2.2.31 Ensure 'Modify an object label' is set to 'No one'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This privilege determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users.

Solution

Make sure 'Modify an object label' is set to no one.

See Also

https://workbench.cisecurity.org/files/1941