2.005 - Systems must be maintained at a supported version of an operating system - SP or releases levels.

Information

Systems at unsupported versions or releases of an operating system will not receive security updates for new vulnerabilities, which leaves them subject to exploitation. Systems must be maintained at a version of the operating system supported by the vendor with new security updates.

Solution

Update the system to a version of the operating system supported by the vendor.

Support for Windows 2008/2008 R2 ended 14 January 2020. After this date, systems must have Windows 2012 or greater installed.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_MS_V6R46_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2, CAT|I, CCI|CCI-000366, Rule-ID|SV-29338r3_rule, STIG-ID|2.005, Vuln-ID|V-1073

Plugin: Windows

Control ID: 9b9bc876d4c8dd95fcf95b53113ec32cbce7ed46deb9d02022f8e074d42b0cf0