1.2.2.5.1 Configure 'Do not process the legacy run list'

Information

This policy setting causes the run list, which is a list of programs that Windows runs automatically when it starts, to be ignored. The customized run lists for Windows Vista are stored in the registry at the following locations: . HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run . HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run You can enable the Do not process the legacy run list setting to help prevent a malicious user from running a program each time Windows Vista starts, which could compromise data on the computer or cause other harm. When this policy setting is enabled, certain system programs are prevented from running, such as antivirus software, and software distribution and monitoring software. It is recommended to evaluate the threat level to your environment before you determine whether to use this policy setting for your organization. A malicious user could configure a program to be run each time Windows starts that could compromise data on the computer or cause other harm.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\System\Logon\Do not process the legacy run list

Impact- If you enable this setting, certain computer programs such as antivirus software and software distribution and monitoring software are also prevented from execution. You should evaluate the threat level to your environment that this setting is designed to safeguard against before you decide on a strategy to use this setting for your organization.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(2), CCE|CCE-17034-0, CSCv6|8.4

Plugin: Windows

Control ID: 074241d11bc0d566e05dec4b8f40e5c89e3ec42ed239e3f1cd0a4bb4262f72d3