3.123 - Auditing Access of Global System Objects must be turned off.

Information

This setting prevents the system from setting up a default system access control list for certain system objects, which could create a very large number of security events, filling the security log in Windows and making it difficult to identify actual issues.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Audit: Audit the access of global system objects' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_MS_V6R46_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CAT|II, CCI|CCI-001095, Rule-ID|SV-29402r2_rule, STIG-ID|3.123, Vuln-ID|V-14228

Plugin: Windows

Control ID: 0d6b280419b6d6baa3eb5666f6195f475e3555626fdfc8c313f70cfa6e637488