3.123 - Auditing Access of Global System Objects must be turned off.

Information

This setting prevents the system from setting up a default system access control list for certain system objects, which could create a very large number of security events, filling the security log in Windows and making it difficult to identify actual issues.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Audit: Audit the access of global system objects' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_R2_DC_V1R34_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CAT|II, CCE|CCE-10487-7, CCI|CCI-001095, Rule-ID|SV-32372r2_rule, STIG-ID|3.123, Vuln-ID|V-14228

Plugin: Windows

Control ID: a038c590e01bc3b5efddc7e27a9ee9a80ceda0b3cefa9c88d578aa08603d54d4