CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
17.6.2 (L1) Ensure 'Audit File Share' is set to 'Success and Failure' (Scored)
ProfileApplicability:
Level 1 (L1) - Corporate/Enterprise Environment (general use)
Description:
This policy setting allows you to audit attempts to access a shared folder.
The recommended state for this setting is: Success and Failure .
Note: There are no system access control lists (SACLs) for shared folders. If this policy setting is enabled, access to all shared folders on the system is audited.
Rationale:
In an enterprise managed environment, workstations should have limited file sharing activity, as file servers would normally handle the overall burden of file sharing activities. Any unusual file sharing activity on workstations may therefore be useful in an investigation of potentially malicious activity.
Audit:
Navigate to the UI Path articulated in the Remediation section and confirm it is set as prescribed.
Remediation:
To establish the recommended configuration via GP, set the following UI path to Success and Failure :
Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Object Access\Audit File Share
464 | P a g e
Made with FlippingBook - Online magazine maker