
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 51
n RoutingandRemoteAccess
n Workstation
n Server
ThereasonweneedtokeeptheWorkstationserviceandtheServerserviceisthat
withoutthem,theRRASMMCsnapinwillnotworkproperly.
Step5Strengthentheaccountandauditsettings.
TheidealpoliciesassuggestedbyPhilipCox(above)include:
PasswordPolicies:
n EnforcePasswordHistory:Enabled(recommendedvalueis5)
n MaximumPasswordAge:Enabled(recommendedvalueis60)
n MinimumPasswordAge:Enabled(recommendedvalueis5)
n PasswordsMustMeetComplexityRequirements:Enabled
n StorePasswordUsingReversibleEncryption:Disabled
AccountLockoutPolicies:
n AccountLockoutThreshold:Enabled(recommendedvalueis5)
n AccountLockoutDuration:Enabled(recommendedvalueis30)
n ResetAccountLockoutThresholdAfter:Disabled(recommendedmanualreset
ofaccounts)
AuditPolicy(Auditsuccessandfailureforthefollowingauditcategories):
n AuditAccountLogon Events
n AuditAccountManagement
n AuditLogonEvents
n AuditPolicyChange
n AuditSystemEvents
Refertohttp://www.sysexp.com/win2k/hardenW2K12.pdf forPhilipCox’sfull
article.
Kommentare zu diesen Handbüchern