: Allow local program exceptions'

Information

This policy setting controls whether administrators can use the Windows Firewall component in Control Panel to define a local program exceptions list. Granting program exeptions could expose the computer to network-based attacks, however not allowing any exceptions is likely to break some applications such as computer management tools

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\Windows Firewall- Allow local program exceptions

Impact- If you disable this policy setting, administrators will not be able to define a local program exceptions list; also, this configuration ensures that program exceptions only come from Group Policy. If this policy setting is enabled, local administrators are allowed to use Control Panel to define program exceptions locally. For enterprise client computers, there may be conditions that justify local program exceptions. These conditions may include applications that were not analyzed when the organization's firewall policy was created or new applications that require nonstandard port configuration. If you choose to enable the Windows Firewall- Allow local program exceptions setting for such situations, remember that the attack surface of the affected computers is increased.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5), CCE|CCE-17446-6

Plugin: Windows

Control ID: 0506df17967cb4df9daf63920373dd022a57187e4c30c1271aff99542f7016d0