WN12-GE-000021 - Necessary services must be documented to maintain a baseline to determine if additional, unnecessary services have been added to a system.

Information

Unnecessary services increase the attack surface of a system. Some services may be run under the local System account, which generally has more permissions than required by the service. Compromising a service could allow an intruder to obtain system permissions and open the system to a variety of attacks.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Document the services required for the system to operate. Remove or disable any services that are not required.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-226252r794534_rule, STIG-ID|WN12-GE-000021, STIG-Legacy|SV-52218, STIG-Legacy|V-3487, Vuln-ID|V-226252

Plugin: Windows

Control ID: 91a36da350f08285b7404a71759d291fb4e887f9f87caae8a1365a9195cf3b55