800-53|AC-6(7)

Title

REVIEW OF USER PRIVILEGES

Description

The organization:

Supplemental

The need for certain assigned user privileges may change over time reflecting changes in organizational missions/business function, environments of operation, technologies, or threat. Periodic review of assigned user privileges is necessary to determine if the rationale for assigning such privileges remains valid. If the need cannot be revalidated, organizations take appropriate corrective actions.

Reference Item Details

Related: CA-7

Category: ACCESS CONTROL

Parent Title: LEAST PRIVILEGE

Family: ACCESS CONTROL

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1 - SerializedSystemIni.dat Password File is not ProtectedWindowsTNS Oracle WebLogic Server 11 Windows Best Practices
1.1.1.2.1.54 Set 'Network access: Remotely accessible registry paths and sub-paths'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.1.54 Set 'Network access: Remotely accessible registry paths and sub-paths'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.1.70 Set 'Network access: Remotely accessible registry paths'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.1.70 Set 'Network access: Remotely accessible registry paths'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.1 Set 'Allow log on through Terminal Services' to 'Administrators'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.2 Set 'Allow log on through Terminal Services' to 'Administrators, Remote desktop Users'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.3 Set 'Take ownership of files or other objects' to 'Administrators'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.3 Set 'Take ownership of files or other objects' to 'Administrators'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.10 Set 'Adjust memory quotas for a process' to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.10 Set 'Adjust memory quotas for a process' to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.11 Configure 'Generate security audits'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.11 Configure 'Generate security audits'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.12 Set 'Shut down the system' to 'Administrators'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.12 Set 'Shut down the system' to 'Administrators'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.13 Configure 'Increase scheduling priority'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.13 Configure 'Increase scheduling priority'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.14 Set 'Replace a process level token' to 'LOCAL SERVICE, NETWORK SERVICE'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.14 Set 'Replace a process level token' to 'LOCAL SERVICE, NETWORK SERVICE'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.15 Configure 'Add workstations to domain'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.16 Configure 'Change the system time'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.16 Configure 'Change the system time'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.17 Configure 'Restore files and directories'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.17 Configure 'Restore files and directories'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.18 Configure 'Create a token object'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.18 Configure 'Create a token object'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.19 Configure 'Synchronize directory service data'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.19 Configure 'Synchronize directory service data'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.20 Set 'Profile system performance' to 'Administrators'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.20 Set 'Profile system performance' to 'Administrators'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.21 Configure 'Access this computer from the network'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.21 Configure 'Access this computer from the network'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.22 Set 'Profile single process' to 'Administrators'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.22 Set 'Profile single process' to 'Administrators'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.23 Configure 'Impersonate a client after authentication'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.23 Configure 'Impersonate a client after authentication'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.24 Set 'Create a pagefile' to 'Administrators'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.24 Set 'Create a pagefile' to 'Administrators'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.25 Set 'Deny log on as a batch job' to 'Guests'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.25 Set 'Deny log on as a batch job' to 'Guests'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.26 Set 'Deny log on through Terminal Services' to 'Guests'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.26 Set 'Deny log on through Terminal Services' to 'Guests'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.27 Configure 'Act as part of the operating system'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.27 Configure 'Act as part of the operating system'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.28 Configure 'Back up files and directories'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.28 Configure 'Back up files and directories'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.29 Set 'Log on as a service' to 'NETWORK SERVICE'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.3.29 Set 'Log on as a service' to 'NETWORK SERVICE'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.3.30 Set 'Deny access to this computer from the network' to 'ANONYMOUS LOGON, Guests'WindowsCIS Windows 2003 MS v3.1.0
1.04 Windows Oracle Account - 'Deny Log on Locally Right'WindowsCIS v1.1.0 Oracle 11g OS Windows Level 1