CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
17 Advanced Audit Policy Configuration
This section contains recommendations for configuring the Windows audit facilities.
17.1 Account Logon
This section contains recommendations for configuring the Account Logon audit policy.
17.1.1 (L1) Ensure 'Audit Credential Validation' is set to 'Success and Failure' (Scored)
ProfileApplicability:
Level 1 (L1) - Corporate/Enterprise Environment (general use)
Description:
This subcategory reports the results of validation tests on credentials submitted for a user account logon request. These events occur on the computer that is authoritative for the credentials. For domain accounts, the Domain Controller is authoritative, whereas for local accounts, the local computer is authoritative. In domain environments, most of the Account Logon events occur in the Security log of the Domain Controllers that are authoritative for the domain accounts. However, these events can occur on other computers in the organization when local accounts are used to log on. Events for this subcategory include: 4774: An account was mapped for logon. 4775: An account could not be mapped for logon. 4776: The Domain Controller attempted to validate the credentials for an account. 4777: The Domain Controller failed to validate the credentials for an account.
The recommended state for this setting is: Success and Failure .
Rationale:
Auditing these events may be useful when investigating a security incident.
Audit:
Navigate to the UI Path articulated in the Remediation section and confirm it is set as prescribed.
437 | P a g e
Made with FlippingBook - Online magazine maker