3.029 - Print driver installation privilege must be restricted to administrators.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The print spooler allows users to add and to delete printer drivers on the local system. This capability must be restricted to privileged groups to ensure only stable, non-malicious drivers are used.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Devices: Prevent users from installing printer drivers' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_7_V1R32_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CAT|III, CCI|CCI-001812, CSCv6|5.1, Rule-ID|SV-25035r2_rule, STIG-ID|3.029, Vuln-ID|V-1151

Plugin: Windows

Control ID: 374332ae8cc9a052600976b7fd4ce5df05df2884b50b32d890eae5fe4f7ffa13