2.006 - ACLs for system files and directories do not conform to minimum requirements - 'C:\Program Files'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Failure to properly configure file and directory permissions (ACLs) allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.

Solution

Maintain the default file ACLs, configure the Security Option: 'Network access: Let everyone permissions apply to anonymous users' to 'Disabled' (V-3377) and restrict the Power Users group to include no members.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_MS_V6R46_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6(7), 800-53|CM-6, CAT|II, CCI|CCI-002165, CSCv6|3.1, Rule-ID|SV-29507r1_rule, STIG-ID|2.006, Vuln-ID|V-1130

Plugin: Windows

Control ID: b0b7224447f009cc66464a9fbebd91a63ad7c5e8619dfef89bfa847b2b984e9a