2.014 - ACLs for disabled services do not conform to minimum standards.

Information

When configuring either the startup mode or access control list for a service, you must configure the other as well. When a service is explicitly disabled, its ACL should also be secured by changing the default ACL from Everyone Full Control to grant Administrators and SYSTEM Full Control and Interactive Read access.

Solution

Create a Custom Security Template using the Security Template MMC Snap-in to set the permissions as required for disabled services.

Import the Custom Template into the Security Configuration and Analysis Snap-In and Select Configure Computer Now

Or import the Custom Template in to a Group Policy for application.

The administrator should have a thorough understanding of these tools before implementing settings with them.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-29524r1_rule, STIG-ID|2.014, Vuln-ID|V-2371

Plugin: Windows

Control ID: 4c98ba7fedb68cb8d08ae9dce25114ca18eb0b6a3087fd85656f3ba5f05a973a