CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
17.3 DetailedTracking
This section contains recommendations for configuring the Detailed Tracking audit policy.
17.3.1 (L1) Ensure 'Audit PNP Activity' is set to include 'Success' (Scored)
ProfileApplicability:
Level 1 (L1) - Corporate/Enterprise Environment (general use)
Description:
This policy setting allows you to audit when plug and play detects an external device.
The recommended state for this setting is to include: Success .
Note: AWindows 10, Server 2016 or newer OS is required to access and set this value in Group Policy.
Rationale:
Enabling this setting will allow a user to audit events when a device is plugged into a system. This can help alert IT staff if unapproved devices are plugged in.
Audit:
Navigate to the UI Path articulated in the Remediation section and confirm it is set as prescribed.
Remediation:
To establish the recommended configuration via GP, set the following UI path to include Success :
Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Detailed Tracking\Audit PNP Activity
446 | P a g e
Made with FlippingBook - Online magazine maker