<?xml version="1.0" encoding="UTF-8"?>
<Benchmark id="FDCC-Windows-Vista" resolved="0" xml:lang="en"
      xmlns="http://checklists.nist.gov/xccdf/1.1"
      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      xmlns:cdf="http://checklists.nist.gov/xccdf/1.1"
      xmlns:cpe="http://cpe.mitre.org/dictionary/2.0"
      xmlns:dc="http://purl.org/dc/elements/1.1/"
      xmlns:xhtml="http://www.w3.org/1999/xhtml" 
      xmlns:dsig="http://www.w3.org/2000/09/xmldsig#"
      xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.1 http://nvd.nist.gov/schema/xccdf-1.1.4.xsd
      http://cpe.mitre.org/dictionary/2.0 http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
      <status date="2009-04-08">accepted</status>
      <title>FDCC: Guidance for Securing Microsoft Windows Vista Systems for IT Professional</title>
      <description>This guide has been created to assist IT professionals, in effectively securing systems with Microsoft Vista</description>
      <notice id="terms_of_use" xml:lang="en">Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment. NIST assumes no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic. NIST would appreciate acknowledgement if the document and template are used.</notice>
      <front-matter xml:lang="en">todo - add text</front-matter>
      <rear-matter xml:lang="en"><xhtml:strong>Trademark Information</xhtml:strong><xhtml:br/><xhtml:br/>Microsoft, Windows, Windows XP, Windows Vista, Internet Explorer, and Windows Firewall are either registered trademarks or trademarks of Microsoft Corporation in the United States and other countries.<xhtml:br/><xhtml:br/>All other names are registered trademarks or trademarks of their respective companies.</rear-matter>
      <reference href="http://nvd.nist.gov/chklst_detail.cfm?config_id=76">
            <dc:publisher>National Institute of Standards and Technology</dc:publisher>
            <dc:identifier>SP 800-68</dc:identifier>
      </reference>
      <platform idref="cpe:/o:microsoft:windows_vista"/>
      <version>v1.2.0.0</version>
      <model system="urn:xccdf:scoring:default"/>
      <model system="urn:xccdf:scoring:flat"/>
      <!-- ==================================================================================================== -->
      <!-- ======================================  NIST 800-53 PROFILES  ====================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following profiles are used to turn on specific controls as definied in 800-53.  These controls  -->
      <!-- help determine the specific rules that will be evaluated as certain rules found in this document     -->
      <!-- require specific controls to be enabled.  This enable FISMA compliance to be achived by combining    -->
      <!-- guidance defined with high level recommendations made in 800-53.                                     -->
      <!--                                                                                                      -->
      <Profile id="low_800_53" abstract="true">
            <title>800-53 Low</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which all three security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of low. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="false"/>
            <select idref="AC-5" selected="false"/>
            <select idref="AC-6" selected="false"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="false"/>
            <select idref="AC-11" selected="false"/>
            <select idref="AC-12" selected="false"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="false"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="false"/>
            <select idref="AC-19" selected="false"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="false"/>
            <select idref="AU-7" selected="false"/>
            <select idref="AU-8" selected="false"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="false"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="false"/>
            <select idref="CM-4" selected="false"/>
            <select idref="CM-5" selected="false"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="false"/>
            <select idref="CP-4" selected="false"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="false"/>
            <select idref="CP-7" selected="false"/>
            <select idref="CP-8" selected="false"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="false"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="false"/>
            <select idref="IR-3" selected="false"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="false"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="false"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="false"/>
            <select idref="MP-4" selected="false"/>
            <select idref="MP-5" selected="false"/>
            <select idref="MP-6" selected="false"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="false"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="false"/>
            <select idref="PE-10" selected="false"/>
            <select idref="PE-11" selected="false"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="false"/>
            <select idref="PE-18" selected="false"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="false"/>
            <select idref="SC-3" selected="false"/>
            <select idref="SC-4" selected="false"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="false"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="false"/>
            <select idref="SC-9" selected="false"/>
            <select idref="SC-10" selected="false"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="false"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="false"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="false"/>
            <select idref="SC-18" selected="false"/>
            <select idref="SC-19" selected="false"/>
            <select idref="SC-20" selected="false"/>
            <select idref="SC-21" selected="false"/>
            <select idref="SC-22" selected="false"/>
            <select idref="SC-23" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="false"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="false"/>
            <select idref="SI-7" selected="false"/>
            <select idref="SI-8" selected="false"/>
            <select idref="SI-9" selected="false"/>
            <select idref="SI-10" selected="false"/>
            <select idref="SI-11" selected="false"/>
            <select idref="SI-12" selected="false"/>
      </Profile>
      <Profile id="moderate_800_53" abstract="true">
            <title>800-53 Moderate</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="false"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="false"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="false"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="false"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="false"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="high_800_53" abstract="true">
            <title>800-53 High</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="all_800_53" abstract="true">
            <title>800-53 All</title>
            <description>This profile selects all the security controls that are recommended by Special Publication 800-53 for information systems. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="true"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="true"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="true"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="true"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="true"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="true"/>
            <select idref="SA-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="true"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="true"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- =========================================  FDCC PROFILES  ========================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- These profiles outline the specific guidance outlined by the Federal Desktop Core Configuration.     -->
      <!-- Each defines the set of XCCDF rules that are applicable for that guidance as well as specific values -->
      <!-- to be used when determining complinace.                                                              -->
      <!--                                                                                                      -->
      <Profile id="federal_desktop_core_configuration_version_1.2.0.0" extends="all_800_53">
            <title>Federal Desktop Core Configuration version 1.2.0.0</title>
            <description>This profile represents guidance outlined in Federal Desktop Core Configuration for desktop systems with Microsoft Windows Vista installed.</description>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  2 - FDCC Security Settings                                                            ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- Account Lockout Policy Settings -->
            <select idref="account_lockout_duration" selected="true"/>
            <select idref="account_lockout_threshold" selected="true"/>
            <select idref="account_lockout_reset_counter" selected="true"/>
            <!--  Password Policy Settings  -->
            <select idref="password_enforce_history" selected="true"/>
            <select idref="password-maximum_age" selected="true"/>
            <select idref="password-minimum-age" selected="true"/>
            <select idref="password-minimum-length" selected="true"/>
            <select idref="password_complexity" selected="true"/>
            <select idref="password_reversible_encryption" selected="true"/>
            <!-- Audit Policy Settings -->
            <select idref="audit_account_logon_events" selected="true"/>
            <select idref="audit_account_management" selected="true"/>
            <select idref="audit_directory_service_access" selected="true"/>
            <select idref="audit_logon_events" selected="true"/>
            <select idref="audit_object_access" selected="true"/>
            <select idref="audit_policy_change" selected="true"/>
            <select idref="audit_privilege_use" selected="true"/>
            <select idref="audit_process_tracking" selected="true"/>
            <select idref="audit_system_events" selected="true"/>
            <!-- Security Options Settings -->
            <!--<select idref="AdministratorAccountStatus" selected="true"/>-->
            <select idref="guest-account-status" selected="true"/>
            <select idref="limit-blank-password-use" selected="true"/>
            <select idref="rename-administrator" selected="true"/>
            <select idref="rename-guest" selected="true"/>
            <select idref="audit-access-global-system-objects" selected="true"/>
            <select idref="audit-use-backup-restore-privilege" selected="true"/>
            <select idref="override-audit-policy-settings" selected="true"/>
            <select idref="shutdown-system-unable-log-audits" selected="true"/>
            <select idref="allow-format-eject-removable-media" selected="true"/>
            <select idref="prevent-users-installing-printers" selected="true"/>
            <select idref="restrict-cdrom-access-local-users-only" selected="true"/>
            <select idref="restrict-floppy-access-local-users-only" selected="true"/>
            <select idref="digitally-encrypt-or-sign-secure-channel-data-always" selected="true"/>
            <select idref="digitally-encrypt-secure-channel-data-when-possible" selected="true"/>
            <select idref="digitally-sign-secure-channel-data-when-possible" selected="true"/>
            <select idref="disable-machine-account-password-changes" selected="true"/>
            <select idref="maximum_machine-account-password-age" selected="true"/>
            <select idref="require-strong-session-key" selected="true"/>
            <select idref="do-not-display-last-user-name" selected="true"/>
            <select idref="do-not-require-ctrlaltdel" selected="true"/>
            <select idref="message-text-users-attempting-logon" selected="true"/>
            <select idref="message-title-users-attempting-logon" selected="true"/>
            <select idref="number-of-previous-logons-to-cache" selected="true"/>
            <select idref="prompt-user-to-change-password-before-expiration" selected="true"/>
            <select idref="require-domain-controller-authentication-to-unlock" selected="true"/>
            <select idref="smart-card-removal-behaviour" selected="true"/>
            <select idref="digitally-sign-communications-client-always" selected="true"/>
            <select idref="digitally-sign-communications-client-server-agrees" selected="true"/>
            <select idref="send-unencrypted-password-to-third-party-smb-servers" selected="true"/>
            <select idref="amount-of-idle-time-required-before-suspending-session" selected="true"/>
            <select idref="digitally-sign-communications-server-always" selected="true"/>
            <select idref="digitally-sign-communications-server-client-agrees" selected="true"/>
            <select idref="disconnect-client-when-logon-hours-expire" selected="true"/>
            <select idref="enable-automatic-logon" selected="true"/>
            <select idref="disable-ip-source-routing" selected="true"/>
            <select idref="enable-dead-gw-detect" selected="true"/>
            <select idref="enable-icmp-redirect" selected="true"/>
            <select idref="keep-alive-time" selected="true"/>
            <select idref="enable-nodefaultexempt-IPSec-Filtering" selected="true"/>
            <select idref="no-drive-type-auto-run" selected="true"/>
            <select idref="no-name-release-on-demand" selected="true"/>
            <select idref="ntfs-disable-8dot3-name-creation" selected="true"/>
            <select idref="perform-router-discovery" selected="true"/>
            <select idref="safe-dll-search-mode" selected="true"/>
            <select idref="screen-saver-grace-period" selected="true"/>
            <select idref="syn-attack-protect" selected="true"/>
            <select idref="tcp-max-connect-response-retransmissions" selected="true"/>
            <select idref="tcp-max-data-retransmissions" selected="true"/>
            <select idref="warning-level" selected="true"/>
            <select idref="anonymous_sid_name_translation" selected="true"/>
            <select idref="do-not-allow-anonymous-enumeration-sam" selected="true"/>
            <select idref="do-not-allow-anonymous-enumeration-sam-accounts-shares" selected="true"/>
            <select idref="do-not-allow-storage-credentials-net-passports-network-authn" selected="true"/>
            <select idref="let-everyone-permissions-apply-to-anonymous-users" selected="true"/>
            <select idref="named-pipes-accessed-anonymously" selected="true"/>
            <select idref="Remotely-accessible-registry-paths" selected="true"/>
            <select idref="Remotely-accessible-registry-paths-and-sub-paths" selected="true"/>
            <select idref="Restrict-anonymous-access-to-Named-Pipes-and-Shares" selected="true"/>
            <select idref="Shares-that-can-be-accessed-anonymously" selected="true"/>
            <select idref="Sharing-and-security-model-for-local-accounts" selected="true"/>
            <select idref="Do-not-store-LAN-Manager-hash-value-on-next-password-change" selected="true"/>
            <select idref="Force-logoff-when-logon-hours-expire" selected="true"/>
            <select idref="Lan-manager-authentication-level" selected="true"/>
            <select idref="LDAP-client-signing-requirements" selected="true"/>
            <select idref="minimum-session-security-ntlm-ssp-based-clients" selected="true"/>
            <select idref="minimum-session-security-ntlm-ssp-based-servers" selected="true"/>
            <select idref="recovery-console-allow-administrative-logon" selected="true"/>
            <select idref="recovery-console-allow-floppy-copy-access-all-drives-folders" selected="true"/>
            <select idref="shutdown-allow-system-shutdown-without-having-logon" selected="true"/>
            <select idref="shutdown-clear-virtual-memory-page" selected="true"/>
            <select idref="system-cryptography-use-fips-compliant-alorithm" selected="true"/>
            <select idref="system-objects-require-case-insesitivity" selected="true"/>
            <select idref="system-objects-strengthen-default-permissions-internal-system-objects" selected="true"/>
            <!-- User Account Control Settings -->
            <select idref="admin_approval_mode" selected="true"/>
            <select idref="behavior_elevation_prompt_administrators" selected="true"/>
            <select idref="behavior_elevation_prompt_standard_users" selected="true"/>
            <select idref="detect_application_installations_prompt_elevation" selected="true"/>
            <select idref="only_elevate_executables_signed_validated" selected="true"/>
            <select idref="only_elevate_uiaccess_applications" selected="true"/>
            <select idref="run_administrators_admin_approval_mode" selected="true"/>
            <select idref="switch_secure_desktop_prompting_elevation" selected="true"/>
            <select idref="virtualize_write_failures_per_user_locations" selected="true"/>

            <!-- User Right Assignments -->
            <select idref="Access-Computer-From-Network-Administrators" selected="true"/>
            <select idref="Act-As-Part-Of-Operating-System-None" selected="true"/>
            <select idref="Adjust-Memory-Quotas-Administrators-LocalService-NetworkService" selected="true"/>
            <select idref="Allow-Log-On-Locally-Administrators-Users" selected="true"/>
            <select idref="Allow-Log-On-Through-Terminal-Services-Administrators-RemoteDesktopUsers" selected="true"/>
            <select idref="Back-Up-Files-And-Directories-Administrators" selected="true"/>
            <select idref="Bypass-Traverse-Checking-Administrators_Users_LocalService_NetworkService" selected="true"/>
            <select idref="Change-System-Time-LocalService-Administrators" selected="true"/>
            <select idref="Change-Time-Zone-Administrators_Users_LocalService" selected="true"/>
            <select idref="Create-Pagefile-Administrators" selected="true"/>
            <select idref="Create-Token-Object-None" selected="true"/>
            <select idref="Create-Global-Objects-Administrators-SERVICE-LocalService-NetworkService" selected="true"/>
            <select idref="Create-Permanent-Shared-Objects-None" selected="true"/>
            <select idref="Debug-Programs-None" selected="true"/>
            <select idref="Deny-Access-From-Network-Guests" selected="true"/>
            <select idref="Deny-Logon-As-Batch-Job-Guests" selected="true"/>
            <select idref="deny_logon_as_service_none" selected="true"/>
            <select idref="Deny-Logon-Locally-Guests" selected="true"/>
            <select idref="Deny-Logon-Through-Terminal-Services-Guest" selected="true"/>
            <select idref="Force-Shutdown-From-Remote-System-Administrators" selected="true"/>
            <select idref="Generate-Security-Audits-LocalService-NetworkService" selected="true"/>
            <select idref="Impersonate-Client-After-Authentication-Administrators-SERVICE-LocalService-NetworkService" selected="true"/>
            <select idref="Increase-Process-Working-Set-Administrators_LocalService" selected="true"/>
            <select idref="Increase-Scheduling-Priority-Administrators" selected="true"/>
            <select idref="Load-And-Unload-Device-Drivers-Administrators" selected="true"/>
            <select idref="Lock-Pages-In-Memory-None" selected="true"/>
            <select idref="Log-On-As-Batch-Job-None" selected="true"/>
            <select idref="Log-On-As-Service-None" selected="true"/>
            <select idref="Manage-Auditing-And-Security-Log-Administrators" selected="true"/>
            <select idref="Modify-Object-Label-None" selected="true"/>
            <select idref="Modify-Firmware-Environment-Values-Administrators" selected="true"/>
            <select idref="Perform-Volume-Maintenance-Tasks-Administrators" selected="true"/>
            <select idref="Profile-Single-Process-Administrators" selected="true"/>
            <select idref="Profile-System-Performance-Administrators" selected="true"/>
            <select idref="Remove-Computer-From-Docking-Station-Administrators-Users" selected="true"/>
            <select idref="Replace-Process-Level-Token-NetworkService-LocalService" selected="true"/>
            <select idref="Restore-Files-And-Directories-Administrators" selected="true"/>
            <select idref="Shut-Down-System-Administrators-Users" selected="true"/>
            <select idref="Synchronize-Directory-Service-Data-None" selected="true"/>
            <select idref="Take-Ownership-Of-Files-Administrators" selected="true"/>
            <!-- System Services Settings -->
            <select idref="wlan_autoconfig" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  3 - FDCC Other Settings                                                               ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- Network Group -->
            <select idref="turn_on_mapper_io_lltdio_driver" selected="true"/>
            <select idref="turn_on_responder_rspndr_driver" selected="true"/>
            <select idref="turn_off_microsoft_peer_to_peer_networking_services" selected="true"/>
            <select idref="prohibit_installation_network_bridge" selected="true"/>
            <select idref="prohibit_internet_connection_firewall" selected="true"/>
            <select idref="prohibit_internet_connection_sharing" selected="true"/>
            <select idref="configuration_of_wireless_settings_using_windows_connect_now" selected="true"/>
            <select idref="prohibit_access_of_the_windows_connect_now_wizards" selected="true"/>
            <!-- System Group -->
            <select idref="allow_remote_access_to_the_pnp_interface" selected="true"/>
            <select idref="do_not_create_system_restore_point_when_new_device_driver_installed" selected="true"/>
            <select idref="do_not_send_windows_error_report_when_generic_driver_is_installed_on_device" selected="true"/>
            <select idref="turn_off_windows_update_device_driver_search_prompt" selected="true"/>
            <select idref="registry_policy" selected="true"/>
            <select idref="turn_off_help_ratings" selected="true"/>
            <select idref="turn_off_help_experience_improvement_program" selected="true"/>
            <select idref="turn_off_automatic_root_certificates_update" selected="true"/>
            <select idref="turn_off_downloading_of_print_drivers_over_http" selected="true"/>
            <select idref="turn_off_event_views_events.asp_links" selected="true"/>
            <select idref="turn_off_handwriting_reconition_error_reporting" selected="true"/>
            <select idref="turn_off_internet_connection_wizard_if_url_connection_is_referring_to_microsoft.com" selected="true"/>
            <select idref="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards" selected="true"/>
            <select idref="Turn-Off-Internet-File-Association-Service" selected="true"/>
            <select idref="Turn-off-printing-over-HTTP" selected="true"/>
            <select idref="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com" selected="true"/>
            <select idref="Turn-off-Search-Companion-content-file-updates" selected="true"/>
            <select idref="Turn-Off-the-Order-Prints-Picture-Task" selected="true"/>
            <select idref="Turn-off-the-Publish-to-Web-task-for-files-and-folders" selected="true"/>
            <select idref="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program" selected="true"/>
            <select idref="turn_off_windows_error_reporting" selected="true"/>
            <select idref="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads" selected="true"/>
            <select idref="Turn-Off-Windows-Movie-Maker-Online-Web-Links" selected="true"/>
            <select idref="Turn-Off-Windows-Movie-Maker-Saving-to-Online-Video-Hosting-Provider" selected="true"/>
            <select idref="Turn-off-Windows-Update-device-driver-searching" selected="true"/>
            <select idref="Always-Use-Classic-Logon" selected="true"/>
            <select idref="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon" selected="true"/>
            <select idref="Require-a-Password-when-a-Computer-Wakes-On-Battery" selected="true"/>
            <select idref="Require-a-Password-when-a-Computer-Wakes-Plugged" selected="true"/>
            <select idref="offer_remote_assistance" selected="true"/>
            <select idref="solicited_remote_assistance" selected="true"/>
            <select idref="turn_on_session_logging" selected="true"/>
            <select idref="restrictions_for_unauthenticated_rpc_clients" selected="true"/>
            <select idref="rpc_endpoint_mapper_client_authentication" selected="true"/>
            <select idref="disable_isatap_teredo_6to4_tunneling_protocols" selected="true"/>
            <!-- Windows Components Group -->
            <select idref="turn_off_autoplay" selected="true"/>
            <select idref="enumerate_administrator_accounts_on_elevation" selected="true"/>
            <select idref="do_not_allow_digital_locker_to_run" selected="true"/>
            <select idref="maximum_application_log_size" selected="true"/>
            <select idref="maximum_security_log_size" selected="true"/>
            <select idref="maximum_setup_log_size" selected="true"/>
            <select idref="maximum_system_log_size" selected="true"/>
            <select idref="turn_off_downloading_of_game_information" selected="true"/>
            <select idref="Prevent-IIS-Installation" selected="true"/>
            <select idref="Disable-remote-Desktop-Sharing" selected="true"/>
            <select idref="turn_off_untrusted_content" selected="true"/>
            <select idref="Allow-indexing-of-encrypted-files" selected="true"/>
            <select idref="Prevent-indexing-uncached-Exchange-folders" selected="true"/>
            <select idref="Do-not-allow-passwords-to-be-saved" selected="true"/>
            <select idref="Do-not-allow-drive-redirection" selected="true"/>
            <select idref="Always-prompt-client-for-password-upon-connection" selected="true"/>
            <select idref="Set-client-connection-encryption-level" selected="true"/>
            <select idref="set_timelimit_for_disconnected_sessions" selected="true"/>
            <select idref="set_timelimit_for_active_but_idle_terminal_services_sessions" selected="true"/>
            <select idref="configure_ms_spynet_reporting" selected="true"/>
            <select idref="disable_logging" selected="true"/>
            <select idref="disable_windows_error_reporting" selected="true"/>
            <select idref="display_error_notification" selected="true"/>
            <select idref="do_not_send_additional_data" selected="true"/>
            <select idref="turn_off_heap_termination_corruption" selected="true"/>
            <select idref="turn_off_shell_protocol_protected_mode" selected="true"/>
            <select idref="disable_ie_security_prompt_windows_installer_scripts" selected="true"/>
            <select idref="enable_user_control_over_installs" selected="true"/>
            <select idref="prohibit_non_administrators_install_signed_updates" selected="true"/>
            <select idref="report_logon_server_not_available_during_user_logon" selected="true"/>
            <select idref="turn_off_communities_features" selected="true"/>
            <select idref="turn_off_windows_mail_app" selected="true"/>
            <select idref="prevent_windows_media_drm_internet_access" selected="true"/>
            <select idref="do_not_show_first_use_dialog_boxes" selected="true"/>
            <select idref="prevent_automatic_updates" selected="true"/>
            <select idref="turn_off_windows_meeting_space" selected="true"/>
            <select idref="do_not_allow_windows_messenger_to_be_run" selected="true"/>
            <select idref="do_not_automatically_start_windows_messenger_initially" selected="true"/>
            <select idref="disable_unpacking_installation_gadgets_not_digitally_signed" selected="true"/>
            <select idref="override_more_gadgets_lnk" selected="true"/>
            <select idref="turn_off_user_installed_windows_sidebar_gidgets" selected="true"/>
            <!-- Local User Policy Group -->
            <select idref="password_protect_the_screen_saver" selected="true"/>
            <select idref="screen_save_timeout" selected="true"/>
            <select idref="prompt_for_password_on_resume_from_hibernate_suspend" selected="true"/>
            <select idref="do_not_preserve_zone_information_in_file_attachments" selected="true"/>
            <select idref="hide_mechanisms_to_remove_zone_information" selected="true"/>
            <select idref="notify_antivirus_programs_when_opening_attachments" selected="true"/>
            <select idref="prevent_users_from_sharing_files_within_their_profile" selected="true"/>
            <!-- Audit Policy Group -->
            <select idref="application-group-management" selected="true"/>
            <select idref="computer-account-management" selected="true"/>
            <select idref="distribution-group-management" selected="true"/>
            <select idref="other-account-management-events" selected="true"/>
            <select idref="security-group-management" selected="true"/>
            <select idref="user-account-management" selected="true"/>
            <select idref="dpapi-activity" selected="true"/>
            <select idref="process-creation" selected="true"/>
            <select idref="process-termination" selected="true"/>
            <select idref="rpc-events" selected="true"/>
            <select idref="detailed-directory-service-replication" selected="true"/>
            <select idref="directory-service-access" selected="true"/>
            <select idref="directory-service-changes" selected="true"/>
            <select idref="directory-service-replication" selected="true"/>
            <select idref="account-lockout" selected="true"/>
            <select idref="ipsec-extended-mode" selected="true"/>
            <select idref="ipsec-main-mode" selected="true"/>
            <select idref="ipsec-quick-mode" selected="true"/>
            <select idref="logoff" selected="true"/>
            <select idref="logon" selected="true"/>
            <select idref="other-logon-logoff-events" selected="true"/>
            <select idref="special-logon" selected="true"/>
            <select idref="application-generated" selected="true"/>
            <select idref="certification-services" selected="true"/>
            <select idref="file-share" selected="true"/>
            <select idref="file-system" selected="true"/>
            <select idref="filtering-platform-connection" selected="true"/>
            <select idref="filtering-platform-packet-drop" selected="true"/>
            <select idref="handle-manipulation" selected="true"/>
            <select idref="kernel-object" selected="true"/>
            <select idref="other-object-access-events" selected="true"/>
            <select idref="registry" selected="true"/>
            <select idref="sam" selected="true"/>
            <select idref="policy_change_audit" selected="true"/>
            <select idref="authentication-policy-change" selected="true"/>
            <select idref="authorization-policy-change" selected="true"/>
            <select idref="filtering-platform-policy-change" selected="true"/>
            <select idref="mpssvc-rule-level-policy-change" selected="true"/>
            <select idref="other-policy-change-events" selected="true"/>
            <select idref="non-sensitive-privilege-use" selected="true"/>
            <select idref="other-privilege-use-events" selected="true"/>
            <select idref="sensitive-privilege-use" selected="true"/>
            <select idref="ipsec-driver" selected="true"/>
            <select idref="other-system-events" selected="true"/>
            <select idref="security-state-change" selected="true"/>
            <select idref="security-system-extension" selected="true"/>
            <select idref="system-integrity" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  4 - Fully Patched System                                                              ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <select idref="security_patches_up_to_date" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <refine-value idref="account_lockout_duration_var" selector="900_seconds"/>
            <refine-value idref="account_lockout_threshold_var" selector="5_attempts"/>
            <refine-value idref="account_lockout_reset_counter_var" selector="900_seconds"/>

            <!-- Enforce user logon restrictions -->
            <!-- Maximum lifetime for service ticket -->
            <!-- Maximum lifetime for user ticket -->
            <!-- Maximum lifetime for user ticket renewal -->
            <!-- Maximum tolerance for computer clock synchronization -->

            <refine-value idref="password_enforce_history_var" selector="24_passwords"/>
            <refine-value idref="password-maximum_age_var" selector="5184000_seconds"/>
            <refine-value idref="password-minimum-age_var" selector="86400_seconds"/>
            <refine-value idref="password-minimum-length_var" selector="12_characters"/>
            <refine-value idref="password_complexity_var" selector="enabled"/>
            <refine-value idref="password_reversible_encryption_var" selector="disabled"/>

            <refine-value idref="audit_account_logon_events_var" selector="none"/>
            <refine-value idref="audit_account_management_var" selector="none"/>
            <refine-value idref="audit_directory_service_access_var" selector="none"/>
            <refine-value idref="audit_logon_events_var" selector="none"/>
            <refine-value idref="audit_object_access_var" selector="none"/>
            <refine-value idref="audit_policy_change_var" selector="none"/>
            <refine-value idref="audit_privilege_use_var" selector="none"/>
            <refine-value idref="audit_process_tracking_var" selector="none"/>
            <refine-value idref="audit_system_events_var" selector="none"/>

            <refine-value idref="guest-account-status_var" selector="disabled"/>
            <refine-value idref="limit-blank-password-use_var" selector="enabled"/>
            <refine-value idref="audit-access-global-system-objects_var" selector="disabled"/>
            <refine-value idref="audit-use-backup-restore-privilege_var" selector="disabled"/>
            <refine-value idref="override-audit-policy-settings_var" selector="enabled"/>
            <refine-value idref="shutdown-system-unable-log-audits_var" selector="disabled"/>
            <refine-value idref="allow-format-eject-removable-media_var" selector="administrator_and_interactiveuser_only"/>
            <refine-value idref="prevent-users-installing-printers_var" selector="disabled"/>
            <refine-value idref="restrict-cdrom-access-local-users-only_var" selector="not_restricted"/>
            <refine-value idref="restrict-floppy-access-local-users-only_var" selector="not_restricted"/>
            <refine-value idref="digitally-encrypt-or-sign-secure-channel-data-always_var" selector="enabled"/>
            <refine-value idref="digitally-encrypt-secure-channel-data-when-possible_var" selector="enabled"/>
            <refine-value idref="digitally-sign-secure-channel-data-when-possible_var" selector="enabled"/>
            <refine-value idref="disable-machine-account-password-changes_var" selector="disabled"/>
            <refine-value idref="maximum_machine-account-password-age_var" selector="30_days"/>
            <refine-value idref="require-strong-session-key_var" selector="enabled"/>
            <refine-value idref="do-not-display-last-user-name_var" selector="enabled"/>
            <refine-value idref="do-not-require-ctrlaltdel_var" selector="disabled"/>
            <refine-value idref="message-text-users-attempting-logon_var" selector="todo"/>
            <refine-value idref="message-title-users-attempting-logon_var" selector="todo"/>
            <refine-value idref="number-of-previous-logons-to-cache_var" selector="2_cached"/>
            <refine-value idref="prompt-user-to-change-password-before-expiration_var" selector="14_days"/>
            <refine-value idref="require-domain-controller-authentication-to-unlock_var" selector="disabled"/>
            <refine-value idref="smart-card-removal-behaviour_var" selector="lock_workstation"/>
            <refine-value idref="digitally-sign-communications-client-always_var" selector="enabled"/>
            <refine-value idref="digitally-sign-communications-client-server-agrees_var" selector="enabled"/>
            <refine-value idref="send-unencrypted-password-to-third-party-smb-servers_var" selector="disabled"/>
            <refine-value idref="amount-of-idle-time-required-before-suspending-session_var" selector="15_minutes"/>
            <refine-value idref="digitally-sign-communications-server-always_var" selector="enabled"/>
            <refine-value idref="digitally-sign-communications-server-client-agrees_var" selector="enabled"/>
            <refine-value idref="disconnect-client-when-logon-hours-expire_var" selector="enabled"/>
            <refine-value idref="enable-automatic-logon_var" selector="disabled"/>
            <refine-value idref="disable-ip-source-routing_var" selector="source_routing_packets_disabled"/>
            <refine-value idref="enable-dead-gw-detect_var" selector="disabled"/>
            <refine-value idref="enable-icmp-redirect_var" selector="disabled"/>
            <refine-value idref="keep-alive-time_var" selector="300000_seconds"/>
            <!-- noDefaultExempt -->
            <refine-value idref="no-name-release-on-demand_var" selector="enabled"/>
            <refine-value idref="ntfs-disable-8dot3-name-creation_var" selector="disabled"/>
            <refine-value idref="perform-router-discovery_var" selector="disabled"/>
            <refine-value idref="safe-dll-search-mode_var" selector="enabled"/>
            <refine-value idref="screen-saver-grace-period_var" selector="5_seconds"/>
            <refine-value idref="syn-attack-protect_var" selector="enabled"/>
            <refine-value idref="tcp-max-connect-response-retransmissions_var" selector="3_and_6_seconds_half_open_connections_dropped_after_21_seconds"/>
            <refine-value idref="tcp-max-data-retransmissions_var" selector="value_of_3"/>
            <refine-value idref="warning-level_var" selector="90_percent"/>
            <!-- Network access: Allow anonymous SID/Name translation -->
            <refine-value idref="anonymous_sid_name_translation_var" selector="False"/>
            <refine-value idref="do-not-allow-anonymous-enumeration-sam_var" selector="enabled"/>
            <refine-value idref="do-not-allow-anonymous-enumeration-sam-accounts-shares_var" selector="enabled"/>
            <refine-value idref="do-not-allow-storage-credentials-net-passports-network-authn_var" selector="enabled"/>
            <refine-value idref="let-everyone-permissions-apply-to-anonymous-users_var" selector="disabled"/>
            <!-- Network access: named-pipes-accessed-anonymously -->
            <!-- Network access: Remotely accessible registry paths -->
            <!-- Network access: Remotely accessible registry paths and subpaths -->
            <refine-value idref="Restrict-anonymous-access-to-Named-Pipes-and-Shares_var" selector="enabled"/>
            <!-- shares-that-can-be-accessed-anonymously_var -->
            <refine-value idref="Do-not-store-LAN-Manager-hash-value-on-next-password-change_var" selector="enabled"/>
            <refine-value idref="Force-logoff-when-logon-hours-expire_var" selector="enabled"/>
            <refine-value idref="Lan-manager-authentication-level_var" selector="send_NTLMv2_response_only_refuse_LM_and_NTLM"/>
            <refine-value idref="LDAP-client-signing-requirements_var" selector="negotiate_signing"/>
            <refine-value idref="minimum-session-security-ntlm-ssp-based-clients_var" selector="require_NTLMv2_and_require_128_bit_encryption"/>
            <refine-value idref="minimum-session-security-ntlm-ssp-based-servers_var" selector="require_NTLMv2_and_require_128_bit_encryption"/>
            <refine-value idref="recovery-console-allow-administrative-logon_var" selector="disabled"/>
            <refine-value idref="recovery-console-allow-floppy-copy-access-all-drives-folders_var" selector="disabled"/>
            <refine-value idref="shutdown-allow-system-shutdown-without-having-logon_var" selector="enabled"/>
            <refine-value idref="shutdown-clear-virtual-memory-page_var" selector="disabled"/>
            <refine-value idref="system-cryptography-use-fips-compliant-alorithm_var" selector="enabled"/>
            <refine-value idref="system-objects-require-case-insesitivity_var" selector="enabled"/>
            <refine-value idref="system-objects-strengthen-default-permissions-internal-system-objects_var" selector="enabled"/>

            <refine-value idref="admin_approval_mode_var" selector="enabled"/>
            <refine-value idref="behavior_elevation_prompt_administrators_var" selector="prompt_for_consent"/>
            <refine-value idref="behavior_elevation_prompt_standard_users_var" selector="prompt_for_credentials"/>
            <refine-value idref="detect_application_installations_prompt_elevation_var" selector="enabled"/>
            <refine-value idref="only_elevate_executables_signed_validated_var" selector="disabled"/>
            <refine-value idref="only_elevate_uiaccess_applications_var" selector="enabled"/>
            <refine-value idref="run_administrators_admin_approval_mode_var" selector="enabled"/>
            <refine-value idref="switch_secure_desktop_prompting_elevation_var" selector="enabled"/>
            <refine-value idref="virtualize_write_failures_per_user_locations_var" selector="enabled"/>

            <refine-value idref="wlan_autoconfig_var" selector="service_disabled"/>

            <refine-value idref="turn_on_mapper_io_lltdio_driver_var" selector="disabled"/>
            <refine-value idref="turn_on_responder_rspndr_driver_var" selector="disabled"/>
            <refine-value idref="turn_off_microsoft_peer_to_peer_networking_services_var" selector="enabled"/>
            <refine-value idref="prohibit_installation_network_bridge_var" selector="enabled"/>
            <refine-value idref="prohibit_internet_connection_firewall_var" selector="enabled"/>
            <refine-value idref="prohibit_internet_connection_sharing_var" selector="enabled"/>
            <refine-value idref="configuration_of_wireless_settings_using_windows_connect_now_var" selector="disabled"/>
            <refine-value idref="prohibit_access_of_the_windows_connect_now_wizards_var" selector="enabled"/>

            <refine-value idref="allow_remote_access_to_the_pnp_interface_var" selector="disabled"/>
            <refine-value idref="do_not_create_system_restore_point_when_new_device_driver_installed_var" selector="disabled"/>
            <refine-value idref="do_not_send_windows_error_report_when_generic_driver_is_installed_on_device_var" selector="enabled"/>
            <refine-value idref="turn_off_windows_update_device_driver_search_prompt_var" selector="enabled"/>
            <refine-value idref="registry_policy_var" selector="enabled:nogpolistchanges"/>
            <refine-value idref="turn_off_help_ratings_var" selector="enabled"/>
            <refine-value idref="turn_off_help_experience_improvement_program_var" selector="enabled"/>
            <refine-value idref="turn_off_automatic_root_certificates_update_var" selector="enabled"/>
            <refine-value idref="turn_off_downloading_of_print_drivers_over_http_var" selector="enabled"/>
            <refine-value idref="turn_off_event_views_events.asp_links_var" selector="disabled"/>
            <refine-value idref="turn_off_handwriting_reconition_error_reporting_var" selector="enabled"/>
            <refine-value idref="turn_off_internet_connection_wizard_if_url_connection_is_referring_to_microsoft.com_var" selector="enabled"/>
            <refine-value idref="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Internet-File-Association-Service_var" selector="enabled"/>
            <refine-value idref="Turn-off-printing-over-HTTP_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com_var" selector="enabled"/>
            <refine-value idref="Turn-off-Search-Companion-content-file-updates_var" selector="enabled"/>
            <refine-value idref="Turn-Off-the-Order-Prints-Picture-Task_var" selector="enabled"/>
            <refine-value idref="Turn-off-the-Publish-to-Web-task-for-files-and-folders_var" selector="enabled"/>
            <refine-value idref="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program_var" selector="enabled"/>
            <refine-value idref="turn_off_windows_error_reporting_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Windows-Movie-Maker-Online-Web-Links_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Windows-Movie-Maker-Saving-to-Online-Video-Hosting-Provider_var" selector="enabled"/>
            <refine-value idref="Turn-off-Windows-Update-device-driver-searching_var" selector="enabled"/>
            <!-- Always-Use-Classic-Logon -->
            <!-- Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon -->
            <refine-value idref="Require-a-Password-when-a-Computer-Wakes-On-Battery_var" selector="enabled"/>
            <refine-value idref="Require-a-Password-when-a-Computer-Wakes-Plugged_var" selector="enabled"/>
            <refine-value idref="offer_remote_assistance_var" selector="disabled"/>
            <refine-value idref="solicited_remote_assistance_var" selector="disabled"/>
            <refine-value idref="turn_on_session_logging_var" selector="enabled"/>
            <refine-value idref="restrictions_for_unauthenticated_rpc_clients_var" selector="enabled:authenticated"/>
            <refine-value idref="rpc_endpoint_mapper_client_authentication_var" selector="enabled"/>
            <refine-value idref="disable_isatap_teredo_6to4_tunneling_protocols_var" selector="disable_all_tunnel_interfaces"/>
            <refine-value idref="enumerate_administrator_accounts_on_elevation_var" selector="disabled"/>
            <refine-value idref="do_not_allow_digital_locker_to_run_var" selector="enabled"/>
            <refine-value idref="maximum_application_log_size_var" selector="enabled:32768_kb"/>
            <refine-value idref="maximum_security_log_size_var" selector="enabled:81920_kb"/>
            <refine-value idref="maximum_setup_log_size_var" selector="enabled:32768_kb"/>
            <refine-value idref="maximum_system_log_size_var" selector="enabled:32768_kb"/>
            <refine-value idref="turn_off_downloading_of_game_information_var" selector="enabled"/>
            <!-- Prevent-IIS-Installation -->
            <refine-value idref="Disable-remote-Desktop-Sharing_var" selector="enabled"/>
            <refine-value idref="turn_off_untrusted_content_var" selector="enabled"/>
            <refine-value idref="Allow-indexing-of-encrypted-files_var" selector="disabled"/>
            <refine-value idref="Prevent-indexing-uncached-Exchange-folders_var" selector="enabled"/>
            <refine-value idref="Do-not-allow-passwords-to-be-saved_var" selector="enabled"/>
            <refine-value idref="Do-not-allow-drive-redirection_var" selector="enabled"/>
            <refine-value idref="Always-prompt-client-for-password-upon-connection_var" selector="enabled"/>
            <refine-value idref="Set-client-connection-encryption-level_var" selector="high"/>
            <refine-value idref="set_timelimit_for_disconnected_sessions_var" selector="60_seconds"/>
            <refine-value idref="set_timelimit_for_active_but_idle_terminal_services_sessions_var" selector="900_seconds"/>
            <refine-value idref="configure_ms_spynet_reporting_var" selector="disabled"/>
            <refine-value idref="disable_logging_var" selector="disabled"/>
            <refine-value idref="disable_windows_error_reporting_var" selector="enabled"/>
            <refine-value idref="display_error_notification_var" selector="disabled"/>
            <refine-value idref="do_not_send_additional_data_var" selector="enabled"/>
            <refine-value idref="turn_off_heap_termination_corruption_var" selector="disabled"/>
            <refine-value idref="turn_off_shell_protocol_protected_mode_var" selector="disabled"/>
            <refine-value idref="disable_ie_security_prompt_windows_installer_scripts_var" selector="disabled"/>
            <refine-value idref="enable_user_control_over_installs_var" selector="disabled"/>
            <refine-value idref="prohibit_non_administrators_install_signed_updates_var" selector="enabled"/>
            <refine-value idref="report_logon_server_not_available_during_user_logon_var" selector="enabled"/>
            <refine-value idref="turn_off_communities_features_var" selector="enabled"/>
            <!-- turn_off_windows_mail_app -->
            <refine-value idref="prevent_windows_media_drm_internet_access_var" selector="enabled"/>
            <refine-value idref="do_not_show_first_use_dialog_boxes_var" selector="enabled"/>
            <refine-value idref="prevent_automatic_updates_var" selector="enabled"/>
            <refine-value idref="turn_off_windows_meeting_space_var" selector="enabled"/>
            <refine-value idref="do_not_allow_windows_messenger_to_be_run_var" selector="enabled"/>
            <refine-value idref="do_not_automatically_start_windows_messenger_initially_var" selector="enabled"/>
            <refine-value idref="disable_unpacking_installation_gadgets_not_digitally_signed_var" selector="enabled"/>
            <!-- override_more_gadgets_lnk -->
            <refine-value idref="turn_off_user_installed_windows_sidebar_gidgets_var" selector="enabled"/>

            <refine-value idref="password_protect_the_screen_saver_var" selector="enabled"/>
            <refine-value idref="screen_save_timeout_var" selector="900_seconds"/>
            <refine-value idref="prompt_for_password_on_resume_from_hibernate_suspend_var" selector="enabled"/>
            <refine-value idref="do_not_preserve_zone_information_in_file_attachments_var" selector="disabled"/>
            <refine-value idref="hide_mechanisms_to_remove_zone_information_var" selector="enabled"/>
            <refine-value idref="notify_antivirus_programs_when_opening_attachments_var" selector="enabled"/>
            <refine-value idref="prevent_users_from_sharing_files_within_their_profile_var" selector="enabled"/>

            <refine-value idref="application-group-management_var" selector="none"/>
            <refine-value idref="computer-account-management_var" selector="success_failure"/>
            <refine-value idref="distribution-group-management_var" selector="none"/>
            <refine-value idref="other-account-management-events_var" selector="success_failure"/>
            <refine-value idref="security-group-management_var" selector="success_failure"/>
            <refine-value idref="user-account-management_var" selector="success_failure"/>
            <refine-value idref="dpapi-activity_var" selector="none"/>
            <refine-value idref="process-creation_var" selector="success"/>
            <refine-value idref="process-termination_var" selector="none"/>
            <refine-value idref="rpc-events_var" selector="none"/>
            <refine-value idref="detailed-directory-service-replication_var" selector="none"/>
            <refine-value idref="directory-service-access_var" selector="none"/>
            <refine-value idref="directory-service-changes_var" selector="none"/>
            <refine-value idref="directory-service-replication_var" selector="none"/>
            <refine-value idref="account-lockout_var" selector="none"/>
            <refine-value idref="ipsec-extended-mode_var" selector="none"/>
            <refine-value idref="ipsec-main-mode_var" selector="none"/>
            <refine-value idref="ipsec-quick-mode_var" selector="none"/>
            <refine-value idref="logoff_var" selector="success"/>
            <refine-value idref="logon_var" selector="success_failure"/>
            <refine-value idref="other-logon-logoff-events_var" selector="none"/>
            <refine-value idref="special-logon_var" selector="success"/>
            <refine-value idref="application-generated_var" selector="none"/>
            <refine-value idref="certification-services_var" selector="none"/>
            <refine-value idref="file-share_var" selector="none"/>
            <refine-value idref="file-system_var" selector="failure"/>
            <refine-value idref="filtering-platform-connection_var" selector="none"/>
            <refine-value idref="filtering-platform-packet-drop_var" selector="none"/>
            <refine-value idref="handle-manipulation_var" selector="none"/>
            <refine-value idref="kernel-object_var" selector="none"/>
            <refine-value idref="other-object-access-events_var" selector="none"/>
            <refine-value idref="registry_var" selector="failure"/>
            <refine-value idref="sam_var" selector="none"/>
            <refine-value idref="policy_change_audit_var" selector="success_failure"/>
            <refine-value idref="authentication-policy-change_var" selector="success"/>
            <refine-value idref="authorization-policy-change_var" selector="none"/>
            <refine-value idref="filtering-platform-policy-change_var" selector="none"/>
            <refine-value idref="mpssvc-rule-level-policy-change_var" selector="none"/>
            <refine-value idref="other-policy-change-events_var" selector="none"/>
            <refine-value idref="non-sensitive-privilege-use_var" selector="none"/>
            <refine-value idref="other-privilege-use-events_var" selector="none"/>
            <refine-value idref="sensitive-privilege-use_var" selector="success_failure"/>
            <refine-value idref="ipsec-driver_var" selector="success_failure"/>
            <refine-value idref="other-system-events_var" selector="none"/>
            <refine-value idref="security-state-change_var" selector="success_failure"/>
            <refine-value idref="security-system-extension_var" selector="success_failure"/>
            <refine-value idref="system-integrity_var" selector="success_failure"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- ================================  NIST SP 800-53 (FISMA) Controls  ================================= -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following group contains all the different controls defined by NIST SP 800-53.  These controls   -->
      <!-- are hidden as they should not appear in any document generated from this file pertaining to specific -->
      <!-- security guidance.  These controls are used by the 800-53 profiles to enable high-level guidance     -->
      <!-- that is then passed down to the FDCC profiles and used to enable specific XCCDF Rules.               -->
      <!--                                                                                                      -->
      <Group id="nist_sp80053_controls" hidden="true">
            <title>NIST SP 800-53 Controls</title>
            <Group id="access_control_checks" hidden="true">
                  <title>Applicable 800-53 Access Control Checks</title>
                  <Group id="AC-1" hidden="true">
                        <title>Access Control Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 11.1.1, 11.4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 15, 16</reference>
                        <reference>DOD 8500.2: ECAN-1, ECPA-1, PRAS-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.1.a(1)(b)</reference>
                  </Group>
                  <Group id="AC-2" hidden="true">
                        <title>Account Management</title>
                        <reference>ISO/IEC 17799: 6.2.2, 6.2.3, 8.3.3, 11.2.1, 11.2.2, 11.2.4, 11.7.2</reference>
                        <reference>NIST 800-26: 6.1.8, 15.1.1, 15.1.4, 15.1.15, 15.1.8, 15.2.2, 16.1.3, 16.1.5, 16.2.12</reference>
                        <reference>GAO FISCAM: AC-2.1 AC-2.2, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAAC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)</reference>
                  </Group>
                  <Group id="AC-3" hidden="true">
                        <title>Access Enforcement</title>
                        <reference>ISO/IEC 17799: 11.2.4, 11.4.5</reference>
                        <reference>NIST 800-26: 10.1.2, 15.1.1, 16.1.1, 16.1.2, 16.1.3, 16.1.7, 16.1.9, 16.2.1, 16.2.7, 16.2.10, 16.2.11, 16.2.15</reference>
                        <reference>GAO FISCAM: AC-2, AC-3.2</reference>
                        <reference>DOD 8500.2: DCFA-1, ECAN-1, EBRU-1, PRNK-1, ECCD-1, ECSD-2</reference>
                        <reference>DCID 6/3: Discretionary Access Control (DAC): 4.B.2.a(2), Mandatory Access Control (MAC): 4.B.4.a(3)</reference>
                  </Group>
                  <Group id="AC-4" hidden="true">
                        <title>Information Flow Enforcement</title>
                        <reference>ISO/IEC 17799: 10.6.2, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>DOD 8500.2: EBBD-1, EBBD-2</reference>
                        <reference>DCID 6/3: 4.B.3.a(3), 7.B.3.g</reference>
                  </Group>
                  <Group id="AC-5" hidden="true">
                        <title>Separation of Duties</title>
                        <reference>ISO/IEC 17799: 10.1.3, 10.6.1, 10.10.1</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2, 6.1.3, 15.2.1, 16.1.2, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2, SD-1.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 2.A.1, 4.B.3.a(18)</reference>
                  </Group>
                  <Group id="AC-6" hidden="true">
                        <title>Least Privilege</title>
                        <reference>ISO/IEC 17799: 11.2.2</reference>
                        <reference>NIST 800-26: 16.1.2, 16.1.3, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="AC-7" hidden="true">
                        <title>Unsuccessful Login Attempts</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>NIST 800-26: 15.1.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(c)-(d)</reference>
                  </Group>
                  <Group id="AC-8" hidden="true">
                        <title>System Use Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1, 15.1.5</reference>
                        <reference>NIST 800-26: 16.2.13, 16.3.1, 17.1.9</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECWM-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(6)</reference>
                  </Group>
                  <Group id="AC-9" hidden="true">
                        <title>Previous Logon Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-2</reference>
                  </Group>
                  <Group id="AC-10" hidden="true">
                        <title>Concurrent Session Control</title>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(a)</reference>
                  </Group>
                  <Group id="AC-11" hidden="true">
                        <title>Session Lock</title>
                        <reference>ISO/IEC 17799: 11.3.2</reference>
                        <reference>NIST 800-26: 16.1.4</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: PESL-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(5)</reference>
                  </Group>
                  <Group id="AC-12" hidden="true">
                        <title>Session Termination</title>
                        <reference>ISO/IEC 17799: 11.3.2, 11.5.5</reference>
                        <reference>NIST 800-26: 16.1.4, 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(b)</reference>
                  </Group>
                  <Group id="AC-13" hidden="true">
                        <title>Supervision and Review—Access Control</title>
                        <reference>ISO/IEC 17799: 10.10.2, 11.2.4</reference>
                        <reference>NIST 800-26: 7.1.10, 11.2.2, 16.1.10, 16.2.5, 17.1.6, 17.1.7</reference>
                        <reference>GAO FISCAM: AC-4, AC-4.3, SS-2.2</reference>
                        <reference>DOD 8500.2: ECAT-1, ECAT-2, E3.3.9</reference>
                        <reference>DCID 6/3: 2.B.7.c, 4.B.3.a(8)(b)</reference>
                  </Group>
                  <Group id="AC-14" hidden="true">
                        <title>Permitted Actions without Identification or Authentication</title>
                        <reference>NIST 800-26: 16.2.12</reference>
                        <reference>DCID 6/3: 7.D.3.a</reference>
                  </Group>
                  <Group id="AC-15" hidden="true">
                        <title>Automated Marking</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 8.2.4, 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(11)</reference>
                  </Group>
                  <Group id="AC-16" hidden="true">
                        <title>Automated Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(3), 4.B.4.a(15), 4.B.4.a(16)</reference>
                  </Group>
                  <Group id="AC-17" hidden="true">
                        <title>Remote Access</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.4.4</reference>
                        <reference>NIST 800-26: 16.2.4, 16.2.8</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: EBRP-1, EBRU-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1)(b), 4.B.3.a(11), 7.D.2.e</reference>
                  </Group>
                  <Group id="AC-18" hidden="true">
                        <title>Wireless Access Restrictions</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.7.1, 11.7.2</reference>
                        <reference>DOD 8500.2: ECCT-1, ECWN-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8), 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="AC-19" hidden="true">
                        <title>Access Control for Portable and Mobile Systems</title>
                        <reference>ISO/IEC 17799: 11.7.1</reference>
                        <reference>NIST 800-26: 7.3.1, 7.3.2</reference>
                        <reference>DOD 8500.2: ECWN-1</reference>
                        <reference>DCID 6/3: 8.B.6.c, 9.G.4</reference>
                  </Group>
                  <Group id="AC-20" hidden="true">
                        <title>Use of External Information Systems</title>
                        <reference>ISO/IEC 17799: 6.1.4, 9.2.5, 11.7.1</reference>
                        <reference>NIST 800-26: 10.2.13</reference>
                        <reference>DCID 6/3: 8.B.6.c</reference>
                  </Group>
            </Group>
            <Group id="awareness_and_training" hidden="true">
                  <title>Applicable 800-53 Awareness and Training</title>
                  <Group id="AT-1" hidden="true">
                        <title>Security Awareness and Training Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 8.2.2, 15.1.1</reference>
                        <reference>NIST 800-26: 13</reference>
                        <reference>DOD 8500.2: PRTN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.c, Manual: 2.B.2.b(8); 2.B.4.e(6)</reference>
                  </Group>
                  <Group id="AT-2" hidden="true">
                        <title>Security Awareness</title>
                        <reference>ISO/IEC 17799: 6.2.3, 8.2.2, 10.4.1, 11.7.1, 13.1.1, 14.1.4, 15.1.4</reference>
                        <reference>NIST 800-26: 13.1.4, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-3" hidden="true">
                        <title>Security Training</title>
                        <reference>ISO/IEC 17799: 8.2.2, 10.3.2, 11.7.1, 13.1.1, 14.1.4</reference>
                        <reference>NIST 800-26: 13.1, 13.1.3, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-4" hidden="true">
                        <title>Security Training Records</title>
                        <reference>NIST 800-26: 13.1.2</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-5" hidden="true">
                        <title>Contacts with Security Groups and Associations</title>
                        <reference>ISO/IEC 17799: 6.1.7</reference>
                  </Group>
            </Group>
            <Group id="audit_and_accountablility" hidden="true">
                  <title>Applicable 800-53 Audit and Accountability</title>
                  <Group id="AU-1" hidden="true">
                        <title>Audit and Accountability Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1, 15.1.1</reference>
                        <reference>NIST 800-26: 17</reference>
                        <reference>DOD 8500.2: ECAT-1, ECTB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.d, Manual: 2.B.4.e(5); 4.B.2.a(4)</reference>
                  </Group>
                  <Group id="AU-2" hidden="true">
                        <title>Auditable Events</title>
                        <reference>ISO/IEC 17799: 10.10.1</reference>
                        <reference>NIST 800-26: 17.1.1, 17.1.2, 17.1.4</reference>
                        <reference>DOD 8500.2: ECAR-3</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(d)</reference>
                  </Group>
                  <Group id="AU-3" hidden="true">
                        <title>Content of Audit Records</title>
                        <reference>ISO/IEC 17799: 10.10.1, 10.10.4</reference>
                        <reference>NIST 800-26: 17.1.1</reference>
                        <reference>DOD 8500.2: ECAR-1, ECAR-2, ECAR-3, ECLC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a), 4.B.2.a(5)(a)</reference>
                  </Group>
                  <Group id="AU-4" hidden="true">
                        <title>Audit Storage Capacity</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="AU-5" hidden="true">
                        <title>Response to Audit Processing Failures</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 4.B.4.a(9)(d)</reference>
                  </Group>
                  <Group id="AU-6" hidden="true">
                        <title>Audit Monitoring, Analysis, and Reporting</title>
                        <reference>ISO/IEC 17799: 10.10.2, 10.10.4, 13.2.1</reference>
                        <reference>NIST 800-26: 16.2.5, 17.1.7, 17.1.8</reference>
                        <reference>GAO FISCAM: AC-4.3</reference>
                        <reference>DOD 8500.2: ECAT-1, E3.3.9</reference>
                        <reference>DCID 6/3: 4.B.4.a(10)</reference>
                  </Group>
                  <Group id="AU-7" hidden="true">
                        <title>Audit Reduction and Report Generation</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>NIST 800-26: 17.1.2, 17.1.7</reference>
                        <reference>DOD 8500.2: ECRG-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(6)</reference>
                  </Group>
                  <Group id="AU-8" hidden="true">
                        <title>Time Stamps</title>
                        <reference>ISO/IEC 17799: 10.10.6</reference>
                        <reference>DOD 8500.2: ECAR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a)</reference>
                  </Group>
                  <Group id="AU-9" hidden="true">
                        <title>Protection of Audit Information</title>
                        <reference>ISO/IEC 17799: 10.10.3, 15.1.3, 15.3.2</reference>
                        <reference>NIST 800-26: 17.1.3, 17.1.4</reference>
                        <reference>DOD 8500.2: ECTP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(b)</reference>
                  </Group>
                  <Group id="AU-10" hidden="true">
                        <title>Non-repudiation</title>
                        <reference>ISO/IEC 17799: 10.8.2, 10.9.1, 12.3.1</reference>
                        <reference>NIST 800-26: 15.1.2, 17.1.1</reference>
                        <reference>DOD 8500.2: DCNR-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(8)</reference>
                  </Group>
                  <Group id="AU-11" hidden="true">
                        <title>Audit Record Retention</title>
                        <reference>ISO/IEC 17799: 10.10.1, 15.1.3</reference>
                        <reference>NIST 800-26: 17.1.4</reference>
                        <reference>DOD 8500.2: ECRR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(c)</reference>
                  </Group>
            </Group>
            <Group id="certification_accreditation_and_security_assessment" hidden="true">
                  <title>Applicable 800-53 Certification, Accreditation, and Security Assessment</title>
                  <Group id="CA-1" hidden="true">
                        <title>Certification, Accreditation, and Security Assessment Policies and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1.4, 10.3.2, 15.1.1</reference>
                        <reference>NIST 800-26: 2, 4</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 2.B.2.b(1)</reference>
                  </Group>
                  <Group id="CA-2" hidden="true">
                        <title>Security Assessments</title>
                        <reference>ISO/IEC 17799: 6.1.8, 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 2.1.1, 2.1.3, 2.1.4</reference>
                        <reference>GAO FISCAM: SP-5.1</reference>
                        <reference>DOD 8500.2: DCII-1, ECMT-1, PEPS-1, E3.3.10</reference>
                        <reference>DCID 6/3: DCID: B.2.b; B.3.a, Manual: 4.B.2.b(6); 5.B.1.b(1); 9.B.1; 9.B.4</reference>
                  </Group>
                  <Group id="CA-3" hidden="true">
                        <title>Information System Connections</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.9.1, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>NIST 800-26: 1.1.1, 3.2.9, 4.1.8, 12.2.3</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCID-1, EBCR-1 EBRU-1, EBPW-1, ECIC-1</reference>
                        <reference>DCID 6/3: 9.B.3, 9.D.3.c</reference>
                  </Group>
                  <Group id="CA-4" hidden="true">
                        <title>Security Certification</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 2.1.2, 3.2.3, 3.2.5, 3.2.6, 4.1.1, 4.1.6, 11.2.8. 12.2.5</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCAR-1, 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 4.B.3.b(8); 9.E.2.a(2); 9.E.2.a(3)</reference>
                  </Group>
                  <Group id="CA-5" hidden="true">
                        <title>Plan of Action and Milestones</title>
                        <reference>ISO/IEC 17799: 15.2.1</reference>
                        <reference>NIST 800-26: 1.1.5, 1.2.3, 2.2.1, 4.2.1</reference>
                        <reference>GAO FISCAM: SP-5.1 SP-5.2</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 9.E.2.a(3)(a)</reference>
                  </Group>
                  <Group id="CA-6" hidden="true">
                        <title>Security Accreditation</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 3.2.7, 12.2.5</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 9.D.3; 9.D.4</reference>
                  </Group>
                  <Group id="CA-7" hidden="true">
                        <title>Continuous Monitoring</title>
                        <reference>ISO/IEC 17799: 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 10.2.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, E3.3.9</reference>
                        <reference>DCID 6/3: DCID: B.2.d; Manual: 2.B.4.e(7); 2.B.5.c(10); 5.B.2.b(2); 9.B.1; 9.D.7</reference>
                  </Group>
            </Group>
            <Group id="configuration_management" hidden="true">
                  <title>Applicable 800-53 Configuration Management</title>
                  <Group id="CM-1" hidden="true">
                        <title>Configuration Management Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.4.1, 12.5.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, DCAR-1, E3.3.8</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-2" hidden="true">
                        <title>Baseline Configuration and System Component Inventory</title>
                        <reference>ISO/IEC 17799: 7.1.1, 15.1.2</reference>
                        <reference>NIST 800-26: 1.1.1, 3.1.9, 10.2.7, 10.2.9, 12.1.4</reference>
                        <reference>GAO FISCAM: CC-2.3, CC-3.1, SS-1.2</reference>
                        <reference>DOD 8500.2: DCHW-1, DCSW-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 4.B.2.b(6)</reference>
                  </Group>
                  <Group id="CM-3" hidden="true">
                        <title>Configuration Change Control</title>
                        <reference>ISO/IEC 17799: 10.1.2, 10.2.3, 12.4.1, 12.5.1, 12.5.2, 12.5.3</reference>
                        <reference>NIST 800-26: 3.1.4, 10.2.2, 10.2.3, 10.2.8, 10.2.10, 10.2.11</reference>
                        <reference>GAO FISCAM: SS-3.2, CC-2.2</reference>
                        <reference>DOD 8500.2: DCPR-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7) 4.B.1.c(3), 4.B.2.b(6), 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-4" hidden="true">
                        <title>Monitoring Configuration Changes</title>
                        <reference>ISO/IEC 17799: 10.1.2</reference>
                        <reference>NIST 800-26: 10.2.1, 10.2.4</reference>
                        <reference>GAO FISCAM: SS-3.1, SS-3.2, CC-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, E3.3.8</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 5.B.2.b(2), 8.B.8.c(7)</reference>
                  </Group>
                  <Group id="CM-5" hidden="true">
                        <title>Access Restrictions for Change</title>
                        <reference>ISO/IEC 17799: 11.6.1</reference>
                        <reference>NIST 800-26: 6.1.3, 6.1.4, 10.1.1, 10.1.4, 10.1.5</reference>
                        <reference>GAO FISCAM: SD-1.1, SS-1.2, SS-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, ECSD-2</reference>
                        <reference>DCID 6/3: 5.B.3.a(2)(b)</reference>
                  </Group>
                  <Group id="CM-6" hidden="true">
                        <title>Configuration Settings</title>
                        <reference>NIST 800-26: 10.2.6, 10.3.1, 16.2.2, 16.2.3, 16.2.11</reference>
                        <reference>DOD 8500.2: DCSS-1, ECSC-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="CM-7" hidden="true">
                        <title>Least Functionality</title>
                        <reference>NIST 800-26: 10.3.1</reference>
                        <reference>DOD 8500.2: DCPP-1, ECIM-1, ECVI-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10), 7.D.2.b</reference>
                  </Group>
            </Group>
            <Group id="contingency_planning" hidden="true">
                  <title>Applicable 800-53 Contingency Planning</title>
                  <Group id="CP-1" hidden="true">
                        <title>Contingency Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 10.4.1, 14.1.1, 14.1.3, 15.1.1</reference>
                        <reference>NIST 800-26: 9</reference>
                        <reference>DOD 8500.2: COBR-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 6.B.1.a(1)</reference>
                  </Group>
                  <Group id="CP-2" hidden="true">
                        <title>Contingency Plan</title>
                        <reference>ISO/IEC 17799: 10.3.2, 10.4.1, 10.8.5, 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 4.1.4, 9.1.1, 9.2, 9.2.1, 9.2.2, 9.2.3, 9.2.10, 12.1.8, 12.2.2</reference>
                        <reference>GAO FISCAM: SC-3.1, SC-1.1</reference>
                        <reference>DOD 8500.2: CODP-1, COEF-1</reference>
                        <reference>DCID 6/3: 6.B.2.b(1)</reference>
                  </Group>
                  <Group id="CP-3" hidden="true">
                        <title>Contingency Training</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 9.3.2</reference>
                        <reference>GAO FISCAM: SC-2.3</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="CP-4" hidden="true">
                        <title>Contingency Plan Testing</title>
                        <reference>ISO/IEC 17799: 10.5.1, 14.1.5</reference>
                        <reference>NIST 800-26: 4.1.4, 9.3.3</reference>
                        <reference>GAO FISCAM: SC-3.1</reference>
                        <reference>DOD 8500.2: COED-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)(b)</reference>
                  </Group>
                  <Group id="CP-5" hidden="true">
                        <title>Contingency Plan Update</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.5</reference>
                        <reference>NIST 800-26: 9.3.1, 9.3.3, 10.2.12</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)</reference>
                  </Group>
                  <Group id="CP-6" hidden="true">
                        <title>Alternate Storage Sites</title>
                        <reference>ISO/IEC 17799: 10.5.1</reference>
                        <reference>NIST 800-26: 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: CODB-2</reference>
                        <reference>DCID 6/3: 6.B.2.a(2), 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-7" hidden="true">
                        <title>Alternate Processing Sites</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.1.3, 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: COAS-1, COEB-1, COSP-1, COSP-2</reference>
                        <reference>DCID 6/3: 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-8" hidden="true">
                        <title>Telecommunications Services</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>DCID 6/3: 6.B.2.a(4)</reference>
                  </Group>
                  <Group id="CP-9" hidden="true">
                        <title>Information System Backup</title>
                        <reference>ISO/IEC 17799: 10.5.1, 11.7.1</reference>
                        <reference>NIST 800-26: 9.1.1, 9.2.6, 9.2.9, 9.3.1, 12.1.9</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: CODB-1, CODB-2, COSW-1</reference>
                        <reference>DCID 6/3: 6.B.1.a(2)</reference>
                  </Group>
                  <Group id="CP-10" hidden="true">
                        <title>Information System Recovery and Reconstitution</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.2.8</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: COTR-1, ECND-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(4), 6.B.1.a(1), 6.B.2.a(3)(d)</reference>
                  </Group>
            </Group>
            <Group id="identification_and_authentication" hidden="true">
                  <title>Applicable 800-53 Identification and Authentication</title>
                  <Group id="IA-1" hidden="true">
                        <title>Identification and Authentication Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11.2.3</reference>
                        <reference>DOD 8500.2: IAIA-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="IA-2" hidden="true">
                        <title>User Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.4.2, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1</reference>
                        <reference>DOD 8500.2: IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)</reference>
                  </Group>
                  <Group id="IA-3" hidden="true">
                        <title>Device Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.7.1</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.5.a(14)</reference>
                  </Group>
                  <Group id="IA-4" hidden="true">
                        <title>Identifier Management</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1.1, 15.2.2, 15.1.8</reference>
                        <reference>GAO FISCAM: AC-2.1, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAGA-1, IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(2)</reference>
                  </Group>
                  <Group id="IA-5" hidden="true">
                        <title>Authenticator Management</title>
                        <reference>ISO/IEC 17799: 11.5.2, 11.5.3</reference>
                        <reference>NIST 800-26: 15.1.6, 15.1.7, 15.1.9, 15.1.10, 15.1.11, 15.1.12, 15.1.13, 16.1.3, 16.2.3</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="IA-6" hidden="true">
                        <title>Authenticator Feedback</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)(g)</reference>
                  </Group>
                  <Group id="IA-7" hidden="true">
                        <title>Cryptographic Module Authentication</title>
                        <reference>NIST 800-26: 16.1.7</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
            </Group>
            <Group id="incident_response" hidden="true">
                  <title>Applicable 800-53 Incident Response</title>
                  <Group id="IR-1" hidden="true">
                        <title>Incident Response Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.4.1, 13.1, 13.2.1, 15.1.1</reference>
                        <reference>NIST 800-26: 14</reference>
                        <reference>DOD 8500.2: VIIR-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.c; C.4 Manual: 2.B.4.e(5); 2.B.2.b(6); 2.B.6.c(10); 8.B.7</reference>
                  </Group>
                  <Group id="IR-2" hidden="true">
                        <title>Incident Response Training</title>
                        <reference>ISO/IEC 17799: 13.1.1</reference>
                        <reference>NIST 800-26: 14.1.4</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.1.b(1)(f), 8.B.1.c(1)(e), 8.B.1.c(2)©</reference>
                  </Group>
                  <Group id="IR-3" hidden="true">
                        <title>Incident Response Testing</title>
                        <reference>ISO/IEC 17799: 14.1.5</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-4" hidden="true">
                        <title>Incident Handling</title>
                        <reference>ISO/IEC 17799: 6.1.6, 13.2.1, 13.2.2</reference>
                        <reference>NIST 800-26: 2.1.5, 14.1.1, 14.1.2, 14.1.6</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7, 9.B.2.e</reference>
                  </Group>
                  <Group id="IR-5" hidden="true">
                        <title>Incident Monitoring</title>
                        <reference>NIST 800-26: 14.1.3</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7.a</reference>
                  </Group>
                  <Group id="IR-6" hidden="true">
                        <title>Incident Reporting</title>
                        <reference>ISO/IEC 17799: 6.1.6, 6.2.2, 6.2.3, 13.1.1, 13.1.2</reference>
                        <reference>NIST 800-26: 14.1.2, 14.1.3, 14.2.1, 14.2.2, 14.2.3</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-7" hidden="true">
                        <title>Incident Response Assistance</title>
                        <reference>ISO/IEC 17799: 14.1.3</reference>
                        <reference>NIST 800-26: 8.1.1, 14.1.1</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DCID 6/3: 8.B.7.c</reference>
                  </Group>
            </Group>
            <Group id="maintenance" hidden="true">
                  <title>Applicable 800-53 Maintenance</title>
                  <Group id="MA-1" hidden="true">
                        <title>System Maintenance Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 10</reference>
                        <reference>DOD 8500.2: PRMP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="MA-2" hidden="true">
                        <title>Periodic Maintenance</title>
                        <reference>ISO/IEC 17799: 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3, 10.2.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5), 8.B.8.c</reference>
                  </Group>
                  <Group id="MA-3" hidden="true">
                        <title>Maintenance Tools</title>
                        <reference>NIST 800-26: 10.1.3, 11.2.4</reference>
                        <reference>DCID 6/3: 6.B.3.a(5), 8.B.8.c(4), 8.B.8.c(5)</reference>
                  </Group>
                  <Group id="MA-4" hidden="true">
                        <title>Remote Maintenance</title>
                        <reference>ISO/IEC 17799: 11.4.4</reference>
                        <reference>NIST 800-26: 10.1.1, 17.1.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: EBRP-1</reference>
                        <reference>DCID 6/3: 8.B.8.d</reference>
                  </Group>
                  <Group id="MA-5" hidden="true">
                        <title>Maintenance Personnel</title>
                        <reference>ISO/IEC 17799: 6.2.3, 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: PRMP-1</reference>
                        <reference>DCID 6/3: 8.B.8.a</reference>
                  </Group>
                  <Group id="MA-6" hidden="true">
                        <title>Timely Maintenance</title>
                        <reference>NIST 800-26: 9.1.2</reference>
                        <reference>GAO FISCAM: SC-1.2</reference>
                        <reference>DOD 8500.2: COMS-1, COSP-1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5)</reference>
                  </Group>
            </Group>
            <Group id="media_protection" hidden="true">
                  <title>Applicable 800-53 Media Protection</title>
                  <Group id="MP-1" hidden="true">
                        <title>Media Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 10.7, 15.1.1, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2</reference>
                        <reference>DOD 8500.2: PESP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.6.c(7); 8.B.2</reference>
                  </Group>
                  <Group id="MP-2" hidden="true">
                        <title>Media Access</title>
                        <reference>ISO/IEC 17799: 10.7.3</reference>
                        <reference>NIST 800-26: 8.2.1, 8.2.2, 8.2.3, 8.2.6, 8.2.7</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(1), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-3" hidden="true">
                        <title>Media Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.7.3, 10.8.2, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2.5, 8.2.6, 10.2.9</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 8.B.2.a, 8.B.2.c</reference>
                  </Group>
                  <Group id="MP-4" hidden="true">
                        <title>Media Storage</title>
                        <reference>ISO/IEC 17799: 10.7.1, 10.7.2, 10.7.3, 10.7.4, 15.1.3</reference>
                        <reference>NIST 800-26: 7.1.4, 8.2.1, 8.2.2, 8.2.9, 10.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PESS-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-5" hidden="true">
                        <title>Media Transport</title>
                        <reference>ISO/IEC 17799: 10.8.3</reference>
                        <reference>NIST 800-26: 8.2.2, 8.2.4</reference>
                        <reference>DCID 6/3: 2.B.9.b(4)</reference>
                  </Group>
                  <Group id="MP-6" hidden="true">
                        <title>Media Sanitization</title>
                        <reference>ISO/IEC 17799: 9.2.6, 10.7.1, 10.7.2</reference>
                        <reference>NIST 800-26: 3.2.11, 3.2.12, 3.2.13, 8.2.8, 8.2.9, 8.2.10</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: PECS-1, PEDD-1</reference>
                        <reference>DCID 6/3: 8.B.5, 2.B.9.b(4), 8.B.5.a(4), 8.B.5.d, 8.B.5.e</reference>
                  </Group>
                  <Group id="MP-7" hidden="true">
                        <title>Media Destruction and Disposal</title>
                        <reference>ISO/IEC 17799: </reference>
                        <reference>NIST 800-26: </reference>
                        <reference>GAO FISCAM: </reference>
                        <reference>DOD 8500.2: </reference>
                        <reference>DCID 6/3: </reference>
                  </Group>
            </Group>
            <Group id="physical_and_environmental_protection" hidden="true">
                  <title>Applicable 800-53 Physical and Environmental Protection</title>
                  <Group id="PE-1" hidden="true">
                        <title>Physical and Environmental Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 7</reference>
                        <reference>DOD 8500.2: PETN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.D</reference>
                  </Group>
                  <Group id="PE-2" hidden="true">
                        <title>Physical Access Authorizations</title>
                        <reference>ISO/IEC 17799: 9.1.2, 9.1.6</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PECF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.E</reference>
                  </Group>
                  <Group id="PE-3" hidden="true">
                        <title>Physical Access Control</title>
                        <reference>ISO/IEC 17799: 9.1.1, 9.1.2, 9.1.5, 9.1.6, 10.5.1</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2, 7.1.5, 7.1.6, 7.1.8</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEPF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-4" hidden="true">
                        <title>Access Control for Transmission Medium</title>
                        <reference>ISO/IEC 17799: 9.2.3</reference>
                        <reference>NIST 800-26: 7.2.2, 16.2.9</reference>
                        <reference>DCID 6/3: 8.D.2, 4.B.1.a(8)</reference>
                  </Group>
                  <Group id="PE-5" hidden="true">
                        <title>Access Control for Display Medium</title>
                        <reference>ISO/IEC 17799: 9.1.2, 11.3.3</reference>
                        <reference>NIST 800-26: 7.2.1</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-6" hidden="true">
                        <title>Monitoring Physical Access</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-7" hidden="true">
                        <title>Visitor Control</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.7, 7.1.11</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-8" hidden="true">
                        <title>Access Records</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2, PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-9" hidden="true">
                        <title>Power Equipment and Power Cabling</title>
                        <reference>ISO/IEC 17799: 9.2.2, 9.2.3</reference>
                        <reference>NIST 800-26: 7.1.16</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-10" hidden="true">
                        <title>Emergency Shutoff</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEMS-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-11" hidden="true">
                        <title>Emergency Power</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>NIST 800-26: 7.1.18</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: COPS-1, COPS-2, COPS-3</reference>
                        <reference>DCID 6/3: 6.B.2.a(6), 6.B.2.a(7)</reference>
                  </Group>
                  <Group id="PE-12" hidden="true">
                        <title>Emergency Lighting</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEEL-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-13" hidden="true">
                        <title>Fire Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.12</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEFD-1, PEFS-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-14" hidden="true">
                        <title>Temperature and Humidity Controls</title>
                        <reference>ISO/IEC 17799: 9.2.1, 10.5.1, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.14, 7.1.15</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEHC-1, PETC-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-15" hidden="true">
                        <title>Water Damage Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.17</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-16" hidden="true">
                        <title>Delivery and Removal</title>
                        <reference>ISO/IEC 17799: 9.1.6, 9.2.7, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.3</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DCID 6/3: 8.B.5.e</reference>
                  </Group>
                  <Group id="PE-17" hidden="true">
                        <title>Alternate Work Site</title>
                        <reference>ISO/IEC 17799: 11.7.2</reference>
                        <reference>DOD 8500.2: EBRU-1</reference>
                  </Group>
                  <Group id="PE-18" hidden="true">
                        <title>Location of Information System Components</title>
                        <reference>ISO/IEC 17799: 9.2.1</reference>
                  </Group>
                  <Group id="PE-19" hidden="true">
                        <title>Information Leakage</title>
                  </Group>
            </Group>
            <Group id="planning" hidden="true">
                  <title>Applicable 800-53 Planning</title>
                  <Group id="PL-1" hidden="true">
                        <title>Security Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1, 15.1.1</reference>
                        <reference>NIST 800-26: 5</reference>
                        <reference>DOD 8500.2: DCAR-1, E3.4.6</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="PL-2" hidden="true">
                        <title>System Security Plan</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 4.1.5, 5.1.1, 5.1.2, 12.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: DCSD-1</reference>
                        <reference>DCID 6/3: 1.F.6, 2.B.6.c(3), 2.B.7.c(5), 9.E.2.a(1)(d), 9.F.2.a, Appendix C</reference>
                  </Group>
                  <Group id="PL-3" hidden="true">
                        <title>System Security Plan Update</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 3.2.10, 5.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 2.B.7.c(5)</reference>
                  </Group>
                  <Group id="PL-4" hidden="true">
                        <title>Rules of Behavior</title>
                        <reference>ISO/IEC 17799: 7.1.3, 8.1.3, 15.1.5</reference>
                        <reference>NIST 800-26: 4.1.3, 13.1.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 2.B.9.b</reference>
                  </Group>
                  <Group id="PL-5" hidden="true">
                        <title>Privacy Impact Assessment</title>
                        <reference>ISO/IEC 17799: 15.1.4</reference>
                        <reference>DCID 6/3: DCID: B.3.a; Manual: 8.B.9</reference>
                  </Group>
                  <Group id="PL-6" hidden="true">
                        <title>Security-Related Activity Planning</title>
                        <reference>ISO/IEC 17799: 15.3.1</reference>
                  </Group>
            </Group>
            <Group id="personnel_security" hidden="true">
                  <title>Applicable 800-53 Personnel Security</title>
                  <Group id="PS-1" hidden="true">
                        <title>Personnel Security Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 8.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 6</reference>
                        <reference>DOD 8500.2: PRRB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.E</reference>
                  </Group>
                  <Group id="PS-2" hidden="true">
                        <title>Position Categorization</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2</reference>
                        <reference>GAO FISCAM: SD-1.2</reference>
                        <reference>DCID 6/3: 8.E</reference>
                  </Group>
                  <Group id="PS-3" hidden="true">
                        <title>Personnel Screening</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.2.1, 6.2.3</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRAS-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(2), 2.B.8.b(5), 8.E</reference>
                  </Group>
                  <Group id="PS-4" hidden="true">
                        <title>Personnel Termination</title>
                        <reference>ISO/IEC 17799: 8.1.3, 8.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6), 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
                  <Group id="PS-5" hidden="true">
                        <title>Personnel Transfer</title>
                        <reference>ISO/IEC 17799: 8.3.1, 8.3.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6)</reference>
                  </Group>
                  <Group id="PS-6" hidden="true">
                        <title>Access Agreements</title>
                        <reference>ISO/IEC 17799: 6.1.5, 8.1.3</reference>
                        <reference>NIST 800-26: 6.1.5, 6.2.2</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 1.E.2, 8.E</reference>
                  </Group>
                  <Group id="PS-7" hidden="true">
                        <title>Third-Party Personnel Security</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 8.1.1, 8.1.2, 8.1.3, 8.2.1, 8.2.2, 11.2.1</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.7.10</reference>
                        <reference>DCID 6/3: 1.A.1, 8.D, 8.E</reference>
                  </Group>
                  <Group id="PS-8" hidden="true">
                        <title>Personnel Sanctions</title>
                        <reference>ISO/IEC 17799: 8.2.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.5</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
            </Group>
            <Group id="risk_assessment" hidden="true">
                  <title>Applicable 800-53 Risk Assessment</title>
                  <Group id="RA-1" hidden="true">
                        <title>Risk Assessment Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="RA-2" hidden="true">
                        <title>Security Categorization</title>
                        <reference>ISO/IEC 17799: 7.2.1</reference>
                        <reference>NIST 800-26: 1.1.3, 3.1.1</reference>
                        <reference>GAO FISCAM: SP-1, AC-1.1, AC-1.2</reference>
                        <reference>DOD 8500.2: E3.4.2</reference>
                        <reference>DCID 6/3: 3.C, 3.D, 9.E.2.a(1)(a), 9.E.2.a(1)(d)</reference>
                  </Group>
                  <Group id="RA-3" hidden="true">
                        <title>Risk Assessment</title>
                        <reference>ISO/IEC 17799: 4, 4.1, 4.2, 6.2.1, 10.10.2, 10.10.5, 12.5.1, 12.6.1, 14.1.1, 14.1.2</reference>
                        <reference>NIST 800-26: 1.1.2, 1.1.4, 1.1.5, 1.1.6, 1.2.1, 1.2.2, 1.2.3, 3.1.7, 3.1.8, 4.1.7, 7.1.13, 7.1.19, 12.2.4</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCDS-1, DCII-1, E3.3.10</reference>
                        <reference>DCID 6/3: 9.B</reference>
                  </Group>
                  <Group id="RA-4" hidden="true">
                        <title>Risk Assessment Update</title>
                        <reference>ISO/IEC 17799: 4.1</reference>
                        <reference>NIST 800-26: 1.1.2, 4.1.2</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: 9.B.4.f, 9.D.1.d</reference>
                  </Group>
                  <Group id="RA-5" hidden="true">
                        <title>Vulnerability Scanning</title>
                        <reference>ISO/IEC 17799: 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 14.2.1</reference>
                        <reference>DOD 8500.2: ECMT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(8)(b), 4.B.3.b(6)(b), 9.B.4.e</reference>
                  </Group>
            </Group>
            <Group id="system_and_services_acquisition" hidden="true">
                  <title>Applicable 800-53 System and Services Acquisition</title>
                  <Group id="SA-1" hidden="true">
                        <title>System and Services Acquisition Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.1, 15.1.1</reference>
                        <reference>NIST 800-26: 3</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SA-2" hidden="true">
                        <title>Allocation of Resources</title>
                        <reference>ISO/IEC 17799: 10.3.1</reference>
                        <reference>NIST 800-26: 3.1.2, 3.1.3, 3.1.5, 5.1.3</reference>
                        <reference>DOD 8500.2: DCPB-1, E3.3.4</reference>
                        <reference>DCID 6/3: DCID: C.2.a, Manual: 2.B.4.e(8)</reference>
                  </Group>
                  <Group id="SA-3" hidden="true">
                        <title>Life Cycle Support</title>
                        <reference>NIST 800-26: 3.1</reference>
                        <reference>DOD 8500.2: 5.8.1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 9.E.2</reference>
                  </Group>
                  <Group id="SA-4" hidden="true">
                        <title>Acquisitions</title>
                        <reference>ISO/IEC 17799: 12.1.1</reference>
                        <reference>NIST 800-26: 3.1.6, 3.1.7, 3.1.10, 3.1.11, 3.1.12</reference>
                        <reference>DOD 8500.2: DCAS-1, DCDS-1, DCIT-1, DCMC-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a; C.2.a, Manual: 9.B.4</reference>
                  </Group>
                  <Group id="SA-5" hidden="true">
                        <title>Information System Documentation</title>
                        <reference>ISO/IEC 17799: 10.7.4</reference>
                        <reference>NIST 800-26: 3.2.3, 3.2.4, 3.2.8, 12.1.1, 12.1.2, 12.1.3, 12.1.6, 12.1.7</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCCS-1, DCHW-1, DCID-1, DCSD-1, DCSW-1, ECND-1, DCFA-1</reference>
                        <reference>DCID 6/3: 4.B.2.b(2), 4.B.2.b(3), 4.B.4.b(4), 9.C.3</reference>
                  </Group>
                  <Group id="SA-6" hidden="true">
                        <title>Software Usage Restrictions</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10, 10.2.13</reference>
                        <reference>GAO FISCAM: SS-3.2, SP-2.1</reference>
                        <reference>DOD 8500.2: DCPD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-7" hidden="true">
                        <title>User Installed Software</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10</reference>
                        <reference>GAO FISCAM: SS-3.2</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-8" hidden="true">
                        <title>Security Engineering Principles</title>
                        <reference>ISO/IEC 17799: 12.1</reference>
                        <reference>NIST 800-26: 3.2.1</reference>
                        <reference>DOD 8500.2: DCBP-1, DCCS-1, E3.4.4</reference>
                        <reference>DCID 6/3: 1.H.1</reference>
                  </Group>
                  <Group id="SA-9" hidden="true">
                        <title>Outsourced Information System Services</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 10.2.1, 10.2.2, 10.6.2</reference>
                        <reference>NIST 800-26: 12.2.3</reference>
                        <reference>DOD 8500.2: DCDS-1, DCID-1 DCIT-1, DCPP-1</reference>
                        <reference>DCID 6/3: 1.B.1, 8.C.2, 8.E</reference>
                  </Group>
                  <Group id="SA-10" hidden="true">
                        <title>Developer Configuration Management</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-3</reference>
                        <reference>DCID 6/3: 4.B.4.b(4), 8.C.2.a</reference>
                  </Group>
                  <Group id="SA-11" hidden="true">
                        <title>Developer Security Testing</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>NIST 800-26: 3.2.1, 3.2.2, 10.2.5, 12.1.5</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-2.1</reference>
                        <reference>DOD 8500.2: E3.4.4</reference>
                        <reference>DCID 6/3: 4.B.4.b(4)</reference>
                  </Group>
            </Group>
            <Group id="system_and_communications_protection" hidden="true">
                  <title>Applicable 800-53 System and Communication Protection</title>
                  <Group id="SC-1" hidden="true">
                        <title>System and Communications Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.8.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SC-2" hidden="true">
                        <title>Application Partitioning</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCPA-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-3" hidden="true">
                        <title>Security Function Isolation</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCSP-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(1), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-4" hidden="true">
                        <title>Information Remnants</title>
                        <reference>ISO/IEC 17799: 10.8.1</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: ECRC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(14)</reference>
                  </Group>
                  <Group id="SC-5" hidden="true">
                        <title>Denial of Service Protection</title>
                        <reference>ISO/IEC 17799: 10.8.4, 13.2.1</reference>
                        <reference>DCID 6/3: 6.B.3.a(6)</reference>
                  </Group>
                  <Group id="SC-6" hidden="true">
                        <title>Resource Priority</title>
                        <reference>DCID 6/3: 6.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-7" hidden="true">
                        <title>Boundary Protection</title>
                        <reference>ISO/IEC 17799: 11.4.6</reference>
                        <reference>NIST 800-26: 16.2.2, 16.2.7, 16.2.9, 16.2.10, 16.2.11, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: COEB-1, EBBD-1, ECIM-1, ECVI-1</reference>
                        <reference>DCID 6/3: 4.B.4.a(27), 5.B.3.a(11)(b), 7.A.3, 7.B, 7.C, 7.D</reference>
                  </Group>
                  <Group id="SC-8" hidden="true">
                        <title>Transmission Integrity</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4, 11.2.9, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-9" hidden="true">
                        <title>Transmission Confidentiality</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>DOD 8500.2: ECCT-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8)(a)</reference>
                  </Group>
                  <Group id="SC-10" hidden="true">
                        <title>Network Disconnect</title>
                        <reference>ISO/IEC 17799: 11.5.6</reference>
                        <reference>NIST 800-26: 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)</reference>
                  </Group>
                  <Group id="SC-11" hidden="true">
                        <title>Trusted Path</title>
                        <reference>ISO/IEC 17799: 10.9.2</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.4.a(14)</reference>
                  </Group>
                  <Group id="SC-12" hidden="true">
                        <title>Cryptographic Key Establishment and Mgmt.</title>
                        <reference>ISO/IEC 17799: 12.3.1, 12.3.2</reference>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
                  <Group id="SC-13" hidden="true">
                        <title>Use of Validated Cryptography</title>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 1.G.1</reference>
                  </Group>
                  <Group id="SC-14" hidden="true">
                        <title>Public Access Protections</title>
                        <reference>ISO/IEC 17799: 10.7.4, 10.9.3</reference>
                        <reference>DOD 8500.2: EBPW-1</reference>
                  </Group>
                  <Group id="SC-15" hidden="true">
                        <title>Collaborative Computing</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: 7.G</reference>
                  </Group>
                  <Group id="SC-16" hidden="true">
                        <title>Transmission of Security Parameters</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.8.2, 10.9.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(3)</reference>
                  </Group>
                  <Group id="SC-17" hidden="true">
                        <title>Public Key Infrastructure Certificates</title>
                        <reference>ISO/IEC 17799: 12.3.2</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-18" hidden="true">
                        <title>Mobile Code</title>
                        <reference>ISO/IEC 17799: 10.4.1, 10.4.2</reference>
                        <reference>DOD 8500.2: DCMC-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 7.E</reference>
                  </Group>
                  <Group id="SC-19" hidden="true">
                        <title>Voice Over Internet Protocol</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: DCID 6/3 2.B.4.d, 9.D.1.a</reference>
                  </Group>
                  <Group id="SC-20" hidden="true">
                        <title>Secure Name Address Resolution Service (Authoritative Source)</title>
                  </Group>
                  <Group id="SC-21" hidden="true">
                        <title>Secure Name Address Resolution Service (Resolution)</title>
                  </Group>
                  <Group id="SC-22" hidden="true">
                        <title>Architecture and Provisioning for Name/Address Resolution Service</title>
                  </Group>
                  <Group id="SC-23" hidden="true">
                        <title>Session Authenticity</title>
                  </Group>
            </Group>
            <Group id="system_and_information_integrity" hidden="true">
                  <title>Applicable 800-53 System and Information Integrity</title>
                  <Group id="SI-1" hidden="true">
                        <title>System and Information Integrity Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5), 5.B.1.b(1), 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="SI-2" hidden="true">
                        <title>Flaw Remediation</title>
                        <reference>ISO/IEC 17799: 10.10.5, 12.4.1, 12.5.1, 12.5.2, 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 11.1.1, 11.1.2, 11.2.2, 11.2.7</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSQ-1, DCCT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(3), 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="SI-3" hidden="true">
                        <title>Malicious Code Protection</title>
                        <reference>ISO/IEC 17799: 10.4.1</reference>
                        <reference>NIST 800-26: 11.1.1, 11.1.2</reference>
                        <reference>DOD 8500.2: ECVP-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.1.a(4), 7.B.4.b(1)</reference>
                  </Group>
                  <Group id="SI-4" hidden="true">
                        <title>Information System Monitoring Tools and Techniques</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.10.1, 10.10.2, 10.10.4</reference>
                        <reference>NIST 800-26: 11.2.5, 11.2.6</reference>
                        <reference>DOD 8500.2: EBBD-1, EBVC-1, ECID-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(5)(b), 4.B.3.a(8)(b), 6.B.3.a(8)</reference>
                  </Group>
                  <Group id="SI-5" hidden="true">
                        <title>Security Alerts and Advisories</title>
                        <reference>ISO/IEC 17799: 6.1.7, 10.4.1</reference>
                        <reference>NIST 800-26: 14.1.1, 14.1.2, 14.1.5</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIVM-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="SI-6" hidden="true">
                        <title>Security Functionality Verification</title>
                        <reference>NIST 800-26: 11.2.1, 11.2.2</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSS-1</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.2.b(2)</reference>
                  </Group>
                  <Group id="SI-7" hidden="true">
                        <title>Software and Information Integrity</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.4</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4</reference>
                        <reference>DOD 8500.2: ECSD-2</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.1.a(3), 5.B.2.a(6)</reference>
                  </Group>
                  <Group id="SI-8" hidden="true">
                        <title>Spam Protection</title>
                        <reference>DCID 6/3: 5.B.1.a(4)</reference>
                  </Group>
                  <Group id="SI-9" hidden="true">
                        <title>Information Input Restrictions</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2</reference>
                        <reference>GAO FISCAM: SD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SI-10" hidden="true">
                        <title>Information Accuracy, Completeness, Validity, and Authenticity</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.1, 12.2.2</reference>
                        <reference>DCID 6/3: 7.B.2.h, 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-11" hidden="true">
                        <title>Error Handling</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.3, 12.2.4</reference>
                        <reference>DCID 6/3: 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-12" hidden="true">
                        <title>Information Output Handling and Retention</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.4</reference>
                        <reference>DOD 8500.2: PESP-1</reference>
                        <reference>DCID 6/3: 2.B.4.d, 8.B.9, 8.G</reference>
                  </Group>
            </Group>
      </Group>
      <!-- ==================================================================================================== -->
      <!-- =====================================  FDCC SECURITY GUIDANCE  ===================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following groups represent the collection of FDCC guidance for Microsoft Windows Vista.  For     -->
      <!-- specific recommendations regarding which rules to enable and which values to use, please refer to    -->
      <!-- the XCCDF profiles above.                                                                            -->
      <!--                                                                                                      -->
      <!-- **************************************************************************************************** -->
      <!-- ***  1 - Introduction                                                                            *** -->
      <!-- **************************************************************************************************** -->
      <Group id="introduction">
            <title>Introduction</title>
            <description>This guide has been created to assist federal agencies in effectively securing systems with Microsoft Windows Vista based on OMB Federal Desktop Core Configuration recommendations.<xhtml:br/><xhtml:br/>Under the direction of OMB and in collaboration with DHS, DISA, NSA, USAF, and Microsoft, NIST has provided the following baseline to help agencies test, implement, and deploy the Microsoft Windows Vista Federal Desktop Core Configuration (FDCC) baseline. The Federal Desktop Core Configuration (FDCC) is an OMB-mandated security configuration.<xhtml:br/><xhtml:br/>Please refer to the FDCC home page for additional information. http://fdcc.nist.gov</description>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  2 - FDCC Security Settings                                                                  *** -->
      <!-- **************************************************************************************************** -->
      <Group id="fdcc_security_settings">
            <title>FDCC Security Settings</title>
            <description>FDCC has identified the following controls that must be checked in order to verify compliance.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Account Policies Group                                                                    -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="account_policies_group">
                  <title>Account Policies Group</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Account Lockout Policy Settings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="account_lockout_policy_settings">
                        <title>Account Lockout Policy Settings</title>
                        <description>Attackers often attempt to gain access to user accounts by guessing passwords. Windows Vista can be configured to lock out (disable) an account when too many failed login attempts occur for a single user account in a certain time period. The following account lockout parameters are set in the NIST templates:<xhtml:br/><xhtml:br/>One of the main challenges in setting account policies is balancing security, functionality, and usability. For example, locking out user accounts after only a few failed logon attempts in a long time period may make it more difficult to gain unauthorized access to accounts by guessing passwords, but may also sharply increase the number of calls to the help desk to unlock accounts accidentally locked by failed attempts from legitimate users. This could also cause more users to write down their passwords or choose easier-to-remember passwords. Organizations should carefully think out such issues before setting Windows Vista account policies.</description>
                        <Value id="account_lockout_duration_var" operator="greater than or equal" type="number">
                              <title>Account Lockout Duration</title>
                              <description>The amount of time in seconds that an account is locked before it is automatically unlocked by the system. 15 minutes = 900 seconds A value of 0 means that an administrator must unlock the account.</description>
                              <value>900</value>
                              <value selector="admin_unlock">0</value>
                              <value selector="900_seconds">900</value>
                              <value selector="86400_seconds">86400</value>
                        </Value>
                        <Value id="account_lockout_threshold_var" operator="less than or equal" type="number">
                              <title>Account Lockout Threshold</title>
                              <description>The maximum number of failed attempts that can occur before the account is locked out</description>
                              <value>50</value>
                              <value selector="3_attempts">3</value>
                              <value selector="5_attempts">5</value>
                              <value selector="10_attempts">10</value>
                              <value selector="50_attempts">50</value>
                        </Value>
                        <Value id="account_lockout_reset_counter_var" operator="greater than or equal" type="number">
                              <title>Reset Account Lockout Counter After</title>
                              <description>The time period in seconds to be used with the lockout threshold value. For example, if the threshold is set to 10 attempts and the duration is set to 15 minutes, then if more than 10 failed login attempts occur with a single user account within a 15-minute period, the account will be disabled. 15 minutes = 900 seconds</description>
                              <value>900</value>
                              <value selector="900_seconds">900</value>
                              <value selector="3600_seconds">3600</value>
                              <value selector="86400_seconds">86400</value>
                        </Value>
                        <Rule id="account_lockout_duration" selected="false" weight="10.0">
                              <title>Account Lockout Duration</title>
                              <description>This value specifies how long the user account should be locked out. This is often set to a low but substantial value (e.g., 15 minutes), for two reasons. First, a legitimate user that is accidentally locked out only has to wait 15 minutes to regain access, instead of asking an administrator to unlock the account. Second, an attacker who is guessing passwords using brute force methods will only be able to try a small number of passwords at a time, then wait 15 minutes before trying any more. This greatly reduces the chances that the brute force attack will be successful.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-7"/>
                              <ident system="http://cce.mitre.org">CCE-2363-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-980</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60071" value-id="account_lockout_duration_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6007"/>
                              </check>
                        </Rule>
                        <Rule id="account_lockout_threshold" selected="false" weight="10.0">
                              <title>Account Lockout Threshold</title>
                              <description>The threshold value specifies the maximum number of failed attempts that can occur before the account is locked out.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-7"/>
                              <ident system="http://cce.mitre.org">CCE-3177-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-658</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60081" value-id="account_lockout_threshold_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6008"/>
                              </check>
                        </Rule>
                        <Rule id="account_lockout_reset_counter" selected="false" weight="10.0">
                              <title>Reset Account Lockout Counter After</title>
                              <description>This specifies the time period to be used with the lockout threshold value. For example, if the threshold is set to 10 attempts and the duration is set to 15 minutes, then if more than 10 failed login attempts occur with a single user account within a 15-minute period, the account will be disabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-7"/>
                              <ident system="http://cce.mitre.org">CCE-2715-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-733</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60091" value-id="account_lockout_reset_counter_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6009"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Password Policy Settings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="password_policy_settings">
                        <title>Password Policy Settings</title>
                        <description>In addition to educating users regarding the selection and use of good passwords, it is also important to set password parameters so that passwords are sufficiently strong. This reduces the likelihood of an attacker guessing or cracking passwords to gain unauthorized access to the system.86 As described in Section 3.2.1, NIST recommends the use of NTLM v2 or Kerberos instead of LM or NTLM v1 for authentication. The following parameters are specified in the NIST templates:</description>
                        <Value id="password_enforce_history_var" operator="greater than or equal" type="number">
                              <title>Enforce Password History</title>
                              <description>The number of passwords remembered</description>
                              <value>24</value>
                              <value selector="24_passwords">24</value>
                              <value selector="5_passwords">5</value>
                        </Value>
                        <Value id="password-maximum_age_var" operator="less than or equal" type="number">
                              <title>Maximum Password Age</title>
                              <description>The maximum age in seconds before a password expires. (90 days = 7776000 seconds; 60 days = 5184000)</description>
                              <value>7776000</value>
                              <value selector="5184000_seconds">5184000</value>
                              <value selector="7776000_seconds">7776000</value>
                        </Value>
                        <Value id="password-minimum-age_var" operator="greater than or equal" type="number">
                              <title>Minimum Password Age</title>
                              <description>The minimum age in seconds before a password may be changed. (1 day = 86400 seconds; 5 days = 432000)</description>
                              <value>86400</value>
                              <value selector="86400_seconds">86400</value>
                              <value selector="432000_seconds">432000</value>
                        </Value>
                        <Value id="password-minimum-length_var" operator="greater than or equal" type="number">
                              <title>Minimum Password Length</title>
                              <description>The minimum number of characters required for a password</description>
                              <value>8</value>
                              <value selector="8_characters">8</value>
                              <value selector="9_characters">9</value>
                              <value selector="12_characters">12</value>
                              <value selector="14_characters">14</value>
                              <value selector="15_characters">15</value>
                        </Value>
                        <Value id="password_complexity_var" operator="equals" type="boolean">
                              <title>Enforce Password Complexity</title>
                              <description>This value determines whether Windows Vista implements a minimum level of strong password filtering. 1 = enabled</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="password_reversible_encryption_var" operator="equals" type="boolean">
                              <title>Enforce Reversible Encryption When Storing Passwords</title>
                              <description>This value determines whether Windows Vista is configured to prevent passwords from being stored using a two-way hash. 1 = enabled</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="password_enforce_history" selected="false" weight="10.0">
                              <title>Enforce Password History</title>
                              <description>This setting determines how many old passwords the system will remember for each account. Users will be prevented from reusing any of the old passwords. For example, if this is set to 24, then the system will not allow users to reuse any of their last 24 passwords. Old passwords may have been compromised, or an attacker may have taken a long time to crack encrypted passwords. Reusing an old password could inadvertently give attackers access to the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2323-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-60</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60011" value-id="password_enforce_history_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6001"/>
                              </check>
                        </Rule>
                        <Rule id="password-maximum_age" selected="false" weight="10.0">
                              <title>Maximum Password Age</title>
                              <description>This forces users to change their passwords regularly. The lower this value is set, the more likely users will be to choose poor passwords that are easier for them to remember (e.g., Mypasswd1, Mypasswd2, Mypasswd3). The higher this value is set, the more likely the password will be compromised and used by unauthorized parties.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2967-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-871</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60021" value-id="password-maximum_age_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6002"/>
                              </check>
                        </Rule>
                        <Rule id="password-minimum-age" selected="false" weight="10.0">
                              <title>Minimum Password Age</title>
                              <description>This setting requires users to wait for a certain number of days before changing their password again. The setting prevents a user from changing a password when it reaches the maximum age and then immediately changing it back to the previous password. Unfortunately, this setting also prevents users who inadvertently reveal a new password to others from changing it immediately without administrator intervention.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-3240-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-324</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60031" value-id="password-minimum-age_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6003"/>
                              </check>
                        </Rule>
                        <Rule id="password-minimum-length" selected="false" weight="10.0">
                              <title>Minimum Password Length</title>
                              <description>This setting specifies the minimum length of a password in characters. The rationale behind this setting is that longer passwords are more difficult to guess and crack than shorter passwords. The downside is that longer passwords are often more difficult for users to remember. Organizations that want to set a relatively large minimum password length should encourage their users to use passphrases, which may be easier to remember than conventional passwords.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2883-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-100</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60061" value-id="password-minimum-length_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6006"/>
                              </check>
                        </Rule>
                        <Rule id="password_complexity" selected="false" weight="10.0">
                              <title>Password Complexity</title>
                              <description>Like the Minimum Password Length setting, this setting makes it more difficult to guess or crack passwords. Enabling this setting implements complexity requirements including not having the user account name in the password and using a mixture of character types, including upper case and lower case letters, digits, and special characters such as punctuation marks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-3033-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-633</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60041" value-id="password_complexity_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6004"/>
                              </check>
                        </Rule>
                        <Rule id="password_reversible_encryption" selected="false" weight="10.0">
                              <title>Reversible Password Encryption</title>
                              <description>If this setting is enabled, passwords will be stored in a decryptible format, putting them at higher risk of compromise. This setting should be disabled unless it is needed to support a legacy authentication protocol, such as Challenge Handshake Authentication Protocol (CHAP).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-3311-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-479</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60051" value-id="password_reversible_encryption_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6005"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Local Policies Group                                                                      -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="local_policies_group">
                  <title>Local Policies Group</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                Audit Policy Settings                -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="audit_policy_ettings">
                        <title>Audit Policy Settings</title>
                        <description>todo - description needed</description>
                        <Value id="audit_account_logon_events_var" type="string" operator="pattern match">
                              <title>Audit Account Logon Events</title>
                              <description>Audits when a user logs on or off a remote computer from this workstation.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_account_management_var" type="string" operator="pattern match">
                              <title>Audit Account Management</title>
                              <description>Audits when a user account or group is created, changed, or deleted; a user account is renamed, disabled, or enabled; a password is set or changed.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_directory_service_access_var" type="string" operator="pattern match">
                              <title>Audit Directory Service Access</title>
                              <description>Audit Directory Service Access</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_logon_events_var" type="string" operator="pattern match">
                              <title>Audit Logon Events</title>
                              <description>Audits users logging on, logging off, or making a network connection to the local computer.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_object_access_var" type="string" operator="pattern match">
                              <title>Audit Object Access</title>
                              <description>Audits a user accessing an object (for example, a file, folder, registry key, or printer) that has its own SACL specified.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_policy_change_var" type="string" operator="pattern match">
                              <title>Audit Policy Change</title>
                              <description>Audits every change to user rights assignment policies, audit policies, and trust policies.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_privilege_use_var" type="string" operator="pattern match">
                              <title>Audit Privilege Use</title>
                              <description>Audits each instance of a user exercising a user right.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_process_tracking_var" type="string" operator="pattern match">
                              <title>Audit Process Tracking</title>
                              <description>Audits detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="audit_system_events_var" type="string" operator="pattern match">
                              <title>Audit System Events</title>
                              <description>Audits when a user restarts or shuts down the computer or when an event occurs that affects either the system security or the security log.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="audit_account_logon_events" selected="false" weight="10.0">
                              <title>Audit Account Logon Events</title>
                              <description>Audits when a user logs on or off a remote computer from this workstation.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2820-9</ident>
                              <ident system="http://cce.mitre.org">CCE-3089-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2628</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2543</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_account_logon_events_var" export-name="oval:gov.nist.fdcc.vista:var:29"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:27"/>
                              </check>
                        </Rule>
                        <Rule id="audit_account_management" selected="false" weight="10.0">
                              <title>Audit Account Management</title>
                              <description>Audits when a user account or group is created, changed, or deleted; a user account is renamed, disabled, or enabled; a password is set or changed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-3287-0</ident>
                              <ident system="http://cce.mitre.org">CCE-3234-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2000</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1646</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_account_management_var" export-name="oval:gov.nist.fdcc.vista:var:31"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:29"/>
                              </check>
                        </Rule>
                        <Rule id="audit_directory_service_access" selected="false" weight="10.0">
                              <title>Audit Directory Service Access</title>
                              <description>Audits the event of a user accessing an active directory object that has its own System Access Control List (SACL) specified. This setting is not applicable to Windows XP systems.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-3041-1</ident>
                              <ident system="http://cce.mitre.org">CCE-3309-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2118</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2390</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_directory_service_access_var" export-name="oval:gov.nist.fdcc.vista:var:32"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:30"/>
                              </check>
                        </Rule>
                        <Rule id="audit_logon_events" selected="false" weight="10.0">
                              <title>Audit Logon Events</title>
                              <description>Audits users logging on, logging off, or making a network connection to the local computer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-3076-7</ident>
                              <ident system="http://cce.mitre.org">CCE-2970-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1686</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1744</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_logon_events_var" export-name="oval:gov.nist.fdcc.vista:var:33"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:32"/>
                              </check>
                        </Rule>
                        <Rule id="audit_object_access" selected="false" weight="10.0">
                              <title>Audit Object Access</title>
                              <description>Audits a user accessing an object (for example, a file, folder, registry key, or printer) that has its own SACL specified. Auditing of success or failure of system wide object access will create numerous log entries. Certain object access failures may be normal as a result of applications requesting all access types to objects, even though the application does not require all access types to function properly. Use object access auditing with caution.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2724-3</ident>
                              <ident system="http://cce.mitre.org">CCE-3243-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2640</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1991</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_object_access_var" export-name="oval:gov.nist.fdcc.vista:var:35"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:34"/>
                              </check>
                        </Rule>
                        <Rule id="audit_policy_change" selected="false" weight="10.0">
                              <title>Audit Policy Change</title>
                              <description>Audits every change to user rights assignment policies, audit policies, and trust policies.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2746-6</ident>
                              <ident system="http://cce.mitre.org">CCE-2653-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2412</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2347</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_policy_change_var" export-name="oval:gov.nist.fdcc.vista:var:36"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:35"/>
                              </check>
                        </Rule>
                        <Rule id="audit_privilege_use" selected="false" weight="10.0">
                              <title>Audit Privilege Use</title>
                              <description>Audits each instance of a user exercising a user right. This is likely to generate a very large number of events.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2322-6</ident>
                              <ident system="http://cce.mitre.org">CCE-3257-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2431</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2584</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_privilege_use_var" export-name="oval:gov.nist.fdcc.vista:var:37"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:36"/>
                              </check>
                        </Rule>
                        <Rule id="audit_process_tracking" selected="false" weight="10.0">
                              <title>Audit of Process Tracking</title>
                              <description>Audits detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access. Enabling this setting will generate many events, so it should only be used when absolutely necessary.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-3024-7</ident>
                              <ident system="http://cce.mitre.org">CCE-2927-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2529</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2617</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_process_tracking_var" export-name="oval:gov.nist.fdcc.vista:var:42"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:40"/>
                              </check>
                        </Rule>
                        <Rule id="audit_system_events" selected="false" weight="10.0">
                              <title>Audit System Events</title>
                              <description>Audits when a user restarts or shuts down the computer or when an event occurs that affects either the system security or the security log.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2953-8</ident>
                              <ident system="http://cce.mitre.org">CCE-3222-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2420</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1680</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="audit_system_events_var" export-name="oval:gov.nist.fdcc.vista:var:38"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:37"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Security Options Settings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="security_options_settings">
                        <title>Security Options Settings</title>
                        <description>Besides the Local Security Policy settings mentioned earlier in this section, additional settings called Security Options can be modified to achieve greater security than the default settings provide. The NIST templates specify values for dozens of such settings. Examples of the types of settings available are as follows: <xhtml:ul>
                                    <xhtml:li>Limiting the use of blank passwords</xhtml:li>
                                    <xhtml:li>Renaming the default Administrator and Guest accounts</xhtml:li>
                                    <xhtml:li>Restricting remote access to floppy and CD-ROM drives</xhtml:li>
                                    <xhtml:li>Encrypting secure channel data in a domain</xhtml:li>
                                    <xhtml:li>Securing the interactive logon screen (e.g., not showing the previous user’s account name, displaying a warning banner, prompting users to change passwords before they expire)</xhtml:li>
                                    <xhtml:li>Restricting which types of network access may be performed</xhtml:li>
                                    <xhtml:li>Specifying which types of authentication may be used (e.g., NTLM v2).</xhtml:li>
                              </xhtml:ul>The Security Options settings can also be accessed and adjusted manually by performing the following steps:<xhtml:ol>
                                    <xhtml:li>From the Start menu, choose Control Panel.</xhtml:li>
                                    <xhtml:li>Select Administrative Tools, and then choose Local Security Policy.</xhtml:li>
                                    <xhtml:li>Expand Local Policies and select Security Options.</xhtml:li>
                                    <xhtml:li>The right pane lists the security option and indicates the current setting for each. Make any necessary changes by double-clicking on the appropriate security option, modifying the setting, and clicking OK to save the change.</xhtml:li>
                              </xhtml:ol>
                        </description>
                        <Value id="AdministratorAccountStatus_var" operator="equals" type="boolean">
                              <title>Accounts: Administrator account status</title>
                              <description>The Administrator account status is enabled to allow the administrator to perform configuration control of the system.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="guest-account-status_var" operator="equals" type="boolean">
                              <title>Status of Guest Account</title>
                              <description>This value defines the desired status of the built-in Guest account. 0 = disabled; 1 = enabled.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="limit-blank-password-use_var" operator="equals" type="number">
                              <title>Accounts: Limit local account use to blank passwords to console logon only</title>
                              <description>This value defines the desired status of limiting the use of blank passwords. 1 = enabled; 0= disabled</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <!-- Accounts: Rename administrator account -->
                        <!-- Accounts: Rename guest account -->
                        <Value id="audit-access-global-system-objects_var" operator="equals" type="number">
                              <title>Audit: Audit the access of global system objects</title>
                              <description>Controls the ability to audit access of global systems objects. When this setting is enabled, system objects such as mutexes, events, semaphores, and DOS devices, are created with a default system access control list (SACL).</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="audit-use-backup-restore-privilege_var" operator="equals" type="string">
                              <title>Audit: Audit the use of Backup and Restore privilege</title>
                              <description>Controls the ability to audit the use of all user privileges, including Backup and Restore. If this policy is disabled, certain user rights will not be audited even if "Audit privilege use" audit policy is enabled.</description>
                              <value>00</value>
                              <value selector="disabled">00</value>
                              <value selector="enabled">01</value>
                        </Value>
                        <Value id="override-audit-policy-settings_var" operator="equals" type="number">
                              <title>Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings</title>
                              <description>Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="shutdown-system-unable-log-audits_var" operator="equals" type="number">
                              <title>Audit: Shut down system immediately if unable to log security audits</title>
                              <description>If events cannot be written to the security log, the system is halted immediately. If the system halts as a result of a full log, an administrator must log ont the system and clear the log.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="allow-format-eject-removable-media_var" operator="equals" type="number">
                              <title>Devices: Allow only administrators to format and eject removable media</title>
                              <description>Verifies that only the correct users are allowed to format and eject removable media 0 - Only Administrator, 1 - Only Administrators and power users, 2 - Only Administrators and Interactive user</description>
                              <value>0</value>
                              <value selector="administrator_only">0</value>
                              <value selector="administrator_and_powerusers_only">1</value>
                              <value selector="administrator_and_interactiveuser_only">2</value>
                        </Value>
                        <Value id="prevent-users-installing-printers_var" operator="equals" type="number">
                              <title>Prevent Users From Installing Printer Drivers</title>
                              <description>Defines who is allowed to add and to delete printer drivers on the local system. 1 = Enabled; 0 = disabled</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="restrict-cdrom-access-local-users-only_var" operator="equals" type="number">
                              <title>Restrict Access to CDROM Drive</title>
                              <description>This value determines if access to the CDROM drive is restricted to locally logged-on users. 1 = restricted</description>
                              <value>0</value>
                              <value selector="not_restricted">0</value>
                              <value selector="restricted">1</value>
                        </Value>
                        <Value id="restrict-floppy-access-local-users-only_var" operator="equals" type="number">
                              <title>Restrict Access to Floppy Drive</title>
                              <description>This value determines if access to the floppy drive is restricted to locally logged-on users. 1 = restricted</description>
                              <value>0</value>
                              <value selector="not_restricted">0</value>
                              <value selector="restricted">1</value>
                        </Value>
                        <Value id="digitally-encrypt-or-sign-secure-channel-data-always_var" operator="equals" type="number">
                              <title>Domain member: Digitally encrypt or sign secure channel data (always)</title>
                              <description>Domain member: Digitally encrypt or sign secure channel data (always). Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted or signed. If this policy is enabled, outgoing secure channel traffic should be encrypted.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="digitally-encrypt-secure-channel-data-when-possible_var" operator="equals" type="number">
                              <title>Domain member: Digitally encrypt secure channel data (when possible)</title>
                              <description>Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but not all information is encrypted. If this policy is enabled, outgoing secure channel traffic should be encrypted.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="digitally-sign-secure-channel-data-when-possible_var" operator="equals" type="number">
                              <title>Domain member: Digitally sign secure channel data (when possible)</title>
                              <description>Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but the channel is not integrity checked. If this policy is enabled, all outgoing secure channel traffic should be signed.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="disable-machine-account-password-changes_var" operator="equals" type="number">
                              <title>Domain member: Disable machine account password changes</title>
                              <description>Computer account passwords are changed automatically every seven days. Enabling this policy to disable automatic password changes can make the system more vulnerable to malicious access. Frequent password changes can be a significant safeguard for your system. If this policy is disabled, a new password for the computer account will be generated every week.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="maximum_machine-account-password-age_var" operator="equals" type="number">
                              <title>Maximum Machine Account Password Age</title>
                              <description>This setting controls the maximum password age that a machine account may have.</description>
                              <value>30</value>
                              <value selector="7_days">7</value>
                              <value selector="30_days">30</value>
                        </Value>
                        <Value id="require-strong-session-key_var" operator="equals" type="number">
                              <title>Require Strong Session Key</title>
                              <description>This setting controls the required strength of a session key.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="do-not-display-last-user-name_var" operator="equals" type="number">
                              <title>Interactive logon: Do not display last user name</title>
                              <description>This setting determines whether the name of the last user to log on to the computer will be displayed in the Windows logon dialog box.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="do-not-require-ctrlaltdel_var" operator="equals" type="number">
                              <title>Interactive logon: Do not require CTRL+ALT+DEL</title>
                              <description>Disabling the Ctrl+Alt+Del security attention sequence can compromise system security. Because only Windows responds to the Ctrl+Alt+Del security sequence, you can be assured that any passwords you enter following that sequence are sent only to Windows. If you eliminate the sequence requirement, malicious programs can request and receive your Windows password. Disabling this sequence also suppresses a custom logon banner. 0 = disabled</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="message-text-users-attempting-logon_var" operator="pattern match" type="string">
                              <title>Interactive logon: Message text for users attempting to log on</title>
                              <description>Specifies a text message that is displayed to users when they log on. This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited.</description>
                              <value>.+</value>
                              <value selector="todo">.+</value>
                        </Value>
                        <Value id="message-title-users-attempting-logon_var" operator="pattern match" type="string">
                              <title>Interactive logon: Message title for users attempting to log on</title>
                              <description>The logon banner should be titled with a warning label containing the name of the owning organization.</description>
                              <value>.+</value>
                              <value selector="todo">.+</value>
                        </Value>
                        <Value id="number-of-previous-logons-to-cache_var" operator="less than or equal" type="number">
                              <title>Number of Previous Logons to Cache (in Case Domain Controller Is Not Available)</title>
                              <description>Defines the number of last logon credentials cached for users who log on interactively to a system.</description>
                              <value>2</value>
                              <value selector="0_cached">0</value>
                              <value selector="1_cached">1</value>
                              <value selector="2_cached">2</value>
                              <value selector="5_cached">5</value>
                              <value selector="10_cached">10</value>
                        </Value>
                        <Value id="prompt-user-to-change-password-before-expiration_var" operator="equals" type="number">
                              <title>Prompt User to Change Password Before Expiration</title>
                              <description>This setting configures the system to display a warning to users telling them how many days are left before their password expires.</description>
                              <value>14</value>
                              <value selector="14_days">14</value>
                        </Value>
                        <Value id="require-domain-controller-authentication-to-unlock_var" operator="equals" type="number">
                              <title>Require Domain Controller Authentication to Unlock Workstation</title>
                              <description>This setting controls the behavior of the system when you attempt to unlock the workstation. If this setting is enabled, the system will pass the credentials to the domain controller (if in a domain) for authentication before allowing the system to be unlocked.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="smart-card-removal-behaviour_var" operator="greater than or equal" type="number">
                              <title>Smart Card Removal Behavior</title>
                              <description>This value determines the desired behavior when a smart card is removed. 0 - No action 1 - Lock workstation 2 - Force logoff</description>
                              <value>1</value>
                              <value selector="no_action">0</value>
                              <value selector="lock_workstation">1</value>
                              <value selector="force_logoff">2</value>
                        </Value>
                        <Value id="digitally-sign-communications-client-always_var" operator="equals" type="number">
                              <title>Client Digitally Sign Communications (Always)</title>
                              <description>This check verifies that the client policy is set to always sign packets.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="digitally-sign-communications-client-server-agrees_var" operator="equals" type="number">
                              <title>Microsoft network client: Digitally sign communications (if server agrees)</title>
                              <description>This check verifies that the client policy is set to sign packets if the server agrees.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="send-unencrypted-password-to-third-party-smb-servers_var" operator="equals" type="number">
                              <title>Microsoft network client: Send unencrypted password to third-party SMB servers</title>
                              <description>Some non-Microsoft SMB servers only support unencrypted (plain text) password authentication. Sending plain text passwords across the network, when authenticating to an SMB server, reduces the overall security of the environment. Check with the Vendor of the SMB server to see if there is a way to support encrypted password authentication.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="amount-of-idle-time-required-before-suspending-session_var" operator="equals" type="number">
                              <title>Amount of Idle Time Required Before Suspending Session</title>
                              <description>Administrators should use this setting to control when a computer disconnects an inactive SMB session. If client activity resumes, the session is automatically reestablished.</description>
                              <value>15</value>
                              <value selector="15_minutes">15</value>
                        </Value>
                        <Value id="digitally-sign-communications-server-always_var" operator="equals" type="number">
                              <title>Microsoft network server: Digitally sign communications (always)</title>
                              <description>This check verifies that the server policy is set to always sign packets.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="digitally-sign-communications-server-client-agrees_var" operator="equals" type="number">
                              <title>Microsoft network server: Digitally sign communications (if client agrees)</title>
                              <description>Microsoft network server: Digitally sign communications (if client agrees). This check verifies that the server policy is set to sign packets if the client agrees.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="disconnect-client-when-logon-hours-expire_var" operator="equals" type="number">
                              <title>Microsoft network server: Disconnect clients when logon hours expire</title>
                              <description>Users should not be permitted to remain logged on to the network after they have exceeded their permitted logon hours. In many cases, this indicates that a user forgot to log off before leaving for the day. However, it may also indicate that a user is attempting unauthorized access at a time when the system may be less closely monitored.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="enable-automatic-logon_var" operator="equals" type="string">
                              <title>MSS: (AutoAdminLogon) Enable Automatic Logon (Not Recommended)</title>
                              <description>Determines whether the automatic logon feature is enabled. Automatic logon uses the domain, user name, and password stored in the registry to log users on to the computer when the system starts. The Log On to Windows dialog box is not displayed.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="disable-ip-source-routing_var" operator="equals" type="number">
                              <title>MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)</title>
                              <description>todo - description needed</description>
                              <value>0</value>
                              <value selector="source_routing_packets_allowed">0</value>
                              <value selector="source_routing_packets_ignored">1</value>
                              <value selector="source_routing_packets_disabled">2</value>
                        </Value>
                        <Value id="enable-dead-gw-detect_var" operator="equals" type="number">
                              <title>MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)</title>
                              <description>todo - description needed</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="enable-icmp-redirect_var" operator="equals" type="number">
                              <title>MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes</title>
                              <description>todo - description needed</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="keep-alive-time_var" operator="equals" type="number">
                              <title>MSS: (KeepAliveTime)How often keep-alive packets are sent in milliseconds</title>
                              <description>This value controls how often TCP attempts to verify that an idle connection is still intact by sending a keep-alive packet. If the remote computer is still reachable, it acknowledges the keep-alive packet. HKLM\System\CurrentControlSet\Tcpip\Parameters\KeepAliveTime</description>
                              <value>300000</value>
                              <value selector="300000_seconds">300000</value>
                        </Value>
                        <Value id="no-name-release-on-demand_var" operator="equals" type="number">
                              <title>MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers</title>
                              <description>Network basic input/output system (NetBIOS) over TCP/IP is a networking protocol that, among other things, provides a means of easily resolving NetBIOS names registered on Windows- based systems to the IP addresses configured on those systems. This value determines whether the computer releases its NetBIOS name when it receives a name release request. The NoNameReleaseOnDemand setting configures the system to refuse name release requests to release its SMB name. This setting prevents an attacker from sending a name release request to a server, causing the server to be inaccessible to legitimate clients. If this setting is configured on a client, however, and that client is mis-configured with the same name as a critical server, the server will be unable to recover the name, and legitimate requests may be directed to the rogue server instead, causing a denial of service condition at best.
                                    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netbt\Parameters\ NoNameReleaseOnDemand registry key.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="ntfs-disable-8dot3-name-creation_var" operator="equals" type="number">
                              <title>MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames (recommended) (Disabled = 0)</title>
                              <description>Vista supports 8.3 file name formats for backward compatibility with 16- bit applications. The 8.3 file name convention is a naming format that allows file names that are up to eight characters in length. The following registry value entry has been added to the template in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem\ NtfsDisable8dotNameCreation registry key. </description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="perform-router-discovery_var" operator="equals" type="number">
                              <title>MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)</title>
                              <description>This setting is used to enable or disabled the Internet Router Discovery Protocol (IRDP). IRDP allows the system to detect and configure Default Gateway addresses automatically. HKLM\System\CurrentControlSet\Tcpip\Parameters\PerformRouterDiscovery</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                              <value selector="enabled_only_if_dhcp_sends_perform_router_discovery_option">2</value>
                        </Value>
                        <Value id="safe-dll-search-mode_var" operator="equals" type="number">
                              <title>MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)</title>
                              <description>Most programs on the Windows platform make use of various Dynamic Link Libraries (DLL) to avoid having to reimplement functionality. The operating system actually loads several DLLs for each program, depending on what type of program it is. When the program does not specify an absolute location for a DLL, the default search order is used to locate it. By default, the search order used by the operating system is as follows: 1. Memory 2. KnownDLLs 3. Manifests and .local 4. Application directory 5. Current working directory 6. System directories (%systemroot%, %systemroot%\system, and %systemroot%\system32) 7. The path variable The fact that the current working directory is searched before the system directories can be used by someone with access to the file system to cause a program launched by a user to load a spoofed DLL. If a user launches a program by double-clicking a document, the current working directory is actually the location of the
                                    document. If a DLL in that directory has the same name as a system DLL in that location will then be loaded instead of the system DLL. This attack vector was actually used by the Nimda virus. To combat this, a new setting was created in Service Pack 3, which moves the current working directory to after the system directories in the search order. To avoid application compatibility issues, however, this switch was not turned on by default. To turn it on, set the following registry valueMACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SafeDllSearchMode</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="screen-saver-grace-period_var" operator="equals" type="number">
                              <title>MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)</title>
                              <description>Setting Added to Registry to Make Screensaver Password Protection Immediate The default grace period allowed for user movement before the screen – saver lock takes effect is five seconds. Leaving the grace period in the default setting makes your computer vulnerable to a potential attack from someone walking up to the console to attempt to log onto the system before the lock takes effect. An entry to the registry can be made to adjust the length of the grace period.</description>
                              <value>0</value>
                              <value selector="zero_seconds">0</value>
                              <value selector="5_seconds">5</value>
                        </Value>
                        <Value id="syn-attack-protect_var" operator="equals" type="number">
                              <title>MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)</title>
                              <description>This registry value causes TCP to adjust retransmission of SYN- ACKs. When you configure this value, the connection responses time- out more quickly in the event of a connect request (SYN) attack. 1 = Connections timeout more quickly if a SYN attack is detected 0 = No additional protection, use default settings Note: W2K had another option = 2 that has been incorporated into option 1 in W2K3. HKLM\System\CurrentControlSet\Tcpip\Parameters\SynAttackProtect</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="tcp-max-connect-response-retransmissions_var" operator="equals" type="number">
                              <title>MSS: (TCPMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged</title>
                              <description>This parameter determines the number of times that TCP retransmits a SYN before aborting the attempt. The retransmission time-out is doubled with each successive retransmission in a given connect attempt. The initial time-out value is three seconds. 0 = No retransmission, half- open connections dropped after 3 seconds 1 = 3 seconds, half- open connections dropped after 9 seconds 2 = 3 and 6 seconds, half- open connections dropped after 21 seconds 3 = 3, 6, and 9 seconds, half- open connections dropped after 45 seconds HKLM\System\CurrentControlSet\Tcpip\Parameters\TcpMaxConnectResponseRetransmissions</description>
                              <value>2</value>
                              <value selector="No_retransmission_half_open_connections_dropped_after_3_seconds">0</value>
                              <value selector="3_seconds_half_open_connections_dropped_after_9_seconds">1</value>
                              <value selector="3_and_6_seconds_half_open_connections_dropped_after_21_seconds">2</value>
                              <value selector="3_6_and_9_seconds_half_open_connections_dropped_after_45_seconds">3</value>
                        </Value>
                        <Value id="tcp-max-data-retransmissions_var" operator="equals" type="number">
                              <title>MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)</title>
                              <description>MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)</description>
                              <value>3</value>
                              <value selector="value_of_3">3</value>
                              <value selector="value_of_5">5</value>
                        </Value>
                        <Value id="warning-level_var" operator="equals" type="number">
                              <title>MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning</title>
                              <description>Windows Server 2003 and Service Pack 3 for Windows 2000 include a new feature for generating a security audit in the security event log when the security log reaches a user defined threshold. Note: new to W2K3 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\WarningLevel</description>
                              <value>90</value>
                              <value selector="90_percent">90</value>
                        </Value>
                        <!-- Network access: Allow anonymous SID/Name translation -->
                        <Value id="anonymous_sid_name_translation_var" operator="equals" type="string">
                              <title>Network access: Allow anonymous SID/Name translation</title>
                              <description>todo - description needed</description>
                              <value>False</value>
                              <value selector="False">False</value>
                              <value selector="True">True</value>
                        </Value>
                        <Value id="do-not-allow-anonymous-enumeration-sam_var" operator="equals" type="number">
                              <title>Network access: Do not allow anonymous enumeration of SAM accounts</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="do-not-allow-anonymous-enumeration-sam-accounts-shares_var" operator="equals" type="number">
                              <title>Network access: Do not allow anonymous enumeration of SAM accounts and shares</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="do-not-allow-storage-credentials-net-passports-network-authn_var" operator="equals" type="number">
                              <title>Network access: Do not allow storage of credentials or .NET Passports for network authentication</title>
                              <description>Network access: Do not allow storage of credentials or .NET Passports for network authentication</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="let-everyone-permissions-apply-to-anonymous-users_var" operator="equals" type="number">
                              <title>Network access: Let Everyone permissions apply to anonymous users</title>
                              <description>Network access: Let Everyone permissions apply to anonymous users</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <!-- named-pipes-accessed-anonymously -->
                        <!-- Network access: Remotely accessible registry paths -->
                        <!-- Remotely-accessible-registry-paths-and-sub-paths -->
                        <Value id="Restrict-anonymous-access-to-Named-Pipes-and-Shares_var" operator="equals" type="number">
                              <title>Network access: Restrict anonymous access to Named Pipes and Shares</title>
                              <description>Network access: Restrict anonymous access to Named Pipes and Shares</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <!-- Shares-that-can-be-accessed-anonymously -->
                        <Value id="Sharing-and-security-model-for-local-accounts_var" operator="equals" type="number">
                              <title>Network access: Sharing and security model for local accounts</title>
                              <description>Network access: Sharing and security model for local accounts</description>
                              <value>0</value>
                              <value selector="classic">0</value>
                              <value selector="guests_only">1</value>
                        </Value>
                        <Value id="Do-not-store-LAN-Manager-hash-value-on-next-password-change_var" operator="equals" type="string">
                              <title>Network security: Do not store LAN Manager hash value on next password change</title>
                              <description>Network security: Do not store LAN Manager hash value on next password change</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Force-logoff-when-logon-hours-expire_var" operator="equals" type="number">
                              <title>Network security: Force logoff when logon hours expire</title>
                              <description>Network security: Force logoff when logon hours expire</description>
                              <value>0</value>
                              <value selector="enabled">0</value>
                              <value selector="disabled">1</value>
                        </Value>
                        <Value id="Lan-manager-authentication-level_var" operator="greater than or equal" type="number">
                              <title>Network Security: LAN Manager Authentication Level</title>
                              <description>Network Security: LAN Manager Authentication Level</description>
                              <value>3</value>
                              <value selector="send_LM_and_NTLM_responses">0</value>
                              <value selector="send_LM_and_NTLM_use_NTLMv2_session_security_if_negotiated">1</value>
                              <value selector="send_NTLM_response_only">2</value>
                              <value selector="send_NTLMv2_response_only">3</value>
                              <value selector="send_NTLMv2_response_only_refuse_LM">4</value>
                              <value selector="send_NTLMv2_response_only_refuse_LM_and_NTLM">5</value>
                        </Value>
                        <Value id="LDAP-client-signing-requirements_var" operator="equals" type="number">
                              <title>Network Security: LDAP client signing requirements</title>
                              <description>Network Security: LDAP client signing requirements</description>
                              <value>1</value>
                              <value selector="none">0</value>
                              <value selector="negotiate_signing">1</value>
                              <value selector="require_signing">2</value>
                        </Value>
                        <Value id="minimum-session-security-ntlm-ssp-based-clients_var" operator="equals" type="number">
                              <title>Network Security: Minimum session security for NTLM SSP based (including secure RPC) clients</title>
                              <description>Network Security: Minimum session security for NTLM SSP based (including secure RPC) clients</description>
                              <value>537395200</value>
                              <value selector="require_NTLMv2_and_require_128_bit_encryption">537395200</value>
                        </Value>
                        <Value id="minimum-session-security-ntlm-ssp-based-servers_var" operator="equals" type="number">
                              <title>Network Security: Minimum session security for NTLM SSP based (including secure RPC) servers</title>
                              <description>Network Security: Minimum session security for NTLM SSP based (including secure RPC) servers</description>
                              <value>537395200</value>
                              <value selector="require_NTLMv2_and_require_128_bit_encryption">537395200</value>
                        </Value>
                        <Value id="recovery-console-allow-administrative-logon_var" operator="equals" type="number">
                              <title>Recovery Console: Allow Automatic Administrative Logon</title>
                              <description>Recovery Console: Allow Automatic Administrative Logon</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="recovery-console-allow-floppy-copy-access-all-drives-folders_var" operator="equals" type="number">
                              <title>Recovery Console: Allow Floppy Copy and Access to All Drives and All Folders</title>
                              <description>Recovery Console: Allow Floppy Copy and Access to All Drives and All Folders</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="shutdown-allow-system-shutdown-without-having-logon_var" operator="equals" type="number">
                              <title>Shutdown: Allow System to be Shut Down Without Having to Log On</title>
                              <description>Shutdown: Allow System to be Shut Down Without Having to Log On</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="shutdown-clear-virtual-memory-page_var" operator="equals" type="number">
                              <title>Shutdown: Clear Virtual Memory Pagefile</title>
                              <description>Shutdown: Clear Virtual Memory Pagefile</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="system-cryptography-use-fips-compliant-alorithm_var" operator="equals" type="number">
                              <title>System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing</title>
                              <description>System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="system-objects-require-case-insesitivity_var" operator="equals" type="number">
                              <title>System objects: Require case insensitivity for non-Windows subsystems</title>
                              <description>System objects: Require case insensitivity for non-Windows subsystems</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="system-objects-strengthen-default-permissions-internal-system-objects_var" operator="equals" type="number">
                              <title>System objects: Strengthen default permissions of internal system objects</title>
                              <description>System objects: Strengthen default permissions of internal system objects</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="AdministratorAccountStatus" selected="false" weight="10.0">
                              <title>Accounts: Administrator account status</title>
                              <description>The Administrator account status is enabled to allow the administrator to perform configuration control of the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3032-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-499</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AdministratorAccountStatus_var" export-name="oval:gov.nist.fdcc.vista:var:50"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:242"/>
                              </check>
                        </Rule>
                        <Rule id="guest-account-status" selected="false" weight="10.0">
                              <title>Accounts: Guest account status</title>
                              <description>A system faces an increased vulnerability threat if the built-in guest account is not disabled. This account is a known account that exists on all Windows systems and cannot be deleted. This account is initialized during the installation of the operating system with no password assigned. This account is a member of the Everyone user group and has all the rights and permissions associated with that group, which could subsequently provide access to system resources to anonymous users. Ensure the built-in guest account is disabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3248-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-332</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60201" value-id="guest-account-status_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6020"/>
                              </check>
                        </Rule>
                        <Rule id="limit-blank-password-use" selected="false" weight="10.0">
                              <title>Accounts: Limit local account use to blank passwords to console logon only</title>
                              <description>In Windows Vista, accounts with null or blank passwords can only be used to log on at the physical system’s logon screen. This means that accounts with blank or null passwords cannot be used over networks or with the secondary logon service (RunAs). This feature prevents attackers and malware from gaining remote access through blank passwords. Section 6 contains information on other recommended password settings.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2398-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-533</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60211" value-id="limit-blank-password-use_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6021"/>
                              </check>
                        </Rule>
                        <Rule id="rename-administrator" selected="false" weight="10.0">
                              <title>Accounts: Rename administrator account</title>
                              <description>The Administrator account is created by default when installing Windows Vista, but is disabled. Associating the Administrator SID with a different name may thwart a potential hacker who is targeting the built-in Administrator account.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2714-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-438</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6022"/>
                              </check>
                        </Rule>
                        <Rule id="rename-guest" selected="false" weight="10.0">
                              <title>Accounts: Rename guest account</title>
                              <description>The Guest account is created by default when installing Windows Vista, but is disabled. Associating the Guest SID with a different name may thwart a potential hacker who is targeting the built-in Guest account.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2359-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-834</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6023"/>
                              </check>
                        </Rule>
                        <Rule id="audit-access-global-system-objects" selected="false" weight="10.0">
                              <title>Audit: Audit the access of global system objects</title>
                              <description>Controls the ability to audit access of global systems objects. When this setting is enabled, system objects such as mutexes, events, semaphores, and DOS devices, are created with a default system access control list (SACL).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3285-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60241" value-id="audit-access-global-system-objects_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6024"/>
                              </check>
                        </Rule>
                        <Rule id="audit-use-backup-restore-privilege" selected="false" weight="10.0">
                              <title>Audit: Audit the use of Backup and Restore privilege</title>
                              <description>Controls the ability to audit the use of all user privileges, including Backup and Restore. If this policy is disabled, certain user rights will not be audited even if "Audit privilege use" audit policy is enabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3303-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-905</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60251" value-id="audit-use-backup-restore-privilege_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6025"/>
                              </check>
                        </Rule>
                        <Rule id="override-audit-policy-settings" selected="false" weight="10.0">
                              <title>Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings</title>
                              <description>Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3450-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-111</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60261" value-id="override-audit-policy-settings_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6026"/>
                              </check>
                        </Rule>
                        <Rule id="shutdown-system-unable-log-audits" selected="false" weight="10.0">
                              <title>Audit: Shut down system immediately if unable to log security audits</title>
                              <description>If events cannot be written to the security log, the system is halted immediately. If the system halts as a result of a full log, an administrator must log ont the system and clear the log.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3001-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-92</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60271" value-id="shutdown-system-unable-log-audits_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6027"/>
                              </check>
                        </Rule>
                        <Rule id="allow-format-eject-removable-media" selected="false" weight="10.0">
                              <title>Devices: Allowed to format and eject removable media</title>
                              <description>Verifies that only the correct users are allowed to format and eject removable media&gt;</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3225-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-919</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60291" value-id="allow-format-eject-removable-media_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6029"/>
                              </check>
                        </Rule>
                        <Rule id="prevent-users-installing-printers" selected="false" weight="10.0">
                              <title>Devices: Prevent users from installing printer drivers</title>
                              <description>This setting determines who is allowed to install a printer driver as part of adding a network printer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3325-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-402</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60301" value-id="prevent-users-installing-printers_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6030"/>
                              </check>
                        </Rule>
                        <Rule id="restrict-cdrom-access-local-users-only" selected="false" weight="10.0">
                              <title>Devices: Restrict CD-ROM access to locally logged-on user only</title>
                              <description>Removable media devices (CD-ROM) are readable by others on the network if they are not properly configured. A process can remain running in the background after a user logs off, thereby, permitting access to the media, while another user is logged on to the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2858-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-565</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60311" value-id="restrict-cdrom-access-local-users-only_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6031"/>
                              </check>
                        </Rule>
                        <Rule id="restrict-floppy-access-local-users-only" selected="false" weight="10.0">
                              <title>Devices: Restrict floppy access to locally logged-on user only</title>
                              <description>Removable media devices (floppy disks) are readable by others on the network if they are not properly configured. A process can remain running in the background after a user logs off, thereby, permitting access to the media, while another user is logged on to the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3168-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-463</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60321" value-id="restrict-floppy-access-local-users-only_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6032"/>
                              </check>
                        </Rule>
                        <Rule id="digitally-encrypt-or-sign-secure-channel-data-always" selected="false" weight="10.0">
                              <title>Domain member: Digitally encrypt or sign secure channel data (always)</title>
                              <description>Domain member: Digitally encrypt or sign secure channel data (always). Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted or signed. If this policy is enabled, outgoing secure channel traffic should be encrypted.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3330-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-549</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60341" value-id="digitally-encrypt-or-sign-secure-channel-data-always_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6034"/>
                              </check>
                        </Rule>
                        <Rule id="digitally-encrypt-secure-channel-data-when-possible" selected="false" weight="10.0">
                              <title>Domain member: Digitally encrypt secure channel data (when possible)</title>
                              <description>Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but not all information is encrypted. If this policy is enabled, outgoing secure channel traffic should be encrypted.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2467-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-161</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60331" value-id="digitally-encrypt-secure-channel-data-when-possible_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6033"/>
                              </check>
                        </Rule>
                        <Rule id="digitally-sign-secure-channel-data-when-possible" selected="false" weight="10.0">
                              <title>Domain member: Digitally sign secure channel data (when possible)</title>
                              <description>Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but the channel is not integrity checked. If this policy is enabled, all outgoing secure channel traffic should be signed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3233-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-918</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60351" value-id="digitally-sign-secure-channel-data-when-possible_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6035"/>
                              </check>
                        </Rule>
                        <Rule id="disable-machine-account-password-changes" selected="false" weight="10.0">
                              <title>Domain member: Disable machine account password changes</title>
                              <description>Computer account passwords are changed automatically every seven days. Enabling this policy to disable automatic password changes can make the system more vulnerable to malicious access. Frequent password changes can be a significant safeguard for your system. If this policy is disabled, a new password for the computer account will be generated every week.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3255-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-831</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60361" value-id="disable-machine-account-password-changes_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6036"/>
                              </check>
                        </Rule>
                        <Rule id="maximum_machine-account-password-age" selected="false" weight="10.0">
                              <title>Domain member: Maximum machine account password age</title>
                              <description>This setting controls the maximum password age that a machine account may have. This setting should be set to no more that 30 days, ensuring that the machine changes its password monthly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3075-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-194</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60371" value-id="maximum_machine-account-password-age_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6037"/>
                              </check>
                        </Rule>
                        <Rule id="require-strong-session-key" selected="false" weight="10.0">
                              <title>Domain member: Require strong session key</title>
                              <description>This setting controls the required strength of a session key.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3212-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-417</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60381" value-id="require-strong-session-key_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6038"/>
                              </check>
                        </Rule>
                        <Rule id="do-not-display-last-user-name" selected="false" weight="10.0">
                              <title>Interactive logon: Do not display last user name</title>
                              <description>This setting determines whether the name of the last user to log on to the computer will be displayed in the Windows logon dialog box.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3173-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-65</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60391" value-id="do-not-display-last-user-name_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6039"/>
                              </check>
                        </Rule>
                        <Rule id="do-not-require-ctrlaltdel" selected="false" weight="10.0">
                              <title>Interactive logon: Do not require CTRL+ALT+DEL</title>
                              <description>Disabling the Ctrl+Alt+Del security attention sequence can compromise system security. Because only Windows responds to the Ctrl+Alt+Del security sequence, you can be assured that any passwords you enter following that sequence are sent only to Windows. If you eliminate the sequence requirement, malicious programs can request and receive your Windows password. Disabling this sequence also suppresses a custom logon banner.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3307-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-133</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60401" value-id="do-not-require-ctrlaltdel_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6040"/>
                              </check>
                        </Rule>
                        <Rule id="message-text-users-attempting-logon" selected="false" weight="10.0">
                              <title>Interactive logon: Message text for users attempting to log on</title>
                              <description>Failure to display the logon banner prior to a logon attempt will negate legal proceedings resulting from unauthorized access to system resources.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-8"/>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3336-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-829</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60411" value-id="message-text-users-attempting-logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6041"/>
                              </check>
                        </Rule>
                        <Rule id="message-title-users-attempting-logon" selected="false" weight="10.0">
                              <title>Interactive logon: Message title for users attempting to log on</title>
                              <description>The logon banner should be titled with a warning label containing the name of the owning organization.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-8"/>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3314-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-23</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60421" value-id="message-title-users-attempting-logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6042"/>
                              </check>
                        </Rule>
                        <Rule id="number-of-previous-logons-to-cache" selected="false" weight="10.0">
                              <title>Interactive logon: Number of previous logons to cache (in case domain controller is not available)</title>
                              <description>The default Windows XP configuration caches the last logon credentials for users who log on interactively to a system. This feature is provided for system availability reasons such as the users machine is disconnected from the network or domain controllers are not available. Even though the credential cache is well-protected, storing encrypted copies of users passwords on workstations do not always have the same physical protection required for domain controllers. If a workstation is attacked, the unauthorized individual may isolate the password to a domain user account using a password-cracking program, and gain access to the domain.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2376-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-773</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60431" value-id="number-of-previous-logons-to-cache_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6043"/>
                              </check>
                        </Rule>
                        <Rule id="prompt-user-to-change-password-before-expiration" selected="false" weight="10.0">
                              <title>Interactive logon: Prompt user to change password before expiration</title>
                              <description>This setting configures the system to display a warning to users telling them how many days are left before their password expires. By giving the user advanced warning, the user has time to construct a sufficiently strong password.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3230-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-814</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60441" value-id="prompt-user-to-change-password-before-expiration_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6044"/>
                              </check>
                        </Rule>
                        <Rule id="require-domain-controller-authentication-to-unlock" selected="false" weight="10.0">
                              <title>Interactive logon: Require Domain Controller authentication to unlock workstation</title>
                              <description>This setting controls the behavior of the system when you attempt to unlock the workstation. If this setting is enabled, the system will pass the credentials to the domain controller (if in a domain) for authentication before allowing the system to be unlocked.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3220-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-374</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60451" value-id="require-domain-controller-authentication-to-unlock_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6045"/>
                              </check>
                        </Rule>
                        <Rule id="smart-card-removal-behaviour" selected="false" weight="10.0">
                              <title>Interactive logon: Smart card removal behavior</title>
                              <description>When the smart card for a logged-on user is removed from the smart card reader, the workstation should be locked.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3251-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-443</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60461" value-id="smart-card-removal-behaviour_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6046"/>
                              </check>
                        </Rule>
                        <Rule id="digitally-sign-communications-client-always" selected="false" weight="10.0">
                              <title>Microsoft network client: Digitally sign communications (always)</title>
                              <description>This check verifies that the client policy is set to always sign packets.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3252-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-576</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60471" value-id="digitally-sign-communications-client-always_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6047"/>
                              </check>
                        </Rule>
                        <Rule id="digitally-sign-communications-client-server-agrees" selected="false" weight="10.0">
                              <title>Microsoft network client: Digitally sign communications (if server agrees)</title>
                              <description>This check verifies that the client policy is set to sign packets if the server agrees.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2380-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-519</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60481" value-id="digitally-sign-communications-client-server-agrees_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6048"/>
                              </check>
                        </Rule>
                        <Rule id="send-unencrypted-password-to-third-party-smb-servers" selected="false" weight="10.0">
                              <title>Microsoft network client: Send unencrypted password to third-party SMB servers</title>
                              <description>Some non-Microsoft SMB servers only support unencrypted (plain text) password authentication. Sending plain text passwords across the network, when authenticating to an SMB server, reduces the overall security of the environment. Check with the Vendor of the SMB server to see if there is a way to support encrypted password authentication.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2838-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-228</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60491" value-id="send-unencrypted-password-to-third-party-smb-servers_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6049"/>
                              </check>
                        </Rule>
                        <Rule id="amount-of-idle-time-required-before-suspending-session" selected="false" weight="10.0">
                              <title>Microsoft network server: Amount of idle time required before suspending session</title>
                              <description>Administrators should use this setting to control when a computer disconnects an inactive SMB session. If client activity resumes, the session is automatically reestablished.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2519-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-222</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60501" value-id="amount-of-idle-time-required-before-suspending-session_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6050"/>
                              </check>
                        </Rule>
                        <Rule id="digitally-sign-communications-server-always" selected="false" weight="10.0">
                              <title>Microsoft network server: Digitally sign communications (always)</title>
                              <description>This check verifies that the server policy is set to always sign packets.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3023-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-171</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60511" value-id="digitally-sign-communications-server-always_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6051"/>
                              </check>
                        </Rule>
                        <Rule id="digitally-sign-communications-server-client-agrees" selected="false" weight="10.0">
                              <title>Microsoft network server: Digitally sign communications (if client agrees)</title>
                              <description>Microsoft network server: Digitally sign communications (if client agrees). This check verifies that the server policy is set to sign packets if the client agrees.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3164-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-104</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60521" value-id="digitally-sign-communications-server-client-agrees_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6052"/>
                              </check>
                        </Rule>
                        <Rule id="disconnect-client-when-logon-hours-expire" selected="false" weight="10.0">
                              <title>Microsoft network server: Disconnect clients when logon hours expire</title>
                              <description>Users should not be permitted to remain logged on to the network after they have exceeded their permitted logon hours. In many cases, this indicates that a user forgot to log off before leaving for the day. However, it may also indicate that a user is attempting unauthorized access at a time when the system may be less closely monitored.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3361-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-278</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60531" value-id="disconnect-client-when-logon-hours-expire_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6053"/>
                              </check>
                        </Rule>
                        <Rule id="enable-automatic-logon" selected="false" weight="10.0">
                              <title>MSS: (AutoAdminLogon) Enable Automatic Logon (Not Recommended)</title>
                              <description>Determines whether the automatic logon feature is enabled. Automatic logon uses the domain, user name, and password stored in the registry to log users on to the computer when the system starts. The Log On to Windows dialog box is not displayed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3072-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-283</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60541" value-id="enable-automatic-logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6054"/>
                              </check>
                        </Rule>
                        <Rule id="disable-ip-source-routing" selected="false" weight="10.0">
                              <title>MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)</title>
                              <description>MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3261-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-564</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60551" value-id="disable-ip-source-routing_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6055"/>
                              </check>
                        </Rule>
                        <Rule id="enable-dead-gw-detect" selected="false" weight="10.0">
                              <title>MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)</title>
                              <description>MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3120-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-897</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60561" value-id="enable-dead-gw-detect_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6056"/>
                              </check>
                        </Rule>
                        <Rule id="enable-icmp-redirect" selected="false" weight="10.0">
                              <title>MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes</title>
                              <description>MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3239-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-150</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60571" value-id="enable-icmp-redirect_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6057"/>
                              </check>
                        </Rule>
                        <Rule id="keep-alive-time" selected="false" weight="10.0">
                              <title>MSS: (KeepAliveTime)How often keep-alive packets are sent in milliseconds</title>
                              <description>This value controls how often TCP attempts to verify that an idle connection is still intact by sending a keep-alive packet. If the remote computer is still reachable, it acknowledges the keep-alive packet. HKLM\System\CurrentControlSet\Tcpip\Parameters\KeepAliveTime</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3142-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-188</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60591" value-id="keep-alive-time_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6059"/>
                              </check>
                        </Rule>
                        <Rule id="enable-nodefaultexempt-IPSec-Filtering" selected="false" weight="10.0">
                              <title>MSS: (NoDefaultExempt) Enable NoDefaultExempt for IPSec Filtering (recommended)</title>
                              <description>MSS: (NoDefaultExempt) Enable NoDefaultExempt for IPSec Filtering</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4904-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-501</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:116"/>
                              </check>
                        </Rule>
                        <Rule id="no-drive-type-auto-run" selected="false" weight="10.0">
                              <title>MSS: (NoDriveTypeAutoRun) Disable Autorun for all drives (recommended)</title>
                              <description>Disable Autorun on all drives, any pluggable device included (not just CDs) Affects registry key: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2719-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-44</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6574"/>
                              </check>
                        </Rule>
                        <Rule id="no-name-release-on-demand" selected="false" weight="10.0">
                              <title>MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers</title>
                              <description>Network basic input/output system (NetBIOS) over TCP/IP is a networking protocol that, among other things, provides a means of easily resolving NetBIOS names registered on Windows- based systems to the IP addresses configured on those systems. This value determines whether the computer releases its NetBIOS name when it receives a name release request. The NoNameReleaseOnDemand setting configures the system to refuse name release requests to release its SMB name. This setting prevents an attacker from sending a name release request to a server, causing the server to be inaccessible to legitimate clients. If this setting is configured on a client, however, and that client is mis-configured with the same name as a critical server, the server will be unable to recover the name, and legitimate requests may be directed to the rogue server instead, causing a denial of service condition at best.
                                    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netbt\Parameters\ NoNameReleaseOnDemand registry key.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2785-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-817</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60611" value-id="no-name-release-on-demand_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6061"/>
                              </check>
                        </Rule>
                        <Rule id="ntfs-disable-8dot3-name-creation" selected="false" weight="10.0">
                              <title>MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames (recommended)</title>
                              <description>Vista supports 8.3 file name formats for backward compatibility with 16- bit applications. The 8.3 file name convention is a naming format that allows file names that are up to eight characters in length. The following registry value entry has been added to the template in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem\ NtfsDisable8dotNameCreation registry key. </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3244-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-511</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60621" value-id="ntfs-disable-8dot3-name-creation_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6062"/>
                              </check>
                        </Rule>
                        <Rule id="perform-router-discovery" selected="false" weight="10.0">
                              <title>MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)</title>
                              <description>This setting is used to enable or disabled the Internet Router Discovery Protocol (IRDP). IRDP allows the system to detect and configure Default Gateway addresses automatically. HKLM\System\CurrentControlSet\Tcpip\Parameters\PerformRouterDiscovery</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3279-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-952</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60631" value-id="perform-router-discovery_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6063"/>
                              </check>
                        </Rule>
                        <Rule id="safe-dll-search-mode" selected="false" weight="10.0">
                              <title>MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)</title>
                              <description>Most programs on the Windows platform make use of various Dynamic Link Libraries (DLL) to avoid having to reimplement functionality. The operating system actually loads several DLLs for each program, depending on what type of program it is. When the program does not specify an absolute location for a DLL, the default search order is used to locate it. By default, the search order used by the operating system is as follows: 1. Memory 2. KnownDLLs 3. Manifests and .local 4. Application directory 5. Current working directory 6. System directories (%systemroot%, %systemroot%\system, and %systemroot%\system32) 7. The path variable The fact that the current working directory is searched before the system directories can be used by someone with access to the file system to cause a program launched by a user to load a spoofed DLL. If a user launches a program by double-clicking a document, the current working directory is actually the location of the
                                    document. If a DLL in that directory has the same name as a system DLL in that location will then be loaded instead of the system DLL. This attack vector was actually used by the Nimda virus. To combat this, a new setting was created in Service Pack 3, which moves the current working directory to after the system directories in the search order. To avoid application compatibility issues, however, this switch was not turned on by default. To turn it on, set the following registry valueMACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SafeDllSearchMode</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3199-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-271</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60641" value-id="safe-dll-search-mode_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6064"/>
                              </check>
                        </Rule>
                        <Rule id="screen-saver-grace-period" selected="false" weight="10.0">
                              <title>MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)</title>
                              <description>Setting Added to Registry to Make Screensaver Password Protection Immediate The default grace period allowed for user movement before the screen – saver lock takes effect is five seconds. Leaving the grace period in the default setting makes your computer vulnerable to a potential attack from someone walking up to the console to attempt to log onto the system before the lock takes effect. An entry to the registry can be made to adjust the length of the grace period.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3050-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-830</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60651" value-id="screen-saver-grace-period_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6065"/>
                              </check>
                        </Rule>
                        <Rule id="syn-attack-protect" selected="false" weight="10.0">
                              <title>MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)</title>
                              <description>This registry value causes TCP to adjust retransmission of SYN- ACKs. When you configure this value, the connection responses time- out more quickly in the event of a connect request (SYN) attack. 1 = Connections timeout more quickly if a SYN attack is detected 0 = No additional protection, use default settings Note: W2K had another option = 2 that has been incorporated into option 1 in W2K3. HKLM\System\CurrentControlSet\Tcpip\Parameters\SynAttackProtect</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2679-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-284</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60661" value-id="syn-attack-protect_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6066"/>
                              </check>
                        </Rule>
                        <Rule id="tcp-max-connect-response-retransmissions" selected="false" weight="10.0">
                              <title>MSS: (TCPMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged</title>
                              <description>This parameter determines the number of times that TCP retransmits a SYN before aborting the attempt. The retransmission time-out is doubled with each successive retransmission in a given connect attempt. The initial time-out value is three seconds. 0 = No retransmission, half- open connections dropped after 3 seconds 1 = 3 seconds, half- open connections dropped after 9 seconds 2 = 3 and 6 seconds, half- open connections dropped after 21 seconds 3 = 3, 6, and 9 seconds, half- open connections dropped after 45 seconds HKLM\System\CurrentControlSet\Tcpip\Parameters\TcpMaxConnectResponseRetransmissions</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3459-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-577</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60671" value-id="tcp-max-connect-response-retransmissions_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6067"/>
                              </check>
                        </Rule>
                        <Rule id="tcp-max-data-retransmissions" selected="false" weight="10.0">
                              <title>MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)</title>
                              <description>MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3460-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-872</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60681" value-id="tcp-max-data-retransmissions_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6068"/>
                              </check>
                        </Rule>
                        <Rule id="warning-level" selected="false" weight="10.0">
                              <title>MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning</title>
                              <description>Windows Server 2003 and Service Pack 3 for Windows 2000 include a new feature for generating a security audit in the security event log when the security log reaches a user defined threshold. Note: new to W2K3 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\WarningLevel</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3181-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-125</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60691" value-id="warning-level_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6069"/>
                              </check>
                        </Rule>
                        <Rule id="anonymous_sid_name_translation" selected="false" weight="10.0" role="unchecked">
                              <title>Network access: Allow anonymous SID-Name translation</title>
                              <description>Determines if an anonymous user can request security identifier (SID) attributes for another user or use a SID to get the corresponding username.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2339-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-953</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:7777" value-id="anonymous_sid_name_translation_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6106"/>
                              </check>
                        </Rule>
                        <Rule id="do-not-allow-anonymous-enumeration-sam" selected="false" weight="10.0">
                              <title>Network access: Do not allow anonymous enumeration of SAM accounts</title>
                              <description>If this setting is disabled, it allows anonymous logon users (null session connections) to list all account names, thus providing a map of potential points to attack the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3272-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-318</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60701" value-id="do-not-allow-anonymous-enumeration-sam_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6070"/>
                              </check>
                        </Rule>
                        <Rule id="do-not-allow-anonymous-enumeration-sam-accounts-shares" selected="false" weight="10.0">
                              <title>Network access: Do not allow anonymous enumeration of SAM accounts and shares</title>
                              <description>If this setting is disabled, it allows anonymous logon users (null session connections) to list all account names and enumerate all shared resources, thus providing a map of potential points to attack the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3232-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-195</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60711" value-id="do-not-allow-anonymous-enumeration-sam-accounts-shares_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6071"/>
                              </check>
                        </Rule>
                        <Rule id="do-not-allow-storage-credentials-net-passports-network-authn" selected="false" weight="10.0">
                              <title>Network access: Do not allow storage of credentials or .NET Passports for network authentication</title>
                              <description>This setting controls the storage of authentication credentials or .NET passports on the local system. Such credentials should never be stored on the local machine as that may lead to account compromise.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3379-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-542</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60721" value-id="do-not-allow-storage-credentials-net-passports-network-authn_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6072"/>
                              </check>
                        </Rule>
                        <Rule id="let-everyone-permissions-apply-to-anonymous-users" selected="false" weight="10.0">
                              <title>Network access: Let Everyone permissions apply to anonymous users</title>
                              <description>This setting helps define the permissions that anonymous users have. If this setting is enabled then anonymous users have the same rights and permissions as the built-in Everyone group. Anonymous users should not have these permissions or rights.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2457-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-18</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:60731" value-id="let-everyone-permissions-apply-to-anonymous-users_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6073"/>
                              </check>
                        </Rule>
                        <Rule id="named-pipes-accessed-anonymously" selected="false" weight="10.0">
                              <title>Network access: Named Pipes that can be accessed anonymously - netlogon, lsarpc, samr, browser</title>
                              <description>Network access: Named Pipes that can be accessed anonymously. Pipes are internal system communications processes. They are identified internally by ID numbers that vary between systems. To make access to these processes easier, these pipes are given names that do not vary between systems. This setting controls which of these pipes anonymous users may access.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3380-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-136</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6074"/>
                              </check>
                        </Rule>
                        <Rule id="Remotely-accessible-registry-paths" selected="false" weight="10.0">
                              <title>Network access: Remotely accessible registry paths(System\CurrentControlSet\Control\ProductOptions; System\CurrentControlSet\Control\Server Applications; Software\Microsoft\Windows NT\CurrentVersion)</title>
                              <description>Network access: Remotely accessible registry paths(System\CurrentControlSet\Control\ProductOptions; System\CurrentControlSet\Control\Server Applications; Software\Microsoft\Windows NT\CurrentVersion)</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2825-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-189</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6075"/>
                              </check>
                        </Rule>
                        <Rule id="Remotely-accessible-registry-paths-and-sub-paths" selected="false" weight="10.0">
                              <title>Network access: Remotely accessible registry paths and sub paths ("Software\Microsoft\Windows NT\CurrentVersion\Print, Software\Microsoft\Windows NT\CurrentVersion\Windows, System\CurrentControlSet\Control\Print\Printers, System\CurrentControlSet\Services\Eventlog, Software\Microsoft\OLAP Server, System\CurrentControlSet\Control\ContentIndex, System\CurrentControlSet\Control\Terminal Server, System\CurrentControlSet\Control\Terminal Server\UserConfig, System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration, Software\Microsoft\Windows NT\CurrentVersion\Perflib, System\CurrentControlSet\Services\SysmonLog")</title>
                              <description>Network access: Remotely accessible registry paths ("Software\Microsoft\Windows NT\CurrentVersion\Print, Software\Microsoft\Windows NT\CurrentVersion\Windows, System\CurrentControlSet\Control\Print\Printers, System\CurrentControlSet\Services\Eventlog, Software\Microsoft\OLAP Server, System\CurrentControlSet\Control\ContentIndex, System\CurrentControlSet\Control\Terminal Server, System\CurrentControlSet\Control\Terminal Server\UserConfig, System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration, Software\Microsoft\Windows NT\CurrentVersion\Perflib, System\CurrentControlSet\Services\SysmonLog")</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4781-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1185</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6076"/>
                              </check>
                        </Rule>
                        <Rule id="Restrict-anonymous-access-to-Named-Pipes-and-Shares" selected="false" weight="10.0">
                              <title>Network access: Restrict anonymous access to Named Pipes and Shares</title>
                              <description>This check determines whether anonymous access is restricted to named pipes and shares.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3292-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-638</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6077" value-id="Restrict-anonymous-access-to-Named-Pipes-and-Shares_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6077"/>
                              </check>
                        </Rule>
                        <Rule id="Shares-that-can-be-accessed-anonymously" selected="false" weight="10.0">
                              <title>Network access: Shares that can be accessed anonymously</title>
                              <description>This setting controls which network shares may be accessed by an anonymous user. The default setting includes the shares, DFS$, and COMCFG. It is recommended that they be left as the default setting.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3349-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-942</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:60771"/>
                              </check>
                        </Rule>
                        <Rule id="Sharing-and-security-model-for-local-accounts" selected="false" weight="10.0">
                              <title>Network access: Sharing and security model for local accounts</title>
                              <description>Windows XP includes two network-sharing security models Classic and Guest only. It is recommended that the Classic mode be used.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3367-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-343</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6079" value-id="Sharing-and-security-model-for-local-accounts_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6079"/>
                              </check>
                        </Rule>
                        <Rule id="Do-not-store-LAN-Manager-hash-value-on-next-password-change" selected="false" weight="10.0">
                              <title>Network security: Do not store LAN Manager hash value on next password change</title>
                              <description>This setting controls whether or not a LAN Manager hash of the password is stored in the SAM the next time the password is changed. The LAN Manager hash is a weak encryption algorithm and there are several tools available that use this hash to retrieve account passwords.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3138-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-233</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6080" value-id="Do-not-store-LAN-Manager-hash-value-on-next-password-change_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6080"/>
                              </check>
                        </Rule>
                        <Rule id="Force-logoff-when-logon-hours-expire" selected="false" weight="10.0">
                              <title>Network security: Force logoff when logon hours expire</title>
                              <description>This setting controls whether or not users are forced to log off when their allowed logon hours expire. If logon hours are set for users, then this should be enforced.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3283-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-775</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6081" value-id="Force-logoff-when-logon-hours-expire_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6081"/>
                              </check>
                        </Rule>
                        <Rule id="Lan-manager-authentication-level" selected="false" weight="10.0">
                              <title>Network Security: LAN Manager Authentication Level</title>
                              <description>Windows network authentication has changed considerably as various security vulnerabilities have been identified and fixed. The original LAN Manager (or LM) password hash is considered very weak, but is still used by most Windows 9x clients. Using commercially available software, and off-the-shelf computers, most LM password hashes can be used to reveal the actual password in a matter of days, or hours. With the release of Windows NT 4.0, Microsoft developed NTLM authentication. Serious vulnerabilities made NTLM almost as easy to crack as LM, so NTLM version 2 (NTLMv2) was introduced. NTLMv2 provides significant improvements to security; when combined with strong password policy, accounts are well protected against brute force attacks. All of these authentication methods are incorporated into Windows 2000. All authentication models work with a hash of the password, not the password itself. This presents challenges with down-level compatibility
                                    between operating systems. In order to smooth the transition, when one computer attempts to authenticate with another, the default behavior is to send the basic LM hash along with the more secure NTLM hash. This setting improves control over the response to an authentication challenge: Send LM and NTLM responses, Send LM and NTLM, Use NTLMv2 session security if negotiated, Send NTLM response only, Send NTLMv2 response only, Send NTLMv2 response only\refuse LM, Send NTLMv2 response only\refuse LM and NTLM, The default, and weakest option, is the first: send LM and NTLM responses. As a result, using NTLM is ineffective because both protocols are sent together. In order to take a much more effective stand to protect network authentication, set LAN Manager Authentication Level to Send NTLMv2 response only\refuse LM and NTLM. Enabling this setting may have adverse effects on your ability to communicate with other Windows machines unless the change is made
                                    network-wide. If you find that you are unable to require a certain level of LM Authentication, back down to “Send LM and NTLM – Use NTLMv2 session security if negotiated” and try your network authentication again. Communication with Windows 9x/Me machines requires the DSCLIENT.EXE utility from the Windows 2000 installation CD. </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4922-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-719</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:609411" value-id="Lan-manager-authentication-level_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6094"/>
                              </check>
                        </Rule>
                        <Rule id="LDAP-client-signing-requirements" selected="false" weight="10.0">
                              <title>Network Security: LDAP client signing requirements</title>
                              <description>Similar to the SMB protocol, the LDAP protocol supports signing. LDAP, “Lightweight Directory Access Protocol,” provides one means for the client to talk to active directory. LDAP protocol is text-based, but supports authentication to gain access to sensitive sections of the directory. Require signing to provide the assurance of mutual authentication for this communications channel.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4940-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-732</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:609511" value-id="LDAP-client-signing-requirements_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6095"/>
                              </check>
                        </Rule>
                        <Rule id="minimum-session-security-ntlm-ssp-based-clients" selected="false" weight="10.0">
                              <title>Network Security: Minimum session security for NTLM SSP based (including secure RPC) clients</title>
                              <description>NTLM authentication can provide a security service to manage connection between various clients and servers, including through the Remote Procedure Call (RPC) service. Windows 2000 improved the security model for secure, authenticated client-server communications; this setting manages the new features for communications established by this workstation.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4583-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-674</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:609611" value-id="minimum-session-security-ntlm-ssp-based-clients_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6096"/>
                              </check>
                        </Rule>
                        <Rule id="minimum-session-security-ntlm-ssp-based-servers" selected="false" weight="10.0">
                              <title>Network Security: Minimum session security for NTLM SSP based (including secure RPC) servers</title>
                              <description> Similar to "Network Security: Minimum session security for NTLM SSP based (including secure RPC) clients", this setting manages features for communication services provided by this workstation to other computers.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4213-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-766</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:609711" value-id="minimum-session-security-ntlm-ssp-based-servers_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6097"/>
                              </check>
                        </Rule>
                        <Rule id="recovery-console-allow-administrative-logon" selected="false" weight="10.0">
                              <title>Recovery Console: Allow Automatic Administrative Logon</title>
                              <description>The Recovery Console, new to Windows 2000 and XP, provides a limited command-line access to an otherwise unbootable operating system. The console allows access to the NTFS file system, which does not natively allow access when the operating system becomes unbootable. Other third-party applications have been developed to perform this action as well, but the Recovery Console is part of the operating system. It can be installed from the Windows 2000 CD with the “d:\i386\winnt32.exe /cmdcons” command. It can also be run directly from the Windows 2000 installation CD. The Recovery Console does not grant full and unrestricted access to the operating system by default. It does require that you log on using the password of the default Administrator account. Keep in mind that this must be the local administrator account, not just a member of the local administrators group. Also, the policy for renaming the administrator account does not apply to the
                                    recovery console, and that password must be used. If configured, a boot to the recovery console could result in automatic logon, and bypass the need for the password of the administrator account. Since this gives administrator access to anyone who can reboot the computer, the setting is generally disabled. </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4107-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-410</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:609811" value-id="recovery-console-allow-administrative-logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6098"/>
                              </check>
                        </Rule>
                        <Rule id="recovery-console-allow-floppy-copy-access-all-drives-folders" selected="false" weight="10.0">
                              <title>Recovery Console: Allow Floppy Copy and Access to All Drives and All Folders</title>
                              <description>By default, the Recovery Console only allows access to the root folder of each drive, and the operating system folder (typically C:\Windows). The console also prevents copying files from the hard drive onto removable media. Although this protection can be bypassed by enabling floppy copy and drive access, the setting is enabled by default and should remain disabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3953-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-76</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:609911" value-id="recovery-console-allow-floppy-copy-access-all-drives-folders_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6099"/>
                              </check>
                        </Rule>
                        <Rule id="shutdown-allow-system-shutdown-without-having-logon" selected="false" weight="10.0">
                              <title>Shutdown: Allow System to be Shut Down Without Having to Log On</title>
                              <description>Some systems run critical processes and should only be shut down by authorized users. Occasionally, special processes could be evoked during system startup, sometimes even trojaned processes. In environments where abnormal system reboots could cause problems, require a logon prior to reboot.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3954-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-224</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:610011" value-id="shutdown-allow-system-shutdown-without-having-logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6100"/>
                              </check>
                        </Rule>
                        <Rule id="shutdown-clear-virtual-memory-page" selected="false" weight="10.0">
                              <title>Shutdown: Clear Virtual Memory Pagefile</title>
                              <description>Virtual memory extends the physical memory available to the CPU. As data and applications fill the available physical memory, the operating system writes less-frequently used pages of memory out to disk, into the virtual memory pagefile. This greatly extends the amount of “virtual” memory available to the computer. Since the pagefile contains information that was in memory, it potentially holds a great deal of information useful for an attacker. Digging through the pagefile can reveal SSL web pages, queries set from the client to databases, sometimes even user ids and passwords from poorly written applications. The workstation does not clean this information from the pagefile on shutdown. Although the file can not be accessed when booted in Windows, anyone booting the workstation to an alternate operating system (e.g., from a boot CD) may access the page file. Enabling this options provides greater security by erasing the data during normal
                                    operations; however, this may also significantly increase the time required to shut down the computer. When enabled, the hibernation file (hiberfil.sys) is also cleaned on shutdown. </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3969-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-422</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:610111" value-id="shutdown-clear-virtual-memory-page_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6101"/>
                              </check>
                        </Rule>
                        <Rule id="system-cryptography-use-fips-compliant-alorithm" selected="false" weight="10.0">
                              <title>System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing</title>
                              <description>System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4774-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-55</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:610211" value-id="system-cryptography-use-fips-compliant-alorithm_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6102"/>
                              </check>
                        </Rule>
                        <Rule id="system-objects-require-case-insesitivity" selected="false" weight="10.0">
                              <title>System objects: Require case insensitivity for non-Windows subsystems</title>
                              <description>The Windows operating systems ignore case when accessing resources; for example, “C:\Windows”, “C:\WINDOWS” and “c:\windows” all refer to the same directory. However, the Windows kernel allows interfaces with other case-sensitive operating systems (e.g., Unix). Enabling this setting causes the interoperability features to be case-insensitive as well. This setting has no effect when the workstation communicates only with other Windows systems. </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4841-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-300</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:610411" value-id="system-objects-require-case-insesitivity_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6104"/>
                              </check>
                        </Rule>
                        <Rule id="system-objects-strengthen-default-permissions-internal-system-objects" selected="false" weight="10.0">
                              <title>System objects: Strengthen default permissions of internal system objects</title>
                              <description>This setting actually digs deep into the operating system behavior and should be left at the default setting (Enabled) unless explicitly required. “Internal system objects” are shared physical and logical resources such as semaphores and DOS device name; the objects all are created with access control lists (ACLs). When enabled, the ACL allows other non-administrative system processes to query internal system objects, but will not allow them to modify them.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4011-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-508</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:610511" value-id="system-objects-strengthen-default-permissions-internal-system-objects_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6105"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            User Account Control Settings            -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="user_account_control_settings">
                        <title>User Account Control</title>
                        <description>User Account Control (UAC) is a new security component in Windows Vista. UAC enables users to perform common tasks as non-administrators, called standard users in Windows Vista, and as administrators without having to switch users, log off, or use Run As. A standard user account is synonymous with a user account in Windows XP. User accounts that are members of the local Administrators group will run most applications as a standard user. By separating user and administrator functions while enabling productivity, UAC is an important enhancement for Windows Vista.</description>
                        <Value id="admin_approval_mode_var" operator="equals" type="number">
                              <title>Admin Approval Mode for the Built-in Administrator account</title>
                              <description>This security setting determines the behavior of Admin Approval Mode for the Built-in Administrator account.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="behavior_elevation_prompt_administrators_var" operator="equals" type="number">
                              <title>Behavior of the elevation prompt for administrators in Admin Approval Mode</title>
                              <description>This security setting determines the behavior of the elevation prompt for administrators.</description>
                              <value>0</value>
                              <value selector="elevate_without_prompting">0</value>
                              <value selector="prompt_for_credentials">1</value>
                              <value selector="prompt_for_consent">2</value>
                        </Value>
                        <Value id="behavior_elevation_prompt_standard_users_var" operator="equals" type="number">
                              <title>Behavior of the elevation prompt for standard users</title>
                              <description>This security setting determines the behavior of the elevation prompt for standard users.</description>
                              <value>0</value>
                              <value selector="automatically_deny">0</value>
                              <value selector="prompt_for_credentials">1</value>
                        </Value>
                        <Value id="detect_application_installations_prompt_elevation_var" operator="equals" type="number">
                              <title>Detect application installations and prompt for elevation</title>
                              <description>This security setting determines the behavior of application installation detection for the computer.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="only_elevate_executables_signed_validated_var" operator="equals" type="number">
                              <title>Only elevate executables that are signed and validated</title>
                              <description>This security setting will enforce public key infrastructure (PKI) signature checks on any interactive application that requests elevation of privilege. Enterprise administrators can control which administrative applications are allowed through the certificates in the local computer's Trusted Publishers certificate store.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="only_elevate_uiaccess_applications_var" operator="equals" type="number">
                              <title>Only elevate UIAccess applications that are installed in secure locations</title>
                              <description>This security setting will enforce the requirement that applications requesting to be run with a UIAccess integrity level must reside in a secure location on the file system.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="run_administrators_admin_approval_mode_var" operator="equals" type="number">
                              <title>Run all administrators in Admin Approval Mode</title>
                              <description>This security setting determines the behavior of all UAC policies for the entire system.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="switch_secure_desktop_prompting_elevation_var" operator="equals" type="number">
                              <title>Switch to the secure desktop when prompting for elevation</title>
                              <description>This security setting determines whether the elevation prompt appears on the interactive user's desktop or the secure desktop.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="virtualize_write_failures_per_user_locations_var" operator="equals" type="number">
                              <title>Virtualize file and registry write failures to per-user locations</title>
                              <description>This security setting enables the redirection of application write failures to defined locations in both the registry and file system. This feature mitigates those applications that historically ran as administrator and wrote runtime application data to protected locations (%ProgramFiles%, %Windir%, %Windir%\system32, or HKLM\Software\...). Virtualization facilitates the running of applications that historically failed to run as standard user because of application write failures.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="admin_approval_mode" selected="false" weight="10.0">
                              <title>Admin Approval Mode for the Built-in Administrator account</title>
                              <description>The "User Account Control: Admin Approval Mode for the Built-in Administrator account" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4955-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1078</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="admin_approval_mode_var" export-name="oval:gov.nist.fdcc.vista:var:8081"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8081"/>
                              </check>
                        </Rule>
                        <Rule id="behavior_elevation_prompt_administrators" selected="false" weight="10.0">
                              <title>Behavior of the elevation prompt for administrators in Admin Approval Mode</title>
                              <description>The "User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4016-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1063</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="behavior_elevation_prompt_administrators_var" export-name="oval:gov.nist.fdcc.vista:var:8082"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8082"/>
                              </check>
                        </Rule>
                        <Rule id="behavior_elevation_prompt_standard_users" selected="false" weight="10.0">
                              <title>Behavior of the elevation prompt for standard users</title>
                              <description>The "User Account Control: Behavior of the elevation prompt for standard users" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4969-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1067</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="behavior_elevation_prompt_standard_users_var" export-name="oval:gov.nist.fdcc.vista:var:8083"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8083"/>
                              </check>
                        </Rule>
                        <Rule id="detect_application_installations_prompt_elevation" selected="false" weight="10.0">
                              <title>Detect application installations and prompt for elevation</title>
                              <description>The "User Account Control: Detect application installations and prompt for elevation" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4612-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1128</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="detect_application_installations_prompt_elevation_var" export-name="oval:gov.nist.fdcc.vista:var:8084"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8084"/>
                              </check>
                        </Rule>
                        <Rule id="only_elevate_executables_signed_validated" selected="false" weight="10.0">
                              <title>Only elevate executables that are signed and validated</title>
                              <description>The "User Account Control: Only elevate executables that are signed and validated" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-5004-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1104</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="only_elevate_executables_signed_validated_var" export-name="oval:gov.nist.fdcc.vista:var:8085"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8085"/>
                              </check>
                        </Rule>
                        <Rule id="only_elevate_uiaccess_applications" selected="false" weight="10.0">
                              <title>Only elevate UIAccess applications that are installed in secure locations</title>
                              <description>The "User Account Control: Only elevate UIAccess applications that are installed in secure locations" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4020-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-986</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="only_elevate_uiaccess_applications_var" export-name="oval:gov.nist.fdcc.vista:var:8086"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8086"/>
                              </check>
                        </Rule>
                        <Rule id="run_administrators_admin_approval_mode" selected="false" weight="10.0">
                              <title>Run all administrators in Admin Approval Mode</title>
                              <description>The "User Account Control: Run all administrators in Admin Approval Mode" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4907-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1050</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="run_administrators_admin_approval_mode_var" export-name="oval:gov.nist.fdcc.vista:var:8087"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8087"/>
                              </check>
                        </Rule>
                        <Rule id="switch_secure_desktop_prompting_elevation" selected="false" weight="10.0">
                              <title>Switch to the secure desktop when prompting for elevation</title>
                              <description>The "User Account Control: Switch to the secure desktop when prompting for elevation" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4925-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-230</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="switch_secure_desktop_prompting_elevation_var" export-name="oval:gov.nist.fdcc.vista:var:8088"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8088"/>
                              </check>
                        </Rule>
                        <Rule id="virtualize_write_failures_per_user_locations" selected="false" weight="10.0">
                              <title>Virtualize file and registry write failures to per-user locations</title>
                              <description>The "User Account Control: Virtualize file and registry write failures to per-user locations" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4194-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-673</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="virtualize_write_failures_per_user_locations_var" export-name="oval:gov.nist.fdcc.vista:var:8089"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8089"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               User Rights Assignments               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="user_rights_assignments">
                        <title>User Rights Assignments</title>
                        <description>The NIST security templates specify which groups (e.g., Administrators, Users) have certain user rights. The goal is for each group to have only the necessary rights, and for users to only belong to the necessary groups. This is the principle of least privilege, described previously in Section 2.2. Examples of user rights that can be specified are as follows: <xhtml:ul>
                                    <xhtml:li>Accessing the system remotely and locally</xhtml:li>
                                    <xhtml:li>Performing backups</xhtml:li>
                                    <xhtml:li>Changing the time and date on the system</xhtml:li>
                                    <xhtml:li>Managing the logs</xhtml:li>
                                    <xhtml:li>Shutting down the system.</xhtml:li>
                              </xhtml:ul>Verify that the user right '' has been granted appropriately.</description>
                        <Rule id="Access-Computer-From-Network-Administrators" selected="false" weight="10.0">
                              <title>Right To Access This Computer From The Network</title>
                              <description>Verify that the user right 'Access This Computer From The Network' has been granted appropriately. (Only Administrators)  NOTE: This can break IPSec see Microsoft Knowledge Base article 823659 for further guidance</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4334-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-532</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6607"/>
                              </check>
                        </Rule>
                        <Rule id="Act-As-Part-Of-Operating-System-None" selected="false" weight="10.0">
                              <title>Right To Act As Part Of The Operating System</title>
                              <description>Verify that the user right 'Act As Part Of The Operating System' has been granted appropriately. (No One)</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4088-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-162</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6609"/>
                              </check>
                        </Rule>
                        <Rule id="Adjust-Memory-Quotas-Administrators-LocalService-NetworkService" selected="false" weight="10.0">
                              <title>Right To Adjust Memory Quotas For A Process</title>
                              <description>Verify that the user right 'Adjust Memory Quotas For A Process' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4854-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-807</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6612"/>
                              </check>
                        </Rule>
                        <Rule id="Allow-Log-On-Locally-Administrators-Users" selected="false" weight="10.0">
                              <title>Right To Log On Locally</title>
                              <description>Verify that the user right 'Allow Log On Locally' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4872-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-965</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6613"/>
                              </check>
                        </Rule>
                        <Rule id="Allow-Log-On-Through-Terminal-Services-Administrators-RemoteDesktopUsers" selected="false" weight="10.0">
                              <title>Right To Log On Through Terminal Services</title>
                              <description>Verify that the user right 'Allow Log On Through Terminal Services' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4264-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-883</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6616"/>
                              </check>
                        </Rule>
                        <Rule id="Back-Up-Files-And-Directories-Administrators" selected="false" weight="10.0">
                              <title>Right To Back Up Files and Directories</title>
                              <description>Verify that the user right 'Back Up Files and Directories' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4827-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-931</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6617"/>
                              </check>
                        </Rule>
                        <Rule id="Bypass-Traverse-Checking-Administrators_Users_LocalService_NetworkService" selected="false" weight="10.0">
                              <title>Right To Bypass Traverse Checking</title>
                              <description>Verify that the user right 'Bypass Traverse Checking' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4973-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-376</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6621"/>
                              </check>
                        </Rule>
                        <Rule id="Change-System-Time-LocalService-Administrators" selected="false" weight="10.0">
                              <title>Right To Change the System Time</title>
                              <description>Verify that the user right 'Change the System Time' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4863-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-799</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6623"/>
                              </check>
                        </Rule>
                        <Rule id="Change-Time-Zone-Administrators_Users_LocalService" selected="false" weight="10.0">
                              <title>Change the time zone</title>
                              <description>The "Change the time zone" user right should be assigned to the appropriate accounts.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5008-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-470</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:662381"/>
                              </check>
                        </Rule>
                        <Rule id="Create-Pagefile-Administrators" selected="false" weight="10.0">
                              <title>Right To Create A Pagefile</title>
                              <description>Verify that the user right 'Create A Pagefile' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4757-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-895</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6624"/>
                              </check>
                        </Rule>
                        <Rule id="Create-Token-Object-None" selected="false" weight="10.0">
                              <title>Right To Create A Token Object</title>
                              <description>Verify that the user right 'Create A Token Object' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4902-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-926</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6625"/>
                              </check>
                        </Rule>
                        <Rule id="Create-Global-Objects-Administrators-SERVICE-LocalService-NetworkService" selected="false" weight="10.0">
                              <title>Right To Create Global Objects</title>
                              <description>Verify that the user right 'Create Global Objects' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4792-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-383</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6626"/>
                              </check>
                        </Rule>
                        <Rule id="Create-Permanent-Shared-Objects-None" selected="false" weight="10.0">
                              <title>Right To Create Permanent Shared Objects</title>
                              <description>Verify that the user right 'Create Permanent Shared Objects' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4184-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-335</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6627"/>
                              </check>
                        </Rule>
                        <Rule id="Debug-Programs-None" selected="false" weight="10.0">
                              <title>Right To Debug Programs</title>
                              <description>Verify that the user right 'Debug Programs' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4687-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-842</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6628"/>
                              </check>
                        </Rule>
                        <Rule id="Deny-Access-From-Network-Guests" selected="false" weight="10.0">
                              <title>Denied Access To This Computer From The Network</title>
                              <description>Verify that the user right 'Deny Access To This Computer From The Network' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4704-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-898</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6630"/>
                              </check>
                        </Rule>
                        <Rule id="Deny-Logon-As-Batch-Job-Guests" selected="false" weight="10.0">
                              <title>Denied Logon As A Batch Job</title>
                              <description>Verify that the user right 'Deny Logon As A Batch Job' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4722-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-165</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6631"/>
                              </check>
                        </Rule>
                        <Rule id="deny_logon_as_service_none" selected="false" weight="10.0">
                              <title>Denied Logon As A Service</title>
                              <description>Verify that the user right 'Deny Logon As A Service' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4867-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-597</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6633"/>
                              </check>
                        </Rule>
                        <Rule id="Deny-Logon-Locally-Guests" selected="false" weight="10.0">
                              <title>Denied Logon Locally</title>
                              <description>Verify that the user right 'Deny Logon Locally' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4889-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-64</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6634"/>
                              </check>
                        </Rule>
                        <Rule id="Deny-Logon-Through-Terminal-Services-Guest" selected="false" weight="10.0">
                              <title>Denied Logon Through Terminal Services</title>
                              <description>Verify that the user right 'Deny Logon Through Terminal Services' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4656-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-108</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6636"/>
                              </check>
                        </Rule>
                        <Rule id="Force-Shutdown-From-Remote-System-Administrators" selected="false" weight="10.0">
                              <title>Right To Force Shutdown From A Remote System</title>
                              <description>Verify that the user right 'Force Shutdown From A Remote System' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4673-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-754</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6638"/>
                              </check>
                        </Rule>
                        <Rule id="Generate-Security-Audits-LocalService-NetworkService" selected="false" weight="10.0">
                              <title>Right To Generate Security Audits</title>
                              <description>Verify that the user right 'Generate Security Audits' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4488-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-939</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6639"/>
                              </check>
                        </Rule>
                        <Rule id="Impersonate-Client-After-Authentication-Administrators-SERVICE-LocalService-NetworkService" selected="false" weight="10.0">
                              <title>Impersonate a Client After Authentication</title>
                              <description>Verify that the user right 'Impersonate a Client After Authentication' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4382-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-304</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6640"/>
                              </check>
                        </Rule>
                        <Rule id="Increase-Process-Working-Set-Administrators_LocalService" selected="false" weight="10.0">
                              <title>Increase a Process Working Set</title>
                              <description>The "Increase a Process Working Set" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4651-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1027</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:662391"/>
                              </check>
                        </Rule>
                        <Rule id="Increase-Scheduling-Priority-Administrators" selected="false" weight="10.0">
                              <title>Right To Increase Scheduling Priority</title>
                              <description>Verify that the user right 'Increase Scheduling Priority' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4796-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-349</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6641"/>
                              </check>
                        </Rule>
                        <Rule id="Load-And-Unload-Device-Drivers-Administrators" selected="false" weight="10.0">
                              <title>Right To Load And Unload Device Drivers</title>
                              <description>Verify that the user right 'Load And Unload Device Drivers' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4034-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-860</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6642"/>
                              </check>
                        </Rule>
                        <Rule id="Lock-Pages-In-Memory-None" selected="false" weight="10.0">
                              <title>Right To Lock Pages In Memory</title>
                              <description>Verify that the user right 'Lock Pages In Memory' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4317-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-749</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6643"/>
                              </check>
                        </Rule>
                        <Rule id="Log-On-As-Batch-Job-None" selected="false" weight="10.0">
                              <title>Right To Log On As A Batch Job</title>
                              <description>Verify that the user right 'Log On As A Batch Job' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4083-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-177</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6644"/>
                              </check>
                        </Rule>
                        <Rule id="Log-On-As-Service-None" selected="false" weight="10.0">
                              <title>Right To Log On As A Service</title>
                              <description>Verify that the user right 'Log On As A Service' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4038-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-216</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6647"/>
                              </check>
                        </Rule>
                        <Rule id="Manage-Auditing-And-Security-Log-Administrators" selected="false" weight="10.0">
                              <title>Right To Manage Auditing And Security Log</title>
                              <description>Verify that the user right 'Manage Auditing And Security Log' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4046-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-850</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6648"/>
                              </check>
                        </Rule>
                        <Rule id="Modify-Object-Label-None" selected="false" weight="10.0">
                              <title>Modify an object label</title>
                              <description>The "Modify an object label" user right should be assigned to the appropriate accounts.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4285-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1023</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:662371"/>
                              </check>
                        </Rule>
                        <Rule id="Modify-Firmware-Environment-Values-Administrators" selected="false" weight="10.0">
                              <title>Right To Modify Firmware Environment Values</title>
                              <description>Verify that the user right 'Modify Firmware Environment Values' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4048-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-17</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6649"/>
                              </check>
                        </Rule>
                        <Rule id="Perform-Volume-Maintenance-Tasks-Administrators" selected="false" weight="10.0">
                              <title>Right To Perform Volume Maintenance Tasks</title>
                              <description>Verify that the user right 'Perform Volume Maintenance Tasks' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4071-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-314</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6650"/>
                              </check>
                        </Rule>
                        <Rule id="Profile-Single-Process-Administrators" selected="false" weight="10.0">
                              <title>Right To Profile Single Process</title>
                              <description>Verify that the user right 'Profile Single Process' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4962-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-260</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6651"/>
                              </check>
                        </Rule>
                        <Rule id="Profile-System-Performance-Administrators" selected="false" weight="10.0">
                              <title>Right To Profile System Performance</title>
                              <description>Verify that the user right 'Profile System Performance' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4618-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-599</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6652"/>
                              </check>
                        </Rule>
                        <Rule id="Remove-Computer-From-Docking-Station-Administrators-Users" selected="false" weight="10.0">
                              <title>Right To Remove Computer From Docking Station</title>
                              <description>Verify that the user right 'Remove Computer From Docking Station' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4861-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-656</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6653"/>
                              </check>
                        </Rule>
                        <Rule id="Replace-Process-Level-Token-NetworkService-LocalService" selected="false" weight="10.0">
                              <title>Right To Replace A Process Level Token</title>
                              <description>Verify that the user right 'Replace A Process Level Token' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4372-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-667</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6654"/>
                              </check>
                        </Rule>
                        <Rule id="Restore-Files-And-Directories-Administrators" selected="false" weight="10.0">
                              <title>Right To Restore Files And Directories</title>
                              <description>Verify that the user right 'Restore Files And Directories' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4948-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-553</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6655"/>
                              </check>
                        </Rule>
                        <Rule id="Shut-Down-System-Administrators-Users" selected="false" weight="10.0">
                              <title>Right To Shut Down The System</title>
                              <description>Verify that the user right 'Shut Down The System' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4569-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-839</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6657"/>
                              </check>
                        </Rule>
                        <Rule id="Synchronize-Directory-Service-Data-None" selected="false" weight="10.0">
                              <title>Right To Synchronize Directory Service Data</title>
                              <description>Verify that the user right 'Synchronize Directory Service Data' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4970-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-381</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6658"/>
                              </check>
                        </Rule>
                        <Rule id="Take-Ownership-Of-Files-Administrators" selected="false" weight="10.0">
                              <title>Right To Take Ownership Of Files Or Other Objects</title>
                              <description>Verify that the user right 'Take Ownership Of Files Or Other Objects' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-4988-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-492</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6659"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  System Services Group                                                                     -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="system_services_group">
                  <title>System Services Group</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              System Services Settings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="system_services_settings">
                        <title>System Services Settings</title>
                        <description>todo - description needed</description>
                        <Value id="wlan_autoconfig_var" operator="equals" type="number">
                              <title>WLAN AutoConfig</title>
                              <description>WLAN AutoConfig</description>
                              <value>4</value>
                              <value selector="service_boot_start">0</value>
                              <value selector="service_system_start">1</value>
                              <value selector="service_auto_start">2</value>
                              <value selector="service_demand_start">3</value>
                              <value selector="service_disabled">4</value>
                        </Value>
                        <Rule id="wlan_autoconfig" selected="false" weight="10.0">
                              <title>WLAN AutoConfig</title>
                              <description>This service enumerates WLAN adapters, manages WLAN connections and profiles.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="AC-18"/>
                              <ident system="http://cce.mitre.org">CCE-4627-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-957</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6148211" value-id="wlan_autoconfig_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:61481"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  3 - FDCC Other Settings                                                                     *** -->
      <!-- **************************************************************************************************** -->
      <Group id="fdcc_other_settings">
            <title>FDCC Other Settings</title>
            <description>FDCC has identified the following additional controls that must be checked in order to verify compliance.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Network Group                                                                             -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="network_group">
                  <title>Computer Configuration - Administrative Templates - Network Settings</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--       Link-Layer Topology Discovery Setttings       -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="link_layer_topology_discovery_settings">
                        <title>Link-Layer Topology Discovery</title>
                        <description>The Link Layer Topology Discovery (LLTD) specification describes how the LLTD protocol operates over wired (802.3 Ethernet) and wireless (802.11) media. LLTD enables device discovery via the data-link layer and determines the topology of a network. This specification also describes the Quality of Service (QoS) Extensions that enable stream prioritization and quality media streaming experiences, even on networks with limited bandwidth.</description>
                        <Value id="turn_on_mapper_io_lltdio_driver_var" operator="equals" type="boolean">
                              <title>Turn on Mapper I/O (LLTDIO) driver</title>
                              <description>This policy setting turns on the Mapper I/O network protocol driver. (Enabled=1; Disabled=0; Not Configured)</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="turn_on_responder_rspndr_driver_var" operator="equals" type="boolean">
                              <title>Turn on Responder (RSPNDR) driver</title>
                              <description>This policy setting turns on the Responder network protocol driver. (Enabled=1; Disabled=0; Not Configured)</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_on_mapper_io_lltdio_driver" selected="false" weight="10.0">
                              <title>Turn on Mapper I/O (LLTDIO) driver</title>
                              <description>This policy setting turns on the Mapper I/O network protocol driver. LLTDIO allows a computer to discover the topology of a network it's connected to.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Link-Layer Topology Discovery</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4992-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-347</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6660" value-id="turn_on_mapper_io_lltdio_driver_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6660"/>
                              </check>
                        </Rule>
                        <Rule id="turn_on_responder_rspndr_driver" selected="false" weight="10.0">
                              <title>Turn on Responder (RSPNDR) driver</title>
                              <description>This policy setting turns on the Responder network protocol driver. The Responder allows a computer to participate in Link Layer Topology Discovery requests so that it can be discovered and located on the network.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Link-Layer Topology Discovery</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4077-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1134</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6661" value-id="turn_on_responder_rspndr_driver_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6661"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--     Microsoft Peer-to-Peer Networking Services      -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="microsoft_peer_to_peer_networking_services_settings">
                        <title>Microsoft Peer-to-Peer Networking Services</title>
                        <description>todo - description needed</description>
                        <Value id="turn_off_microsoft_peer_to_peer_networking_services_var" operator="equals" type="boolean">
                              <title>Turn Off Microsoft Peer-to-Peer Networking Services</title>
                              <description>This setting turns off Microsoft Peer-to-Peer Networking Services. (Enabled=1; Disabled=0; Not Configured)</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_microsoft_peer_to_peer_networking_services" selected="false" weight="10.0">
                              <title>Turn Off Microsoft Peer-to-Peer Networking Services</title>
                              <description>This setting turns off Microsoft Peer-to-Peer Networking Services in its entirety, and will cause all dependent applications to stop working.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Microsoft Peer-to-Peer Networking Services</dc:source>
                              </reference>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-3270-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-86</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6662" value-id="turn_off_microsoft_peer_to_peer_networking_services_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6662"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Network Connection Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="network_connection_settings">
                        <title>Network Connection Settings</title>
                        <description>The features for implementing and administering small networks are described as follows:<xhtml:p/>-- Internet Connection Sharing (ICS) --<xhtml:p/>ICS provides Internet access for a home or small office network by using one common connection as the Internet gateway. The ICS host is the only computer that is directly connected to the Internet. Multiple ICS clients simultaneously use the common Internet connection and benefit from Internet services as if the clients were directly connected to the Internet service provider (ISP). Security is enhanced when ICS is enabled because only the ICS host computer is visible to the Internet. The addresses of ICS clients are hidden from the Internet rendering ICS clients invisible to the Internet. In addition, ICS simplifies the configuration of small networks by providing local private network services, such as name resolution and addressing.<xhtml:p/>Note: You should not use Internet Connection Sharing in an
                              existing network with Windows 2000 Server domain controllers, Domain Name System (DNS) servers, gateways, Dynamic Host Configuration Protocol (DHCP) servers, or systems configured for static IP addresses.<xhtml:p/>-- Internet Connection Firewall (ICF) --<xhtml:p/>With ICF, the firewall checks all communications that cross the connection between your network and the Internet and is selective about which responses from the Internet it allows. ICF protects only the computer on which it is enabled. If ICF is enabled on the Internet Connection Sharing (ICS) host computer, however, ICS clients that use the shared Internet connection for Internet connectivity are protected because they cannot be seen from outside your network. For this reason, you should always enable ICF on the ICS host computer. In addition, if there are clients on your network with direct Internet connections, or if you have a stand-alone computer that is connected to the Internet, then you
                              should enable ICF on those Internet connections as well.<xhtml:p/>-- Network Bridge --<xhtml:p/>Network Bridge removes the need for routing and bridging hardware in a home or small office network that consists of multiple LAN segments. With Network Bridge, multiple LAN segments become a single IP subnet, even if the LAN segments are of mixed network media types. Network Bridge automates the configuration and management of the address allocation, routing, and name resolution that is typically required in a network that consists of multiple LAN segments.<xhtml:p/>Caution If neither ICF nor ICS is enabled on your network, do not set up Network Bridge between the public Internet connection and the private network connection. Setting up Network Bridge between the public Internet connection and the private network connection creates an unprotected link between your network and the Internet, leaving your network vulnerable to external attacks. When either ICF or
                              ICS is enabled, this risk is mitigated.</description>
                        <Value id="prohibit_installation_network_bridge_var" operator="equals" type="number">
                              <title>Prohibit installation and configuration of Network Bridge on your DNS domain network</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Value id="prohibit_internet_connection_firewall_var" operator="equals" type="number">
                              <title>Prohibit use of Internet Connection Firewall on your DNS domain network</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Value id="prohibit_internet_connection_sharing_var" operator="equals" type="number">
                              <title>Prohibit use of Internet Connection Sharing on your DNS domain network</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Rule id="prohibit_installation_network_bridge" selected="false" weight="10.0">
                              <title>Prohibit installation and configuration of Network Bridge on your DNS domain network</title>
                              <description>Installation and Configuration of Network Bridge on the DNS Domain Network should be properly configured.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections</dc:source>
                              </reference>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-4152-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-896</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:3366991" value-id="prohibit_installation_network_bridge_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:3366991"/>
                              </check>
                        </Rule>
                        <Rule id="prohibit_internet_connection_firewall" selected="false" weight="10.0">
                              <title>Prohibit use of Internet Connection Firewall on your DNS domain network</title>
                              <description>The "Prohibit use of Internet Connection Firewall on your DNS domain network" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections</dc:source>
                              </reference>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-5020-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-241</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:3366992" value-id="prohibit_internet_connection_firewall_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:3366992"/>
                              </check>
                        </Rule>
                        <Rule id="prohibit_internet_connection_sharing" selected="false" weight="10.0">
                              <title>Prohibit use of Internet Connection Sharing on your DNS domain network</title>
                              <description>The "Prohibit use of Internet Connection Sharing on your DNS domain network" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections</dc:source>
                              </reference>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-4078-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-672</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:3366993" value-id="prohibit_internet_connection_sharing_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:3366993"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            Windows Connect Now Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_connect_now">
                        <title>Network connections - Windows Connect Now</title>
                        <description>todo - description needed</description>
                        <Value id="configuration_of_wireless_settings_using_windows_connect_now_var" operator="equals" type="number">
                              <title>Configuration of Wireless Settings Using Windows Connect Now</title>
                              <description>Configuration of Wireless Settings Using Windows Connect Now. (Enabled = 0; Disabled = 1)</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="prohibit_access_of_the_windows_connect_now_wizards_var" operator="equals" type="number">
                              <title>Prohibit Access of the Windows Connect Now Wizards</title>
                              <description>Prohibit Access of the Windows Connect Now Wizards. (Enabled = 1; Disabled = 0)</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="configuration_of_wireless_settings_using_windows_connect_now" selected="false" weight="10.0">
                              <title>Configuration of Wireless Settings Using Windows Connect Now</title>
                              <description>Configuration of Wireless Settings Using Windows Connect Now</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Windows Connect Now</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5061-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-734</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6665" value-id="configuration_of_wireless_settings_using_windows_connect_now_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6665"/>
                              </check>
                        </Rule>
                        <Rule id="prohibit_access_of_the_windows_connect_now_wizards" selected="false" weight="10.0">
                              <title>Prohibit Access of the Windows Connect Now Wizards</title>
                              <description>Prohibit Access of the Windows Connect Now Wizards</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Windows Connect Now</dc:source>
                              </reference>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-3045-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-629</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6666" value-id="prohibit_access_of_the_windows_connect_now_wizards_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6666"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  System Group                                                                              -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="system_group">
                  <title>Computer Configuration - Administrative Templates - System Settings</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            Device Installation Setttings            -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="device_installation_settings">
                        <title>Local Computer - Administrative Templates - System Settings - Device Installation</title>
                        <description>todo - description needed</description>
                        <Value id="allow_remote_access_to_the_pnp_interface_var" operator="equals" type="number">
                              <title>Allow remote access to the PnP interface</title>
                              <description>Computer Configuration\Administrative Templates\System\Device Installation: Allow remote access to the PnP interface. (Enabled = 1; Disabled = 0)</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="do_not_create_system_restore_point_when_new_device_driver_installed_var" operator="equals" type="number">
                              <title>Do not create system restore point when new device driver installed</title>
                              <description>Computer Configuration\Administrative Templates\System\Device Installation: Do not create system restore point when new device driver installed. (Enabled = 1; Disabled = 0)</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="do_not_send_windows_error_report_when_generic_driver_is_installed_on_device_var" operator="equals" type="number">
                              <title>Do not send a Windows Error Report when a generic driver is installed on a device</title>
                              <description>Computer Configuration\Administrative Templates\System\Device Installation: Do not send a Windows Error Report when a generic driver is installed on a device. (Enabled = 0; Disabled = 1)</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="allow_remote_access_to_the_pnp_interface" selected="false" weight="10.0">
                              <title>Allow remote access to the PnP interface</title>
                              <description>Computer Configuration\Administrative Templates\System\Device Installation: Allow remote access to the PnP interface.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Device Installation</dc:source>
                              </reference>
                              <requires idref="AC-17"/>
                              <ident system="http://cce.mitre.org">CCE-3331-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-593</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6667" value-id="allow_remote_access_to_the_pnp_interface_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6667"/>
                              </check>
                        </Rule>
                        <Rule id="do_not_create_system_restore_point_when_new_device_driver_installed" selected="false" weight="10.0">
                              <title>Do not create system restore point when new device driver installed</title>
                              <description>Computer Configuration\Administrative Templates\System\Device Installation: Do not create system restore point when new device driver installed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Device Installation</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3464-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-849</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6668" value-id="do_not_create_system_restore_point_when_new_device_driver_installed_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6668"/>
                              </check>
                        </Rule>
                        <Rule id="do_not_send_windows_error_report_when_generic_driver_is_installed_on_device" selected="false" weight="10.0">
                              <title>Do not send a Windows Error Report when a generic driver is installed on a device</title>
                              <description>Computer Configuration\Administrative Templates\System\Device Installation: Do not send a Windows Error Report when a generic driver is installed on a device.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Device Installation</dc:source>
                              </reference>
                              <requires idref="SI-11"/>
                              <ident system="http://cce.mitre.org">CCE-3468-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-571</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6669" value-id="do_not_send_windows_error_report_when_generic_driver_is_installed_on_device_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6669"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            Driver Installation Setttings            -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="driver_installation_settings">
                        <title>Local Computer - Administrative Templates - System Settings - Driver Installation</title>
                        <description>todo - description needed</description>
                        <Value id="turn_off_windows_update_device_driver_search_prompt_var" operator="equals" type="number">
                              <title>Turn Off Windows Update Device Driver Search Prompt</title>
                              <description>Computer Configuration\Administrative Templates\System\Driver Installation: Turn Off Windows Update Device Driver Search Prompt. (Enabled = 1; Disabled = 0)</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_windows_update_device_driver_search_prompt" selected="false" weight="10.0">
                              <title>Turn Off Windows Update Device Driver Search Prompt</title>
                              <description>Computer Configuration\Administrative Templates\System\Driver Installation: Turn Off Windows Update Device Driver Search Prompt.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Driver Installation</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3278-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-927</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6670" value-id="turn_off_windows_update_device_driver_search_prompt_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6670"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Group Policy Setttings                -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="group_policy_settings">
                        <title>Group Policy Client-Side Extensions</title>
                        <description>The following rules specify the desired setting for the client-side extensions designed for Group Policy.</description>
                        <Value id="registry_policy_var" operator="equals" type="number">
                              <title>Registry Policy Processing</title>
                              <description>Computer Configuration\Administrative Templates\System: Group Policy - Registry Policy Processing.</description>
                              <value>0</value>
                              <value selector="not_configured">-1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled:nobackgroundpolicy">1</value>
                              <value selector="enabled:nogpolistchanges">2</value>
                              <value selector="enabled:nobackgroundpolicy_and_nogpolistchanges">3</value>
                        </Value>
                        <Rule id="registry_policy" selected="false" weight="10.0">
                              <title>Registry Policy</title>
                              <description>Computer Configuration\Administrative Templates\System: Group Policy - Registry Policy Processing.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Group Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3452-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-584</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6672" value-id="registry_policy_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6672"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--          Internet Communication Setttings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="internet_communication_settings">
                        <title>Computer_Configuration - Administrative_Templates - System: Internet Communication Management - Internet Communication settings</title>
                        <description>todo - description needed</description>
                        <Value id="turn_off_automatic_root_certificates_update_var" operator="equals" type="string">
                              <title>Turn Off Automatic Root Certificates Update</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Automatic Root Certificates Update.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_off_downloading_of_print_drivers_over_http_var" operator="equals" type="string">
                              <title>Turn off downloading of print drivers over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off downloading of print drivers over HTTP.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_off_event_views_events.asp_links_var" operator="equals" type="string">
                              <title>Turn Off Event Views "Events.asp" Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Event Views "Events.asp" Links.</description>
                              <value>Disabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_off_handwriting_reconition_error_reporting_var" operator="equals" type="string">
                              <title>Turn Off Handwriting Reconition Error Reporting</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Handwriting Reconition Error Reporting.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_off_internet_connection_wizard_if_url_connection_is_referring_to_microsoft.com_var" operator="equals" type="string">
                              <title>Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards_var" operator="equals" type="string">
                              <title>Turn off Internet download for Web publishing and online ordering wizards</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Internet download for Web publishing and online ordering wizards.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Internet-File-Association-Service_var" operator="equals" type="string">
                              <title>Turn Off Internet File Association Service</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet File Association Service.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-printing-over-HTTP_var" operator="equals" type="string">
                              <title>Turn off printing over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off printing over HTTP.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com_var" operator="equals" type="string">
                              <title>Turn Off Registration if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Registration if URL Connection is Referring to Microsoft.com.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-Search-Companion-content-file-updates_var" operator="equals" type="string">
                              <title>Turn off Search Companion content file updates</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Search Companion content file updates.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-the-Order-Prints-Picture-Task_var" operator="equals" type="string">
                              <title>Turn Off the "Order Prints" Picture Task</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off the "Order Prints" Picture Task.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-the-Publish-to-Web-task-for-files-and-folders_var" operator="equals" type="string">
                              <title>Turn off the "Publish to Web" task for files and folders</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the "Publish to Web" task for files and folders.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program_var" operator="equals" type="string">
                              <title>Turn off the Windows Messenger Customer Experience Improvement Program</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the Windows Messenger Customer Experience Improvement Program.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_off_windows_error_reporting_var" operator="equals" type="string">
                              <title>Turn Off Windows Error Reporting</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Error Reporting.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads_var" operator="equals" type="string">
                              <title>Turn Off Windows Movies Maker Automatic Codec Downloads</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movies Maker Automatic Codec Downloads.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Windows-Movie-Maker-Online-Web-Links_var" operator="equals" type="string">
                              <title>Turn Off Windows Movie Maker Online Web Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Online Web Links.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Windows-Movie-Maker-Saving-to-Online-Video-Hosting-Provider_var" operator="equals" type="string">
                              <title>Turn Off Windows Movie Maker Saving to Online Video Hosting Provider</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Saving to Online Video Hosting Provider.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-Windows-Update-device-driver-searching_var" operator="equals" type="string">
                              <title>Turn off Windows Update device driver searching</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Windows Update device driver searching.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="turn_off_automatic_root_certificates_update" selected="false" weight="10.0">
                              <title>Turn Off Automatic Root Certificates Update</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Automatic Root Certificates Update.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3454-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-858</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6674" value-id="turn_off_automatic_root_certificates_update_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6674"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_downloading_of_print_drivers_over_http" selected="false" weight="10.0">
                              <title>Turn off downloading of print drivers over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off downloading of print drivers over HTTP.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2754-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-887</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6572" value-id="turn_off_downloading_of_print_drivers_over_http_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6572"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_event_views_events.asp_links" selected="false" weight="10.0">
                              <title>Turn Off Event Views "Events.asp" Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Event Views "Events.asp" Links.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3348-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-263</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6675" value-id="turn_off_event_views_events.asp_links_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6675"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_handwriting_reconition_error_reporting" selected="false" weight="10.0">
                              <title>Turn Off Handwriting Reconition Error Reporting</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Handwriting Reconition Error Reporting.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2868-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-430</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6676" value-id="turn_off_handwriting_reconition_error_reporting_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6676"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_internet_connection_wizard_if_url_connection_is_referring_to_microsoft.com" selected="false" weight="10.0">
                              <title>Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3432-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1055</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6679" value-id="turn_off_internet_connection_wizard_if_url_connection_is_referring_to_microsoft.com_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6679"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards" selected="false" weight="10.0">
                              <title>Turn off Internet download for Web publishing and online ordering wizards</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Internet download for Web publishing and online ordering wizards.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3364-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-691</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6568" value-id="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6568"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Internet-File-Association-Service" selected="false" weight="10.0">
                              <title>Turn Off Internet File Association Service</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet File Association Service.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2697-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1064</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6680" value-id="Turn-Off-Internet-File-Association-Service_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6680"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-printing-over-HTTP" selected="false" weight="10.0">
                              <title>Turn off printing over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off printing over HTTP.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3421-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-852</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6571" value-id="Turn-off-printing-over-HTTP_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6571"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com" selected="false" weight="10.0">
                              <title>Turn Off Registration if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Registration if URL Connection is Referring to Microsoft.com.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3093-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-88</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6681" value-id="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6681"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-Search-Companion-content-file-updates" selected="false" weight="10.0">
                              <title>Turn off Search Companion content file updates</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Search Companion content file updates.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2778-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-818</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6570" value-id="Turn-off-Search-Companion-content-file-updates_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6570"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-the-Order-Prints-Picture-Task" selected="false" weight="10.0">
                              <title>Turn Off the "Order Prints" Picture Task</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off the "Order Prints" Picture Task.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3115-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-375</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6682" value-id="Turn-Off-the-Order-Prints-Picture-Task_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6682"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-the-Publish-to-Web-task-for-files-and-folders" selected="false" weight="10.0">
                              <title>Turn off the "Publish to Web" task for files and folders</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the "Publish to Web" task for files and folders.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2477-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1009</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6567" value-id="Turn-off-the-Publish-to-Web-task-for-files-and-folders_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6567"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program" selected="false" weight="10.0">
                              <title>Turn off the Windows Messenger Customer Experience Improvement Program</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the Windows Messenger Customer Experience Improvement Program.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3259-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-722</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6569" value-id="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6569"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_windows_error_reporting" selected="false" weight="10.0">
                              <title>Turn Off Windows Error Reporting</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Error Reporting.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4694-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-592</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6683" value-id="turn_off_windows_error_reporting_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6683"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads" selected="false" weight="10.0">
                              <title>Turn Off Windows Movies Maker Automatic Codec Downloads</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movies Maker Automatic Codec Downloads.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3403-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1040</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6696" value-id="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6696"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Windows-Movie-Maker-Online-Web-Links" selected="false" weight="10.0">
                              <title>Turn Off Windows Movie Maker Online Web Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Online Web Links.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3297-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1062</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6684" value-id="Turn-Off-Windows-Movie-Maker-Online-Web-Links_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6684"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Windows-Movie-Maker-Saving-to-Online-Video-Hosting-Provider" selected="false" weight="10.0">
                              <title>Turn Off Windows Movie Maker Saving to Online Video Hosting Provider</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Saving to Online Video Hosting Provider.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3385-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-93</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6697" value-id="Turn-Off-Windows-Movie-Maker-Saving-to-Online-Video-Hosting-Provider_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6697"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-Windows-Update-device-driver-searching" selected="false" weight="10.0">
                              <title>Turn off Windows Update device driver searching</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Windows Update device driver searching.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3278-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-927</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6573" value-id="Turn-off-Windows-Update-device-driver-searching_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6573"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                   Logon Setttings                   -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="logon_settings">
                        <title>Computer_Configuration - Administrative_Templates - System - Logon</title>
                        <description>todo - description needed</description>
                        <Value id="Always-Use-Classic-Logon_var" operator="equals" type="string">
                              <title>Always Use Classic Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Always Use Classic Logon.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="SSLF-rev2-Laptop">Enabled</value>
                              <value selector="SSLF-rev2-Desktop">Enabled</value>
                        </Value>
                        <Value id="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon_var" operator="equals" type="string">
                              <title>Don’t Display the Getting Started Welcome Screen at Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Don’t Display the Getting Started Welcome Screen at Logon.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="SSLF-rev2-Laptop">Enabled</value>
                              <value selector="SSLF-rev2-Desktop">Enabled</value>
                        </Value>
                        <Rule id="Always-Use-Classic-Logon" selected="false" weight="10.0">
                              <title>Always Use Classic Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Always Use Classic Logon.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Logon</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4813-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-231</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6686" value-id="Always-Use-Classic-Logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6686"/>
                              </check>
                        </Rule>
                        <Rule id="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon" selected="false" weight="10.0">
                              <title>Don’t Display the Getting Started Welcome Screen at Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Don’t Display the Getting Started Welcome Screen at Logon.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Logon</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2781-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1020</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6687" value-id="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6687"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                   Sleep Setttings                   -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="sleep_settings">
                        <title>Computer_Configuration - Administrative_Templates - System - Power Management - Sleep settings</title>
                        <description>todo - description needed</description>
                        <Value id="Require-a-Password-when-a-Computer-Wakes-On-Battery_var" operator="equals" type="string">
                              <title>Require a Password when a Computer Wakes (On Battery)</title>
                              <description>Computer Configuration\Administrative Templates\System\Power Management: Sleep Settings - Require a Password when a Computer Wakes (On Battery).</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Require-a-Password-when-a-Computer-Wakes-Plugged_var" operator="equals" type="string">
                              <title>Require a Password when a Computer Wakes (Plugged)</title>
                              <description>Computer Configuration\Administrative Templates\System\Power Management: Sleep Settings - Require a Password when a Computer Wakes (Plugged).</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="Require-a-Password-when-a-Computer-Wakes-On-Battery" selected="false" weight="10.0">
                              <title>Require a Password when a Computer Wakes (On Battery)</title>
                              <description>Computer Configuration\Administrative Templates\System\Power Management: Sleep Settings - Require a Password when a Computer Wakes (On Battery).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Power Management\Sleep Settings</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2821-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-346</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6689" value-id="Require-a-Password-when-a-Computer-Wakes-On-Battery_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6689"/>
                              </check>
                        </Rule>
                        <Rule id="Require-a-Password-when-a-Computer-Wakes-Plugged" selected="false" weight="10.0">
                              <title>Require a Password when a Computer Wakes (Plugged)</title>
                              <description>Computer Configuration\Administrative Templates\System\Power Management: Sleep Settings - Require a Password when a Computer Wakes (Plugged).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Power Management\Sleep Settings</dc:source>
                              </reference>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-3469-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1011</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6690" value-id="Require-a-Password-when-a-Computer-Wakes-Plugged_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6690"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Remote Assistance Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="remote_assistance_settings">
                        <title>Computer_Configuration - Administrative_Templates - System: Remote Assistance</title>
                        <description>todo - description needed</description>
                        <Value id="offer_remote_assistance_var" operator="equals" type="string">
                              <title>Offer Remote Assistance</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - Offer Remote Assistance.</description>
                              <value>Disabled</value>
                              <value selector="not_configured">Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="solicited_remote_assistance_var" operator="equals" type="string">
                              <title>Solicited Remote Assistance</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - Solicited Remote Assistance.</description>
                              <value>Disabled</value>
                              <value selector="not_configured">Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_on_session_logging_var" operator="equals" type="string">
                              <title>Turn on session logging</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - Turn on session logging.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="offer_remote_assistance" selected="false" weight="10.0">
                              <title>Offer Remote Assistance</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - Offer Remote Assistance.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Assistance</dc:source>
                              </reference>
                              <requires idref="AC-17"/>
                              <ident system="http://cce.mitre.org">CCE-3217-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-434</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6563" value-id="offer_remote_assistance_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6563"/>
                              </check>
                        </Rule>
                        <Rule id="solicited_remote_assistance" selected="false" weight="10.0">
                              <title>Solicited Remote Assistance</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - Solicited Remote Assistance.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Assistance</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3323-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-859</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6564" value-id="solicited_remote_assistance_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6564"/>
                              </check>
                        </Rule>
                        <Rule id="turn_on_session_logging" selected="false" weight="10.0">
                              <title>Turn on session logging</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - Turn on session logging.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Assistance</dc:source>
                              </reference>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-3271-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-835</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6694" value-id="turn_on_session_logging_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6694"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Remote Procedure Call Setttings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="remote_procedure_call_settings">
                        <title>Computer_Configuration - Administrative_Templates - System: Remote Procedure Call</title>
                        <description>todo - description needed</description>
                        <Value id="restrictions_for_unauthenticated_rpc_clients_var" operator="greater than or equal" type="number">
                              <title>Restrictions for Unauthenticated RPC clients</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - Restrictions for Unauthenticated RPC clients. (Enabled: Authenticated = 1)</description>
                              <value>1</value>
                              <value selector="enabled:none">0</value>
                              <value selector="enabled:authenticated">1</value>
                              <value selector="enabled:authenticated_with_exceptions">2</value>
                        </Value>
                        <Value id="rpc_endpoint_mapper_client_authentication_var" operator="equals" type="string">
                              <title>RPC Endpoint Mapper Client Authentication</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - RPC Endpoint Mapper Client Authentication.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="restrictions_for_unauthenticated_rpc_clients" selected="false" weight="10.0">
                              <title>Restrictions for Unauthenticated RPC clients</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - Restrictions for Unauthenticated RPC clients.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Procedure Call</dc:source>
                              </reference>
                              <requires idref="IA-2"/>
                              <ident system="http://cce.mitre.org">CCE-3160-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-423</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6565" value-id="restrictions_for_unauthenticated_rpc_clients_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6565"/>
                              </check>
                        </Rule>
                        <Rule id="rpc_endpoint_mapper_client_authentication" selected="false" weight="10.0">
                              <title>RPC Endpoint Mapper Client Authentication</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - RPC Endpoint Mapper Client Authentication.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Procedure Call</dc:source>
                              </reference>
                              <requires idref="IA-2"/>
                              <ident system="http://cce.mitre.org">CCE-3394-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-145</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6566" value-id="rpc_endpoint_mapper_client_authentication_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6566"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Disable Components Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="disable_components_settings">
                        <title>Disable Components Settings</title>
                        <description>todo - description needed</description>
                        <Value id="disable_isatap_teredo_6to4_tunneling_protocols_var" operator="equals" type="number">
                              <title>Disable ISATAP, Teredo, and 6to4 tunneling protocols</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disable_all_tunnel_interfaces">1</value>
                              <value selector="disable_6to4">2</value>
                              <value selector="disable_isatap">4</value>
                              <value selector="disable_teredo">8</value>
                              <value selector="disable_teredo_6to4">10</value>
                              <value selector="disable_all_lan_ppp">16</value>
                              <value selector="disable_all_lan_ppp_tunnel">17</value>
                              <value selector="prefer_ipv4_over_ipv6">32</value>
                              <value selector="disable_ipv6_over_all_interfaces_and_prefer_ipv4_to_ipv6">255</value>
                        </Value>
                        <Rule id="disable_isatap_teredo_6to4_tunneling_protocols" selected="false" weight="10.0">
                              <title>Disable ISATAP, Teredo, and 6to4 tunneling protocols</title>
                              <description>Disable ISATAP, Teredo, and 6to4 tunneling protocols</description>
                              <requires idref="CM-6"/>
                              <!--
                               This rule corresponds to 3 different CCEs.  We need to work out with the CCE community
                               if these 3 CCEs should be combined into one or if a forth CCE needs to be issed to
                               relate to the 'disable all' setting.
                               
                              <ident system="http://cce.mitre.org">CCE-1227</ident>
                              <ident system="http://cce.mitre.org">CCE-1036</ident>
                              <ident system="http://cce.mitre.org">CCE-1148</ident>
                              -->
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6566666" value-id="disable_isatap_teredo_6to4_tunneling_protocols_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6566666"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Windows Components Group                                                                  -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="windows_components_group">
                  <title>Computer Configuration - Administrative Templates - Windows Components</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Autoplay Policies Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="autoplay_policies_settings">
                        <title>Autoplay Policies</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Autoplay Policies</description>
                        <Rule id="turn_off_autoplay" selected="false" weight="10.0">
                              <title>Turn off Autoplay</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\Autoplay Policies: Turn off Autoplay.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\AutoPlay Policies</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2719-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-44</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:65741"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--         Credential User Interface Setttings         -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="credential_user_interface_settings">
                        <title>Credential User Interface</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Credential User Interface</description>
                        <Value id="enumerate_administrator_accounts_on_elevation_var" operator="equals" type="string">
                              <title>Enumerate administrator accounts on elevation</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\Credential User Interface: Enumerate administrator accounts on elevation.</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="enumerate_administrator_accounts_on_elevation" selected="false" weight="10.0">
                              <title>Enumerate administrator accounts on elevation</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\Credential User Interface: Enumerate administrator accounts on elevation.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Credential User Interface</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-2471-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-935</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6575" value-id="enumerate_administrator_accounts_on_elevation_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6575"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Digial Locker Setttings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="digial_locker_settings">
                        <title>Digial Locker</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Digial Locker</description>
                        <Value id="do_not_allow_digital_locker_to_run_var" operator="equals" type="string">
                              <title>Do not allow Digital Locker to run</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\Digial Locker: Do not allow Digital Locker to run.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="do_not_allow_digital_locker_to_run" selected="false" weight="10.0">
                              <title>Do not allow Digital Locker to run</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\Digial Locker: Do not allow Digital Locker to run.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Digital Locker</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3482-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1747</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6698" value-id="do_not_allow_digital_locker_to_run_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6698"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Event Log Service Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="event_log_service_settings">
                        <title>Event Log Service Settings</title>
                        <description>Windows Vista records information about significant events in four logs: the Application Log, the Security Log, the Setup Log, and the System Log. The logs contain error messages, audit information, and other records of activity on the system. The logs can be used not only to identify suspicious and malicious behavior and investigate security incidents, but also to assist in troubleshooting system and application problems. It is important to specify the maximum log size because if it is too low, the system will not have much room for storing information on system activity.</description>
                        <Value id="maximum_application_log_size_var" type="number" operator="greater than or equal">
                              <title>Maximum Application Log Size</title>
                              <description>The value defines the maximum size (in KB) of the application log.</description>
                              <value>32768</value>
                              <value selector="enabled:16384_kb">16384</value>
                              <value selector="enabled:32768_kb">32768</value>
                              <value selector="enabled:81920_kb">81920</value>
                        </Value>
                        <Value id="maximum_security_log_size_var" type="number" operator="greater than or equal">
                              <title>Maximum Security Log Size</title>
                              <description>The value defines the maximum size (in KB) of the security log.</description>
                              <value>81920</value>
                              <value selector="enabled:16384_kb">16384</value>
                              <value selector="enabled:32768_kb">32768</value>
                              <value selector="enabled:81920_kb">81920</value>
                        </Value>
                        <Value id="maximum_setup_log_size_var" type="number" operator="greater than or equal">
                              <title>Maximum Setup Log Size</title>
                              <description>The value defines the maximum size (in KB) of the setup log.</description>
                              <value>32768</value>
                              <value selector="enabled:16384_kb">16384</value>
                              <value selector="enabled:32768_kb">32768</value>
                              <value selector="enabled:81920_kb">81920</value>
                        </Value>
                        <Value id="maximum_system_log_size_var" type="number" operator="greater than or equal">
                              <title>Maximum System Log Size</title>
                              <description>The value defines the maximum size (in KB) of the system log.</description>
                              <value>32768</value>
                              <value selector="enabled:16384_kb">16384</value>
                              <value selector="enabled:32768_kb">32768</value>
                              <value selector="enabled:81920_kb">81920</value>
                        </Value>
                        <Rule id="maximum_application_log_size" selected="false" weight="10.0">
                              <title>Maximum Application Log Size</title>
                              <description>Maximum Application Log Size</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Event Log Service\Application</dc:source>
                              </reference>
                              <requires idref="AU-4"/>
                              <ident system="http://cce.mitre.org">CCE-3015-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-185</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="maximum_application_log_size_var" export-name="oval:gov.nist.fdcc.vista:var:16"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:197"/>
                              </check>
                        </Rule>
                        <Rule id="maximum_security_log_size" selected="false" weight="10.0">
                              <title>Maximum Security Log Size</title>
                              <description>Maximum Security Log Size</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Event Log Service\Security</dc:source>
                              </reference>
                              <requires idref="AU-4"/>
                              <ident system="http://cce.mitre.org">CCE-3302-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-757</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="maximum_security_log_size_var" export-name="oval:gov.nist.fdcc.vista:var:81"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:198"/>
                              </check>
                        </Rule>
                        <Rule id="maximum_setup_log_size" selected="false" weight="10.0">
                              <title>Maximum Setup Log Size</title>
                              <description>Maximum Setup Log Size</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Event Log Service\Setup</dc:source>
                              </reference>
                              <requires idref="AU-4"/>
                              <ident system="http://cce.mitre.org">CCE-4086-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-262</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="maximum_setup_log_size_var" export-name="oval:gov.nist.fdcc.vista:var:19898"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:19898"/>
                              </check>
                        </Rule>
                        <Rule id="maximum_system_log_size" selected="false" weight="10.0">
                              <title>Maximum System Log Size</title>
                              <description>Maximum System Log Size</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Event Log Service\System</dc:source>
                              </reference>
                              <requires idref="AU-4"/>
                              <ident system="http://cce.mitre.org">CCE-3165-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-735</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="maximum_system_log_size_var" export-name="oval:gov.nist.fdcc.vista:var:84"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:199"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Game Explorer Setttings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="game_explorer_settings">
                        <title>Game Explorer</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Game Explorer</description>
                        <Value id="turn_off_downloading_of_game_information_var" operator="equals" type="string">
                              <title>Turn Off Downloading of Game Information</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\Game Explorer: Turn Off Downloading of Game Information.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="turn_off_downloading_of_game_information" selected="false" weight="10.0">
                              <title>Turn Off Downloading of Game Information</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\Game Explorer: Turn Off Downloading of Game Information.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Game Explorer</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2755-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1778</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6703" value-id="turn_off_downloading_of_game_information_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6703"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--       Internet Information Services Setttings       -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="internet_information_services_settings">
                        <title>Internet Information Services</title>
                        <description>Internet Information Services</description>
                        <Value id="Prevent-IIS-Installation_var" operator="equals" type="number">
                              <title>Prevent IIS Installation</title>
                              <description>This blocks even local Administrators from adding local web services to the Vista client</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                              <value selector="SSLF-rev2-Laptop">1</value>
                              <value selector="SSLF-rev2-Desktop">1</value>
                              <value selector="FDCC-Laptop">1</value>
                              <value selector="FDCC-Desktop">1</value>
                        </Value>
                        <Rule id="Prevent-IIS-Installation" selected="false" weight="10.0">
                              <title>Prevent IIS Installation</title>
                              <description>This blocks even local Administrators from adding local web services to the XP client</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Information Services</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-3288-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-474</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61071" value-id="Prevent-IIS-Installation_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6107"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                NetMeeting Setttings                 -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="netmeeting_settings">
                        <title>NetMeeting</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: NetMeeting</description>
                        <Value id="Disable-remote-Desktop-Sharing_var" operator="equals" type="string">
                              <title>Disable remote Desktop Sharing</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\NetMeeting: Disable remote Desktop Sharing.</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="Disable-remote-Desktop-Sharing" selected="false" weight="10.0">
                              <title>Disable remote Desktop Sharing</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\NetMeeting: Disable remote Desktop Sharing.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\NetMeeting</dc:source>
                              </reference>
                              <requires idref="AC-17"/>
                              <ident system="http://cce.mitre.org">CCE-3082-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-232</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6595" value-id="Disable-remote-Desktop-Sharing_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6595"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Online Assistance Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="online_assistance_settings">
                        <title>Online Assistance</title>
                        <description>Online Assistance</description>
                        <Value id="turn_off_untrusted_content_var" operator="equals" type="number">
                              <title>Turn off Untrusted Content</title>
                              <description>Specifies whether untrusted content is rendered. By default, the Help viewer renders untrusted assistance content pages with the exception of active links. Active links, such as ShellExecute and Guided Help, are rendered as text and are not clickable.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_untrusted_content" selected="false" weight="10.0">
                              <title>Turn off Untrusted Content</title>
                              <description>Specifies whether untrusted content is rendered. By default, the Help viewer renders untrusted assistance content pages with the exception of active links. Active links, such as ShellExecute and Guided Help, are rendered as text and are not clickable.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Online Assistance</dc:source>
                              </reference>
                              <requires idref="SI-10"/>
                              <ident system="http://cce.mitre.org">CCE-3046-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-95</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61091" value-id="turn_off_untrusted_content_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6109"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                  Search Setttings                   -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="search_settings">
                        <title>Search</title>
                        <description>Search</description>
                        <Value id="Allow-indexing-of-encrypted-files_var" operator="equals" type="string">
                              <title>Allow indexing of encrypted files</title>
                              <description>Allow indexing of encrypted files</description>
                              <value>Disabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Prevent-indexing-uncached-Exchange-folders_var" operator="equals" type="string">
                              <title>Prevent indexing uncached Exchange folders</title>
                              <description>Prevent indexing uncached Exchange folders</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="Allow-indexing-of-encrypted-files" selected="false" weight="10.0">
                              <title>Allow indexing of encrypted files</title>
                              <description>Allow indexing of encrypted files</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Search</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3376-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1049</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6704" value-id="Allow-indexing-of-encrypted-files_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6704"/>
                              </check>
                        </Rule>
                        <Rule id="Prevent-indexing-uncached-Exchange-folders" selected="false" weight="10.0">
                              <title>Prevent indexing uncached Exchange folders</title>
                              <description>Prevent indexing uncached Exchange folders</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Search</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3143-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1058</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6705" value-id="Prevent-indexing-uncached-Exchange-folders_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6705"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Terminal Services Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="terminal_services_settings">
                        <title>Terminal Services</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Terminal Services</description>
                        <Value id="Do-not-allow-passwords-to-be-saved_var" operator="equals" type="string">
                              <title>Do not allow passwords to be saved</title>
                              <description>Do not allow passwords to be saved</description>
                              <value>Enabled</value>
                              <value selector="not_configured">Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Do-not-allow-drive-redirection_var" operator="equals" type="string">
                              <title>Do not allow drive redirection</title>
                              <description>Do not allow drive redirection</description>
                              <value>Enabled</value>
                              <value selector="not_configured">Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Always-prompt-client-for-password-upon-connection_var" operator="equals" type="string">
                              <title>Always prompt client for password upon connection</title>
                              <description>Always prompt client for password upon connection</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Set-client-connection-encryption-level_var" operator="equals" type="number">
                              <title>Set client connection encryption level</title>
                              <description>Set client connection encryption level</description>
                              <value>3</value>
                              <value selector="low">1</value>
                              <value selector="client_compatible">2</value>
                              <value selector="high">3</value>
                        </Value>
                        <Value id="set_timelimit_for_disconnected_sessions_var" operator="equals" type="number">
                              <title>Set a time limit for disconnected sessions</title>
                              <description>You can use this policy setting to specify the maximum amount of time that a disconnected session is kept active on the server. By default, Terminal Services allows users to disconnect from a remote session without logging off and ending the session. (1 min)</description>
                              <value>60000</value>
                              <value selector="60_seconds">60000</value>
                        </Value>
                        <Value id="set_timelimit_for_active_but_idle_terminal_services_sessions_var" operator="equals" type="number">
                              <title>Set a time limit for active but idle Terminal Services sessions</title>
                              <description>This policy setting allows you to specify the maximum amount of time that an active Terminal Services session can be idle (without user input) before it is automatically disconnected. (15 min)</description>
                              <value>900000</value>
                              <value selector="900_seconds">900000</value>
                        </Value>
                        <Rule id="Do-not-allow-passwords-to-be-saved" selected="false" weight="10.0">
                              <title>Do not allow passwords to be saved</title>
                              <description>The "Do not allow passwords to be saved" setting should be configured correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Remote Desktop Connection Client</dc:source>
                              </reference>
                              <requires idref="IA-2"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2975-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-976</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6596" value-id="Do-not-allow-passwords-to-be-saved_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6596"/>
                              </check>
                        </Rule>
                        <Rule id="Do-not-allow-drive-redirection" selected="false" weight="10.0">
                              <title>Do not allow drive redirection</title>
                              <description>The "Do not allow drive redirection" setting should be configured correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Device and Resource Redirection</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4501-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-648</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6598" value-id="Do-not-allow-drive-redirection_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6598"/>
                              </check>
                        </Rule>
                        <Rule id="Always-prompt-client-for-password-upon-connection" selected="false" weight="10.0">
                              <title>Always prompt client for password upon connection</title>
                              <description>The "Always Prompt Client for Password upon Connection" policy should be set correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Security</dc:source>
                              </reference>
                              <requires idref="IA-2"/>
                              <ident system="http://cce.mitre.org">CCE-3429-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-855</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6599" value-id="Always-prompt-client-for-password-upon-connection_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6599"/>
                              </check>
                        </Rule>
                        <Rule id="Set-client-connection-encryption-level" selected="false" weight="10.0">
                              <title>Set client connection encryption level</title>
                              <description>The "Set Client connection Encryption Level" policy should be set correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Security</dc:source>
                              </reference>
                              <requires idref="SC-13"/>
                              <ident system="http://cce.mitre.org">CCE-4866-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-397</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6600" value-id="Set-client-connection-encryption-level_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6600"/>
                              </check>
                        </Rule>
                        <Rule id="set_timelimit_for_disconnected_sessions" selected="false" weight="10.0">
                              <title>Set a time limit for disconnected sessions</title>
                              <description>The "Set time limit for disconnected sessions" policy should be set correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Session Time Limits</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-5007-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-920</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6726" value-id="set_timelimit_for_disconnected_sessions_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6726"/>
                              </check>
                        </Rule>
                        <Rule id="set_timelimit_for_active_but_idle_terminal_services_sessions" selected="false" weight="10.0">
                              <title>Set a time limit for active but idle Terminal Services sessions</title>
                              <description>The "Set time limit for idle sessions" policy should be set correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Session Time Limits</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-4267-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-123</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6725" value-id="set_timelimit_for_active_but_idle_terminal_services_sessions_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6725"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Windows Defender Setttings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_defender_settings">
                        <title>Windows Defender</title>
                        <description>Windows Defender</description>
                        <Value id="configure_ms_spynet_reporting_var" operator="equals" type="number">
                              <title>Configure Microsoft SpyNet Reporting</title>
                              <description>When Windows Defender detects software or changes by software not yet classified for risks, you see how other members responded to the alert. In turn, the action you apply help other members choose how to respond. Your actions also help Microsoft choose which software to investigate for potential threats. You can choose to send basic or additional information about detected software. Additional information helps improve how Windows Defender works. It can include, for example, the location of detected items on your computer if harmful software has been removed. Windows Defender will automatically collect and send the information.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="configure_ms_spynet_reporting" selected="false" weight="10.0">
                              <title>Configure Microsoft SpyNet Reporting</title>
                              <description>When Windows Defender detects software or changes by software not yet classified for risks, you see how other members responded to the alert. In turn, the action you apply help other members choose how to respond. Your actions also help Microsoft choose which software to investigate for potential threats. You can choose to send basic or additional information about detected software. Additional information helps improve how Windows Defender works. It can include, for example, the location of detected items on your computer if harmful software has been removed. Windows Defender will automatically collect and send the information.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Defender</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4761-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-312</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6727" value-id="configure_ms_spynet_reporting_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6727"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--          Windows Error Reporting Setttings          -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_error_reporting_settings">
                        <title>Windows Error Reporting</title>
                        <description>Windows Error Reporting</description>
                        <Value id="disable_logging_var" operator="equals" type="number">
                              <title>Disable Logging</title>
                              <description>If this setting is enabled Windows Error Reporting events will not be logged to the system event log.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="disable_windows_error_reporting_var" operator="equals" type="number">
                              <title>Disable Windows Error Reporting</title>
                              <description>If this setting is enabled, Windows Error Reporting will not send any problem information to Microsoft. Additionally, solution information will not be available in the Problem Reports and Solutions control panel.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="display_error_notification_var" operator="equals" type="number">
                              <title>Display Error Notification</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Value id="do_not_send_additional_data_var" operator="equals" type="number">
                              <title>Do Not Send Additional Data</title>
                              <description>If this setting is enabled any additional data requests from Microsoft in response to a Windows Error Reporting event will be automatically declined without notice to the user.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="disable_logging" selected="false" weight="10.0">
                              <title>Disable Logging</title>
                              <description>If this setting is enabled Windows Error Reporting events will not be logged to the system event log.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Error Reporting</dc:source>
                              </reference>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-4915-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-959</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61141" value-id="disable_logging_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6114"/>
                              </check>
                        </Rule>
                        <Rule id="disable_windows_error_reporting" selected="false" weight="10.0">
                              <title>Disable Windows Error Reporting</title>
                              <description>If this setting is enabled, Windows Error Reporting will not send any problem information to Microsoft. Additionally, solution information will not be available in the Problem Reports and Solutions control panel.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Error Reporting</dc:source>
                              </reference>
                              <requires idref="SI-2"/>
                              <ident system="http://cce.mitre.org">CCE-5034-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-803</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61151" value-id="disable_windows_error_reporting_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6115"/>
                              </check>
                        </Rule>
                        <Rule id="display_error_notification" selected="false" weight="10.0">
                              <title>Display Error Notification</title>
                              <description>The "Display Error Notification" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Error Reporting</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4919-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-259</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:3366994" value-id="display_error_notification_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:3366994"/>
                              </check>
                        </Rule>
                        <Rule id="do_not_send_additional_data" selected="false" weight="10.0">
                              <title>Do Not Send Additional Data</title>
                              <description>If this setting is enabled any additional data requests from Microsoft in response to a Windows Error Reporting event will be automatically declined without notice to the user.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Error Reporting</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4089-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-798</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61171" value-id="do_not_send_additional_data_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6117"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Windows Explorer Setttings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_explorer_settings">
                        <title>Windows Explorer Settings</title>
                        <description>Windows Explorer</description>
                        <Value id="turn_off_heap_termination_corruption_var" operator="equals" type="number">
                              <title>Turn off Heap termination on corruption</title>
                              <description>Turn off Heap termination on corruption</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="turn_off_shell_protocol_protected_mode_var" operator="equals" type="number">
                              <title>Turn off shell protocol protected mode</title>
                              <description>Turn off shell protocol protected mode</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_heap_termination_corruption" selected="false" weight="10.0">
                              <title>Turn off Heap termination on corruption</title>
                              <description>Turn off Heap termination on corruption</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Explorer</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2962-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-384</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61181" value-id="turn_off_heap_termination_corruption_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6118"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_shell_protocol_protected_mode" selected="false" weight="10.0">
                              <title>Turn off shell protocol protected mode</title>
                              <description>Turn off shell protocol protected mode</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Explorer</dc:source>
                              </reference>
                              <requires idref="SI-3"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3125-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-480</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61191" value-id="turn_off_shell_protocol_protected_mode_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6119"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Windows Installer Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_installer_settings">
                        <title>Windows Installer Settings</title>
                        <description>Windows Installer</description>
                        <Value id="disable_ie_security_prompt_windows_installer_scripts_var" operator="equals" type="number">
                              <title>Disable IE security prompt for Windows Installer scripts</title>
                              <description>Disable IE security prompt for Windows Installer scripts</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="enable_user_control_over_installs_var" operator="equals" type="number">
                              <title>Enable user control over installs</title>
                              <description>Permits users to change installation options that typically are available only to system administrators. This setting bypasses some of the security features of Windows Installer.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="prohibit_non_administrators_install_signed_updates_var" operator="equals" type="number">
                              <title>Prohibit non-administrators from applying vendor signed updates</title>
                              <description>This setting controls the ability of non-administrators to install updates that have been digitally signed by the application vendor.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="disable_ie_security_prompt_windows_installer_scripts" selected="false" weight="10.0">
                              <title>Disable IE security prompt for Windows Installer scripts</title>
                              <description>Disable IE security prompt for Windows Installer scripts</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Installer</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4991-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-261</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61201" value-id="disable_ie_security_prompt_windows_installer_scripts_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6120"/>
                              </check>
                        </Rule>
                        <Rule id="enable_user_control_over_installs" selected="false" weight="10.0">
                              <title>Enable user control over installs</title>
                              <description>Permits users to change installation options that typically are available only to system administrators. This setting bypasses some of the security features of Windows Installer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Installer</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4629-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-415</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61211" value-id="enable_user_control_over_installs_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6121"/>
                              </check>
                        </Rule>
                        <Rule id="prohibit_non_administrators_install_signed_updates" selected="false" weight="10.0">
                              <title>Prohibit non-administrators from applying vendor signed updates</title>
                              <description>This setting controls the ability of non-administrators to install updates that have been digitally signed by the application vendor.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Installer</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-3398-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-612</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61221" value-id="prohibit_non_administrators_install_signed_updates_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6122"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Windows Logon Options Setttings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_logon_options_settings">
                        <title>Windows Logon Optionsr</title>
                        <description>Windows Logon Options</description>
                        <Value id="report_logon_server_not_available_during_user_logon_var" operator="equals" type="number">
                              <title>Report when logon server was not available during user logon</title>
                              <description>This policy controls whether the logged on user should be notified if the logon server could not be contacted during logon and he has been logged on using previously stored account information.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="report_logon_server_not_available_during_user_logon" selected="false" weight="10.0">
                              <title>Report Logon Server Not Available During User logon</title>
                              <description>This setting controls the ability of non-administrators to install updates that have been digitally signed by the application vendor.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Logon Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3341-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-392</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61231" value-id="report_logon_server_not_available_during_user_logon_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6123"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Windows Mail Setttings                -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="Windows_Mail">
                        <title>Windows Mail</title>
                        <description>Windows Mail</description>
                        <Value id="turn_off_communities_features_var" operator="equals" type="number">
                              <title>Turn off the communities features</title>
                              <description>Windows Mail will not check your newsgroup servers for Communities support.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="turn_off_windows_mail_app_var" operator="equals" type="number">
                              <title>Turn off Windows Mail application</title>
                              <description>Denies or allows access to the Windows Mail application. If you enable this setting, access to the Windows Mail application is denied. If you disable or do not configure this setting, access to the Windows Mail application is allowed.</description>
                              <value>0</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                              <value selector="SSLF-rev2-Laptop">0</value>
                              <value selector="SSLF-rev2-Desktop">0</value>
                              <value selector="FDCC-Laptop">0</value>
                              <value selector="FDCC-Desktop">0</value>
                        </Value>
                        <Rule id="turn_off_communities_features" selected="false" weight="10.0">
                              <title>Turn off the communities features</title>
                              <description>Windows Mail will not check your newsgroup servers for Communities support.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Mail</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2521-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-96</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61241" value-id="turn_off_communities_features_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6124"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_windows_mail_app" selected="false" weight="10.0">
                              <title>Turn off Windows Mail application</title>
                              <description>Denies or allows access to the Windows Mail application. If you enable this setting, access to the Windows Mail application is denied. If you disable or do not configure this setting, access to the Windows Mail application is allowed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Mail</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2525-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-331</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61251" value-id="turn_off_windows_mail_app_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6125"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!-- Windows Media Digital Rights Management Setttings    -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="Windows_Media_Digital_Rights_Management">
                        <title>Windows Media Digital Rights Management</title>
                        <description>Windows Media Digital Rights Management</description>
                        <Value id="prevent_windows_media_drm_internet_access_var" operator="equals" type="number">
                              <title>Prevent Windows Media DRM Internet Access</title>
                              <description>Prevents Windows Media Digital Rights Management (DRM) from accessing the Internet (or intranet). When enabled, Windows Media DRM is prevented from accessing the Internet (or intranet) for license acquisition and security upgrades.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="prevent_windows_media_drm_internet_access" selected="false" weight="10.0">
                              <title>Prevent Windows Media DRM Internet Access</title>
                              <description>Prevents Windows Media Digital Rights Management (DRM) from accessing the Internet (or intranet). When enabled, Windows Media DRM is prevented from accessing the Internet (or intranet) for license acquisition and security upgrades.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Media Digital Rights Management</dc:source>
                              </reference>
                              <requires idref="AC-4"/>
                              <ident system="http://cce.mitre.org">CCE-3486-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1089</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61261" value-id="prevent_windows_media_drm_internet_access_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6126"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Windows Media Player Setttings            -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_media_player_settings">
                        <title>Windows Media Player Settings</title>
                        <description>todo - description needed</description>
                        <Value id="do_not_show_first_use_dialog_boxes_var" type="number" operator="equals">
                              <title>do_not_show_first_use_dialog_boxes</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="prevent_automatic_updates_var" type="number" operator="equals">
                              <title>prevent_automatic_updates</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="do_not_show_first_use_dialog_boxes" selected="false" weight="10.0">
                              <title>Do Not Show First Use Dialog Boxes</title>
                              <description>The "Do Not Show First Use Dialog Boxes" setting for Windows Media Player should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Media Player</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4405-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1140</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:612261221" value-id="do_not_show_first_use_dialog_boxes_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:612261221"/>
                              </check>
                        </Rule>
                        <Rule id="prevent_automatic_updates" selected="false" weight="10.0">
                              <title>Prevent Automatic Updates</title>
                              <description>The "Disable Media Player for automatic updates" policy should be set correctly. </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Media Player</dc:source>
                              </reference>
                              <requires idref="SI-2"/>
                              <ident system="http://cce.mitre.org">CCE-4898-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-455</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:612261222" value-id="prevent_automatic_updates_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:612261222"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Windows Meeting Space Setttings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="Windows_Meeting_Space">
                        <title>Windows Meeting Space</title>
                        <description>Windows Meeting Space</description>
                        <Value id="turn_off_windows_meeting_space_var" operator="equals" type="number">
                              <title>Turn off Windows Meeting Space</title>
                              <description>Windows Meeting Space is a feature that enables quick, face-to-face collaboration for sharing programs and handouts and for passing notes. If you enable this setting, Windows Meeting Space will be turned off.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_windows_meeting_space" selected="false" weight="10.0">
                              <title>Turn off Windows Meeting Space</title>
                              <description>Windows Meeting Space is a feature that enables quick, face-to-face collaboration for sharing programs and handouts and for passing notes. If you enable this setting, Windows Meeting Space will be turned off.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Meeting Space</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2557-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-992</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61271" value-id="turn_off_windows_meeting_space_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6127"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Windows Messenger Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="Windows_Messenger">
                        <title>Windows Messenger</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Windows Messenger</description>
                        <Value id="do_not_allow_windows_messenger_to_be_run_var" operator="equals" type="string">
                              <title>Do not allow Windows Messenger to be run</title>
                              <description>Do not allow Windows Messenger to be run</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="do_not_automatically_start_windows_messenger_initially_var" type="number" operator="equals">
                              <title>do_not_automatically_start_windows_messenger_initially</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="do_not_allow_windows_messenger_to_be_run" selected="false" weight="10.0">
                              <title>Do not allow Windows Messenger to be run</title>
                              <description>Do not allow Windows Messenger to be run</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Messenger</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3316-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-729</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6601" value-id="do_not_allow_windows_messenger_to_be_run_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6601"/>
                              </check>
                        </Rule>
                        <Rule id="do_not_automatically_start_windows_messenger_initially" selected="false" weight="10.0">
                              <title>Do not automatically start Windows Messenger initially</title>
                              <description>The "Do Not Automatically Start Windows Messenger" policy should be set correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Messenger</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4797-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-309</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:612261224" value-id="do_not_automatically_start_windows_messenger_initially_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:612261224"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Windows SideBar Setttings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="Windows_SideBar">
                        <title>Windows SideBar</title>
                        <description>Windows SideBar</description>
                        <Value id="disable_unpacking_installation_gadgets_not_digitally_signed_var" operator="equals" type="number">
                              <title>Disable unpacking and installation of gadgets that are not digitally signed</title>
                              <description>Sidebar gadgets can be deployed as compressed files, either digitally signed or unsigned. If you enable this setting, Windows Sidebar will not extract any gadgets that have not been digitally signed. If you disable or do not configure this setting, Window</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="turn_off_user_installed_windows_sidebar_gidgets_var" operator="equals" type="number">
                              <title>Turn Off User Installed Windows Sidebar Gidgets</title>
                              <description>Turn Off User Installed Windows Sidebar Gidgets</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="disable_unpacking_installation_gadgets_not_digitally_signed" selected="false" weight="10.0">
                              <title>Disable unpacking and installation of gadgets that are not digitally signed</title>
                              <description>Sidebar gadgets can be deployed as compressed files, either digitally signed or unsigned. If you enable this setting, Windows Sidebar will not extract any gadgets that have not been digitally signed. If you disable or do not configure this setting, Window</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Sidebar</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3456-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-297</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61291" value-id="disable_unpacking_installation_gadgets_not_digitally_signed_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6129"/>
                              </check>
                        </Rule>
                        <Rule id="override_more_gadgets_lnk" selected="false" weight="10.0">
                              <title>Override the More Gadgets Lnk</title>
                              <description>Override the More Gadgets Lnk</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Sidebar</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3214-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-702</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6130"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_user_installed_windows_sidebar_gidgets" selected="false" weight="10.0">
                              <title>Turn Off User Installed Windows Sidebar Gidgets</title>
                              <description>Turn Off User Installed Windows Sidebar Gidgets</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Sidebar</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3500-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-644</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:61311" value-id="turn_off_user_installed_windows_sidebar_gidgets_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6131"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Local User Policy Group                                                                   -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="local_user_policy_group">
                  <title>Local User Policy Settings</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Control Panel Setttings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="control_panel_settings">
                        <title>Local User Policy: Control Panel</title>
                        <description>todo - description needed</description>
                        <Value id="password_protect_the_screen_saver_var" operator="equals" type="string">
                              <title>Password protect the screen saver</title>
                              <description>Password protect the screen saver</description>
                              <value>Enabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="screen_save_timeout_var" operator="equals" type="number">
                              <title>Screen Saver timeout</title>
                              <description>Specifies how much user idle time must elapse before the screen saver is launched. When configured, this idle time can be set from a minimum of 1 second to a maximum of 86,400 seconds, or 24 hours. If set to zero, the screen saver will not be started.</description>
                              <value>900</value>
                              <value selector="900_seconds">900</value>
                        </Value>
                        <Rule id="password_protect_the_screen_saver" selected="false" weight="10.0">
                              <title>Password protect the screen saver</title>
                              <description>Determines whether screen savers used on the computer are password protected. If you enable this setting, all screen savers are password protected. If you disable this setting, password protection cannot be set on any screen saver.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Control Panel\Display</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-4290-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-949</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6707" value-id="password_protect_the_screen_saver_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6707"/>
                              </check>
                        </Rule>
                        <Rule id="screen_save_timeout" selected="false" weight="10.0">
                              <title>Screen Saver timeout</title>
                              <description>Specifies how much user idle time must elapse before the screen saver is launched. When configured, this idle time can be set from a minimum of 1 second to a maximum of 86,400 seconds, or 24 hours. If set to zero, the screen saver will not be started.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Control Panel\Display</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3050-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-830</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6708" value-id="screen_save_timeout_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6708"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Power Management Setttings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="power-management-settings">
                        <title>Power Management settings</title>
                        <description>todo - description needed</description>
                        <Value id="prompt_for_password_on_resume_from_hibernate_suspend_var" operator="equals" type="string">
                              <title>Prompt for password on resume from hibernate / suspend</title>
                              <description>Prompt for password on resume from hibernate / suspend</description>
                              <value>Enabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="prompt_for_password_on_resume_from_hibernate_suspend" selected="false" weight="10.0">
                              <title>Prompt for password on resume from hibernate / suspend</title>
                              <description>This settings allows you to configure client computers to always lock when resuming from a hibernate or suspend. If you enable this setting, the client computer is locked when it is resumed from a suspend or hibernate state.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\System\Power Management</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-3169-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-509</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6714" value-id="prompt_for_password_on_resume_from_hibernate_suspend_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6714"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            Attachment Manager Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="attachment-manager-settigns">
                        <title>Attachment Manager Settings</title>
                        <description>todo - description needed</description>
                        <Value id="do_not_preserve_zone_information_in_file_attachments_var" operator="equals" type="string">
                              <title>Do not preserve zone information in file attachments</title>
                              <description>Do not preserve zone information in file attachments</description>
                              <value>Disabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="hide_mechanisms_to_remove_zone_information_var" operator="equals" type="string">
                              <title>Hide mechanisms to remove zone information</title>
                              <description>Hide mechanisms to remove zone information</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="notify_antivirus_programs_when_opening_attachments_var" operator="equals" type="string">
                              <title>Notify antivirus programs when opening attachments</title>
                              <description>Notify antivirus programs when opening attachments</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="do_not_preserve_zone_information_in_file_attachments" selected="false" weight="10.0">
                              <title>Do not preserve zone information in file attachments</title>
                              <description>This policy setting allows you to manage whether Windows marks file attachments with information about their zone of origin (i.e. restricted, Internet, intranet, local).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Windows Components\Attachment Manager</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3437-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-12</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6502" value-id="do_not_preserve_zone_information_in_file_attachments_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6502"/>
                              </check>
                        </Rule>
                        <Rule id="hide_mechanisms_to_remove_zone_information" selected="false" weight="10.0">
                              <title>Hide mechanisms to remove zone information</title>
                              <description>This policy setting allows you to manage whether users can manually remove the zone information from saved file attachments by clicking the Unblock button in the file’s property sheet or by using a check box in the security warning dialog.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Windows Components\Attachment Manager</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2979-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-58</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6503" value-id="hide_mechanisms_to_remove_zone_information_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6503"/>
                              </check>
                        </Rule>
                        <Rule id="notify_antivirus_programs_when_opening_attachments" selected="false" weight="10.0">
                              <title>Notify antivirus programs when opening attachments</title>
                              <description>This policy setting allows you to manage the behavior for notifying registered antivirus programs. If multiple programs are registered, they will all be notified.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Windows Components\Attachment Manager</dc:source>
                              </reference>
                              <requires idref="SI-3"/>
                              <ident system="http://cce.mitre.org">CCE-3300-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-372</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6504" value-id="notify_antivirus_programs_when_opening_attachments_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6504"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Network Sharing Setttings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="network-sharing-settings">
                        <title>Network Sharing Settings</title>
                        <description>todo - description needed</description>
                        <Value id="prevent_users_from_sharing_files_within_their_profile_var" operator="equals" type="string">
                              <title>Prevent users from sharing files within their profile</title>
                              <description>Prevent users from sharing files within their profile</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="prevent_users_from_sharing_files_within_their_profile" selected="false" weight="10.0">
                              <title>Prevent users from sharing files within their profile</title>
                              <description>By default users are allowed to share files within their profile to other users on their network once an administrator opts in the computer. An administrator can opt in the computer by using the sharing wizard to share a file within their profile.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Windows Components\Network Sharing</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-5070-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1144</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.vista:var:6715" value-id="prevent_users_from_sharing_files_within_their_profile_var"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:6715"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--          Internet Communication Setttings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="user_internet_communication_settings">
                        <title>Internet Communication settings</title>
                        <description>todo - description needed</description>
                        <Value id="turn_off_help_ratings_var" operator="equals" type="number">
                              <title>Turn off Help Ratings</title>
                              <description>Specifies whether users can provide ratings for Help content.</description>
                              <value>0</value>
                              <value selector="not_configured">-1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="turn_off_help_experience_improvement_program_var" operator="equals" type="number">
                              <title>Turn off Help Experience Improvement Program</title>
                              <description>Specifies whether users can participate in the Help Experience Improvement program.</description>
                              <value>0</value>
                              <value selector="not_configured">-1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_help_ratings" selected="false" weight="10.0">
                              <title>Turn off Help Ratings</title>
                              <description>Specifies whether users can provide ratings for Help content.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration | Administrative Templates | System | Internet Communication Management | Internet Communication settings</dc:source>
                              </reference>
                              <ident system="http://cce.mitre.org">CCE-4851-2</ident>
                              <ident system="http://cce.mitre.org">CCE-1109</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="turn_off_help_ratings_var" export-name="oval:gov.nist.fdcc.vista:var:8090"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8090"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_help_experience_improvement_program" selected="false" weight="10.0">
                              <title>Turn off Help Experience Improvement Program</title>
                              <description>Specifies whether users can participate in the Help Experience Improvement program.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration | Administrative Templates | System | Internet Communication Management | Internet Communication settings</dc:source>
                              </reference>
                              <ident system="http://cce.mitre.org">CCE-5239-9</ident>
                              <ident system="http://cce.mitre.org">CCE-174</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="turn_off_help_experience_improvement_program_var" export-name="oval:gov.nist.fdcc.vista:var:8091"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8091"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Audit Policy Group                                                                        -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="audit_policy_group">
                  <title>Audit Policy Group</title>
                  <description>Windows Vista give more control over individual audit policy through subcategories that were not available in earlier versions of Windows operating systems.</description>
                  <!--                                                                                          -->
                  <!-- NOTE - The individual audit policy subcategories that are available in Windows Vista are -->
                  <!-- not exposed in the interface of Group Policy tools.                                      -->
                  <!--                                                                                          -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            Account Management Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="account_management_settings">
                        <title>Account Management Settings</title>
                        <description>The Account Management audit category helps you track attempts to create new users or groups, rename users or groups, enable or disable user accounts, change account passwords, and enable auditing for Account Management events. If you enable this Audit policy setting, administrators can track events to detect malicious, accidental, and authorized creation of user and group accounts.</description>
                        <Value id="application-group-management_var" operator="pattern match" type="string">
                              <title>application-group-management</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="computer-account-management_var" operator="pattern match" type="string">
                              <title>computer-account-management</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="distribution-group-management_var" operator="pattern match" type="string">
                              <title>distribution-group-management</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="other-account-management-events_var" operator="pattern match" type="string">
                              <title>other-account-management-events</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="security-group-management_var" operator="pattern match" type="string">
                              <title>security-group-management</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="user-account-management_var" operator="pattern match" type="string">
                              <title>user-account-management</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="application-group-management" selected="false" weight="10.0">
                              <title>Application Group Management</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4938-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-801</ident>
                              <ident system="http://cce.mitre.org">CCE-4700-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1016</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="application-group-management_var" export-name="oval:gov.nist.fdcc.vista:var:8001"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8001"/>
                              </check>
                        </Rule>
                        <Rule id="computer-account-management" selected="false" weight="10.0">
                              <title>Computer Account Management</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4093-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1070</ident>
                              <ident system="http://cce.mitre.org">CCE-4228-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-840</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="computer-account-management_var" export-name="oval:gov.nist.fdcc.vista:var:8002"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8002"/>
                              </check>
                        </Rule>
                        <Rule id="distribution-group-management" selected="false" weight="10.0">
                              <title>Distribution Group Management</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4115-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-515</ident>
                              <ident system="http://cce.mitre.org">CCE-4140-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1048</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="distribution-group-management_var" export-name="oval:gov.nist.fdcc.vista:var:8003"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8003"/>
                              </check>
                        </Rule>
                        <Rule id="other-account-management-events" selected="false" weight="10.0">
                              <title>Other Account Management Events</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4916-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-206</ident>
                              <ident system="http://cce.mitre.org">CCE-4783-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1202</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="other-account-management-events_var" export-name="oval:gov.nist.fdcc.vista:var:8004"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8004"/>
                              </check>
                        </Rule>
                        <Rule id="security-group-management" selected="false" weight="10.0">
                              <title>Security Group Management</title>
                              <description>todo - description needed</description>
                              <requires idref="SI-6"/>
                              <ident system="http://cce.mitre.org">CCE-5048-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1118</ident>
                              <ident system="http://cce.mitre.org">CCE-4142-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-369</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="security-group-management_var" export-name="oval:gov.nist.fdcc.vista:var:8005"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8005"/>
                              </check>
                        </Rule>
                        <Rule id="user-account-management" selected="false" weight="10.0">
                              <title>User Account Management</title>
                              <description>todo - description needed</description>
                              <requires idref="AC-2"/>
                              <ident system="http://cce.mitre.org">CCE-4833-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1043</ident>
                              <ident system="http://cce.mitre.org">CCE-5097-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-924</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="user-account-management_var" export-name="oval:gov.nist.fdcc.vista:var:8006"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8006"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Detailed Tracking Setttings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="detailed_tracking_settings">
                        <title>Detailed Tracking Settings</title>
                        <description>The Detailed Tracking audit category determines whether to audit detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access. Enabling Audit process tracking will generate a large number of events, so it is typically set to No Auditing. However, this setting can provide a great benefit during an incident response from the detailed log of the processes started and the time when they were launched.</description>
                        <Value id="dpapi-activity_var" operator="pattern match" type="string">
                              <title>dpapi-activity</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="process-creation_var" operator="pattern match" type="string">
                              <title>process-creation</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="process-termination_var" operator="pattern match" type="string">
                              <title>process-termination</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="rpc-events_var" operator="pattern match" type="string">
                              <title>rpc-events_var</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="dpapi-activity" selected="false" weight="10.0">
                              <title>DPAPI Activity</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-13"/>
                              <ident system="http://cce.mitre.org">CCE-5000-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1413</ident>
                              <ident system="http://cce.mitre.org">CCE-4493-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-699</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="dpapi-activity_var" export-name="oval:gov.nist.fdcc.vista:var:8007"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8007"/>
                              </check>
                        </Rule>
                        <Rule id="process-creation" selected="false" weight="10.0">
                              <title>Process Creation</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4166-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-913</ident>
                              <ident system="http://cce.mitre.org">CCE-5094-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1079</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="process-creation_var" export-name="oval:gov.nist.fdcc.vista:var:8008"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8008"/>
                              </check>
                        </Rule>
                        <Rule id="process-termination" selected="false" weight="10.0">
                              <title>Process Termination</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4869-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-416</ident>
                              <ident system="http://cce.mitre.org">CCE-4363-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1250</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="process-termination_var" export-name="oval:gov.nist.fdcc.vista:var:8009"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8009"/>
                              </check>
                        </Rule>
                        <Rule id="rpc-events" selected="false" weight="10.0">
                              <title>RPC Events</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4891-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1219</ident>
                              <ident system="http://cce.mitre.org">CCE-4759-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1365</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="rpc-events_var" export-name="oval:gov.nist.fdcc.vista:var:8010"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8010"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                 DS Access Setttings                 -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="ds_access_settings">
                        <title>DS Access Settings</title>
                        <description>The DS Access audit category applies only to domain controllers.</description>
                        <Value id="detailed-directory-service-replication_var" operator="pattern match" type="string">
                              <title>detailed-directory-service-replication</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="directory-service-access_var" operator="pattern match" type="string">
                              <title>directory-service-access</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="directory-service-changes_var" operator="pattern match" type="string">
                              <title>directory-service-changes</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="directory-service-replication_var" operator="pattern match" type="string">
                              <title>directory-service-replication</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="detailed-directory-service-replication" selected="false" weight="10.0">
                              <title>Detailed Directory Service Replication</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5023-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-207</ident>
                              <ident system="http://cce.mitre.org">CCE-4658-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1186</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="detailed-directory-service-replication_var" export-name="oval:gov.nist.fdcc.vista:var:8011"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8011"/>
                              </check>
                        </Rule>
                        <Rule id="directory-service-access" selected="false" weight="10.0">
                              <title>Directory Service Access</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5028-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1199</ident>
                              <ident system="http://cce.mitre.org">CCE-4931-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-459</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="directory-service-access_var" export-name="oval:gov.nist.fdcc.vista:var:8012"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8012"/>
                              </check>
                        </Rule>
                        <Rule id="directory-service-changes" selected="false" weight="10.0">
                              <title>Directory Service Changes</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5067-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-317</ident>
                              <ident system="http://cce.mitre.org">CCE-4808-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-982</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="directory-service-changes_var" export-name="oval:gov.nist.fdcc.vista:var:8013"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8013"/>
                              </check>
                        </Rule>
                        <Rule id="directory-service-replication" selected="false" weight="10.0">
                              <title>Directory Service Replication</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5089-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-881</ident>
                              <ident system="http://cce.mitre.org">CCE-4176-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-247</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="directory-service-replication_var" export-name="oval:gov.nist.fdcc.vista:var:8014"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8014"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Logon Logoff Setttings                -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="logon_logoff_settings">
                        <title>Logon Logoff Settings</title>
                        <description>This audit category generates events that record the creation and destruction of logon sessions. These events occur on the accessed computer. For interactive logons, the generation of these events occurs on the computer that is logged on to. If a network logon takes place to access a share, these events generate on the computer that hosts the accessed resource.</description>
                        <Value id="account-lockout_var" operator="pattern match" type="string">
                              <title>account-lockout</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="ipsec-extended-mode_var" operator="pattern match" type="string">
                              <title>ipsec-extended-mode</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="ipsec-main-mode_var" operator="pattern match" type="string">
                              <title>ipsec-main-mode</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="ipsec-quick-mode_var" operator="pattern match" type="string">
                              <title>ipsec-quick-mode</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="logoff_var" operator="pattern match" type="string">
                              <title>logoff</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="logon_var" operator="pattern match" type="string">
                              <title>logon</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="other-logon-logoff-events_var" operator="pattern match" type="string">
                              <title>other-logon-logoff-events</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="special-logon_var" operator="pattern match" type="string">
                              <title>special-logon</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="account-lockout" selected="false" weight="10.0">
                              <title>Account Lockout</title>
                              <description>todo - description needed</description>
                              <requires idref="AC-7"/>
                              <ident system="http://cce.mitre.org">CCE-4342-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1264</ident>
                              <ident system="http://cce.mitre.org">CCE-4857-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1282</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="account-lockout_var" export-name="oval:gov.nist.fdcc.vista:var:8015"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8015"/>
                              </check>
                        </Rule>
                        <Rule id="ipsec-extended-mode" selected="false" weight="10.0">
                              <title>IPsec Extended Mode</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-8"/>
                              <ident system="http://cce.mitre.org">CCE-5011-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1028</ident>
                              <ident system="http://cce.mitre.org">CCE-4505-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-362</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="ipsec-extended-mode_var" export-name="oval:gov.nist.fdcc.vista:var:8016"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8016"/>
                              </check>
                        </Rule>
                        <Rule id="ipsec-main-mode" selected="false" weight="10.0">
                              <title>IPsec Main Mode</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-8"/>
                              <ident system="http://cce.mitre.org">CCE-5016-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1207</ident>
                              <ident system="http://cce.mitre.org">CCE-4650-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-351</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="ipsec-main-mode_var" export-name="oval:gov.nist.fdcc.vista:var:8017"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8017"/>
                              </check>
                        </Rule>
                        <Rule id="ipsec-quick-mode" selected="false" weight="10.0">
                              <title>IPsec Quick Mode</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-8"/>
                              <ident system="http://cce.mitre.org">CCE-5038-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1257</ident>
                              <ident system="http://cce.mitre.org">CCE-4928-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1274</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="ipsec-quick-mode_var" export-name="oval:gov.nist.fdcc.vista:var:8018"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8018"/>
                              </check>
                        </Rule>
                        <Rule id="logoff" selected="false" weight="10.0">
                              <title>Logoff</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4703-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-493</ident>
                              <ident system="http://cce.mitre.org">CCE-4183-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-996</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="logoff_var" export-name="oval:gov.nist.fdcc.vista:var:8019"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8019"/>
                              </check>
                        </Rule>
                        <Rule id="logon" selected="false" weight="10.0">
                              <title>Logon</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5018-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1284</ident>
                              <ident system="http://cce.mitre.org">CCE-4423-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1097</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="logon_var" export-name="oval:gov.nist.fdcc.vista:var:8020"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8020"/>
                              </check>
                        </Rule>
                        <Rule id="other-logon-logoff-events" selected="false" weight="10.0">
                              <title>Other Logon/Logoff Events</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5163-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-378</ident>
                              <ident system="http://cce.mitre.org">CCE-5066-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1208</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="other-logon-logoff-events_var" export-name="oval:gov.nist.fdcc.vista:var:8021"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8021"/>
                              </check>
                        </Rule>
                        <Rule id="special-logon" selected="false" weight="10.0">
                              <title>Special Logon</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4956-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-371</ident>
                              <ident system="http://cce.mitre.org">CCE-4824-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1038</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="special-logon_var" export-name="oval:gov.nist.fdcc.vista:var:8022"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8022"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Object Access Setttings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="object_access_settings">
                        <title>Object Access Settings</title>
                        <description>By itself, this policy setting will not cause auditing of any events. It determines whether to audit the event of a user who accesses an object—for example, a file, folder, registry key, or printer—that has a specified system access control list (SACL), effectively enabling auditing to take place.</description>
                        <Value id="application-generated_var" operator="pattern match" type="string">
                              <title>application-generated</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="certification-services_var" operator="pattern match" type="string">
                              <title>certification-services</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="file-share_var" operator="pattern match" type="string">
                              <title>file-share</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="file-system_var" operator="pattern match" type="string">
                              <title>file-system</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="filtering-platform-connection_var" operator="pattern match" type="string">
                              <title>filtering-platform-connection</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="filtering-platform-packet-drop_var" operator="pattern match" type="string">
                              <title>filtering-platform-packet-drop</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="handle-manipulation_var" operator="pattern match" type="string">
                              <title>handle-manipulation</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="kernel-object_var" operator="pattern match" type="string">
                              <title>kernel-object</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="other-object-access-events_var" operator="pattern match" type="string">
                              <title>other-object-access-events</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="registry_var" operator="pattern match" type="string">
                              <title>registry</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="sam_var" operator="pattern match" type="string">
                              <title>sam</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="application-generated" selected="false" weight="10.0">
                              <title>Application Generated</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5084-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1322</ident>
                              <ident system="http://cce.mitre.org">CCE-4829-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-379</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="application-generated_var" export-name="oval:gov.nist.fdcc.vista:var:8023"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8023"/>
                              </check>
                        </Rule>
                        <Rule id="certification-services" selected="false" weight="10.0">
                              <title>Certification Services</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4714-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1345</ident>
                              <ident system="http://cce.mitre.org">CCE-4868-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1261</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="certification-services_var" export-name="oval:gov.nist.fdcc.vista:var:8024"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8024"/>
                              </check>
                        </Rule>
                        <Rule id="file-share" selected="false" weight="10.0">
                              <title>File Share</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4200-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1372</ident>
                              <ident system="http://cce.mitre.org">CCE-5145-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1033</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="file-share_var" export-name="oval:gov.nist.fdcc.vista:var:8025"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8025"/>
                              </check>
                        </Rule>
                        <Rule id="file-system" selected="false" weight="10.0">
                              <title>File System</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4921-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1085</ident>
                              <ident system="http://cce.mitre.org">CCE-5039-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1340</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="file-system_var" export-name="oval:gov.nist.fdcc.vista:var:8026"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8026"/>
                              </check>
                        </Rule>
                        <Rule id="filtering-platform-connection" selected="false" weight="10.0">
                              <title>Filtering Platform Connection</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-4568-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-717</ident>
                              <ident system="http://cce.mitre.org">CCE-5079-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-744</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="filtering-platform-connection_var" export-name="oval:gov.nist.fdcc.vista:var:8027"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8027"/>
                              </check>
                        </Rule>
                        <Rule id="filtering-platform-packet-drop" selected="false" weight="10.0">
                              <title>Filtering Platform Packet Drop</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-4947-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-385</ident>
                              <ident system="http://cce.mitre.org">CCE-4335-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-589</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="filtering-platform-packet-drop_var" export-name="oval:gov.nist.fdcc.vista:var:8028"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8028"/>
                              </check>
                        </Rule>
                        <Rule id="handle-manipulation" selected="false" weight="10.0">
                              <title>Handle Manipulation</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-7"/>
                              <ident system="http://cce.mitre.org">CCE-4828-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1363</ident>
                              <ident system="http://cce.mitre.org">CCE-4965-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1244</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="handle-manipulation_var" export-name="oval:gov.nist.fdcc.vista:var:8029"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8029"/>
                              </check>
                        </Rule>
                        <Rule id="kernel-object" selected="false" weight="10.0">
                              <title>Kernel Object</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4996-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1288</ident>
                              <ident system="http://cce.mitre.org">CCE-4885-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1305</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="kernel-object_var" export-name="oval:gov.nist.fdcc.vista:var:8030"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8030"/>
                              </check>
                        </Rule>
                        <Rule id="other-object-access-events" selected="false" weight="10.0">
                              <title>Other Object Access Events</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5132-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-642</ident>
                              <ident system="http://cce.mitre.org">CCE-4691-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1026</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="other-object-access-events_var" export-name="oval:gov.nist.fdcc.vista:var:8031"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8031"/>
                              </check>
                        </Rule>
                        <Rule id="registry" selected="false" weight="10.0">
                              <title>Registry</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4594-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1138</ident>
                              <ident system="http://cce.mitre.org">CCE-5087-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1283</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="registry_var" export-name="oval:gov.nist.fdcc.vista:var:8032"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8032"/>
                              </check>
                        </Rule>
                        <Rule id="sam" selected="false" weight="10.0">
                              <title>SAM</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4616-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-446</ident>
                              <ident system="http://cce.mitre.org">CCE-4982-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-451</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="sam_var" export-name="oval:gov.nist.fdcc.vista:var:8033"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8033"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Policy Change Setttings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="policy_change_settings">
                        <title>Policy Change Settings</title>
                        <description>The Policy Change audit category determines whether to audit every incident of a change to user rights assignment policies, Windows Firewall policies, Trust policies, or changes to the Audit policy itself.</description>
                        <Value id="policy_change_audit_var" operator="pattern match" type="string">
                              <title>policy_change_audit</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="authentication-policy-change_var" operator="pattern match" type="string">
                              <title>authentication-policy-change</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="authorization-policy-change_var" operator="pattern match" type="string">
                              <title>authorization-policy-change</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="filtering-platform-policy-change_var" operator="pattern match" type="string">
                              <title>filtering-platform-policy-change</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="mpssvc-rule-level-policy-change_var" operator="pattern match" type="string">
                              <title>mpssvc-rule-level-policy-change</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="other-policy-change-events_var" operator="pattern match" type="string">
                              <title>other-policy-change-events</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="policy_change_audit" selected="false" weight="10.0">
                              <title>Audit Policy Change</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-4201-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1110</ident>
                              <ident system="http://cce.mitre.org">CCE-5137-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-991</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="policy_change_audit_var" export-name="oval:gov.nist.fdcc.vista:var:8034"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8034"/>
                              </check>
                        </Rule>
                        <Rule id="authentication-policy-change" selected="false" weight="10.0">
                              <title>Authentication Policy Change</title>
                              <description>todo - description needed</description>
                              <requires idref="IA-1"/>
                              <ident system="http://cce.mitre.org">CCE-4877-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-388</ident>
                              <ident system="http://cce.mitre.org">CCE-4516-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-180</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="authentication-policy-change_var" export-name="oval:gov.nist.fdcc.vista:var:8035"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8035"/>
                              </check>
                        </Rule>
                        <Rule id="authorization-policy-change" selected="false" weight="10.0">
                              <title>Authorization Policy Change</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5172-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-187</ident>
                              <ident system="http://cce.mitre.org">CCE-5058-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-448</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="authorization-policy-change_var" export-name="oval:gov.nist.fdcc.vista:var:8036"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8036"/>
                              </check>
                        </Rule>
                        <Rule id="filtering-platform-policy-change" selected="false" weight="10.0">
                              <title>Filtering Platform Policy Change</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5177-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1042</ident>
                              <ident system="http://cce.mitre.org">CCE-4939-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1112</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="filtering-platform-policy-change_var" export-name="oval:gov.nist.fdcc.vista:var:8037"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8037"/>
                              </check>
                        </Rule>
                        <Rule id="mpssvc-rule-level-policy-change" selected="false" weight="10.0">
                              <title>MPSSVC Rule-Level Policy Change</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5181-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-203</ident>
                              <ident system="http://cce.mitre.org">CCE-4204-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-879</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="mpssvc-rule-level-policy-change_var" export-name="oval:gov.nist.fdcc.vista:var:8038"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8038"/>
                              </check>
                        </Rule>
                        <Rule id="other-policy-change-events" selected="false" weight="10.0">
                              <title>Other Policy Change Events</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4479-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-205</ident>
                              <ident system="http://cce.mitre.org">CCE-4995-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-787</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="other-policy-change-events_var" export-name="oval:gov.nist.fdcc.vista:var:8039"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8039"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Privilege Use Setttings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="privilege_use_settings">
                        <title>Privilege Use Settings</title>
                        <description>The Privilege Use audit category determines whether to audit each instance of a user exercising a user right. If you configure this value to Success, an audit entry is generated each time that a user right is exercised successfully. If you configure this value to Failure, an audit entry is generated each time that a user right is exercised unsuccessfully. This policy setting can generate a very large number of event records.</description>
                        <Value id="non-sensitive-privilege-use_var" operator="pattern match" type="string">
                              <title>non-sensitive-privilege-use</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="other-privilege-use-events_var" operator="pattern match" type="string">
                              <title>other-privilege-use-events</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="sensitive-privilege-use_var" operator="pattern match" type="string">
                              <title>sensitive-privilege-use</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="non-sensitive-privilege-use" selected="false" weight="10.0">
                              <title>Non Sensitive Privilege Use</title>
                              <description>todo - description needed</description>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-5114-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-391</ident>
                              <ident system="http://cce.mitre.org">CCE-4990-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-404</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="non-sensitive-privilege-use_var" export-name="oval:gov.nist.fdcc.vista:var:8040"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8040"/>
                              </check>
                        </Rule>
                        <Rule id="other-privilege-use-events" selected="false" weight="10.0">
                              <title>Other Privilege Use Events</title>
                              <description>todo - description needed</description>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-5131-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1203</ident>
                              <ident system="http://cce.mitre.org">CCE-4205-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-406</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="other-privilege-use-events_var" export-name="oval:gov.nist.fdcc.vista:var:8041"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8041"/>
                              </check>
                        </Rule>
                        <Rule id="sensitive-privilege-use" selected="false" weight="10.0">
                              <title>Sensitive Privilege Use</title>
                              <description>todo - description needed</description>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4300-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-488</ident>
                              <ident system="http://cce.mitre.org">CCE-4734-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1258</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="sensitive-privilege-use_var" export-name="oval:gov.nist.fdcc.vista:var:8042"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8042"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                  System Setttings                   -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="system_settings">
                        <title>System Settings</title>
                        <description>The System audit category allows you to monitor system events that succeed and fail, and provides a record of these events that may help determine instances of unauthorized system access. System events include starting or shutting down computers in your environment, full event logs, or other security-related events that affect the entire system.</description>
                        <Value id="ipsec-driver_var" operator="pattern match" type="string">
                              <title>ipsec-driver</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="other-system-events_var" operator="pattern match" type="string">
                              <title>other-system-events</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="security-state-change_var" operator="pattern match" type="string">
                              <title>security-state-change</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="security-system-extension_var" operator="pattern match" type="string">
                              <title>security-system-extension</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="system-integrity_var" operator="pattern match" type="string">
                              <title>system-integrity</title>
                              <description>todo - description needed</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="ipsec-driver" selected="false" weight="10.0">
                              <title>IPsec Driver</title>
                              <description>todo - description needed</description>
                              <requires idref="SC-8"/>
                              <ident system="http://cce.mitre.org">CCE-4976-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1177</ident>
                              <ident system="http://cce.mitre.org">CCE-4879-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1314</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="ipsec-driver_var" export-name="oval:gov.nist.fdcc.vista:var:8043"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8043"/>
                              </check>
                        </Rule>
                        <Rule id="other-system-events" selected="false" weight="10.0">
                              <title>Other System Events</title>
                              <description>todo - description needed</description>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4998-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1332</ident>
                              <ident system="http://cce.mitre.org">CCE-4883-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-337</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="other-system-events_var" export-name="oval:gov.nist.fdcc.vista:var:8044"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8044"/>
                              </check>
                        </Rule>
                        <Rule id="security-state-change" selected="false" weight="10.0">
                              <title>Security State Change</title>
                              <description>todo - description needed</description>
                              <requires idref="SI-6"/>
                              <ident system="http://cce.mitre.org">CCE-4535-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1121</ident>
                              <ident system="http://cce.mitre.org">CCE-5157-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1139</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="security-state-change_var" export-name="oval:gov.nist.fdcc.vista:var:8045"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8045"/>
                              </check>
                        </Rule>
                        <Rule id="security-system-extension" selected="false" weight="10.0">
                              <title>Security System Extension</title>
                              <description>todo - description needed</description>
                              <requires idref="SI-6"/>
                              <ident system="http://cce.mitre.org">CCE-5170-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1270</ident>
                              <ident system="http://cce.mitre.org">CCE-4910-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1102</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="security-system-extension_var" export-name="oval:gov.nist.fdcc.vista:var:8046"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8046"/>
                              </check>
                        </Rule>
                        <Rule id="system-integrity" selected="false" weight="10.0">
                              <title>System Integrity</title>
                              <description>todo - description needed</description>
                              <requires idref="SI-7"/>
                              <ident system="http://cce.mitre.org">CCE-5047-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-856</ident>
                              <ident system="http://cce.mitre.org">CCE-4822-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-336</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="system-integrity_var" export-name="oval:gov.nist.fdcc.vista:var:8047"/>
                                    <check-content-ref href="fdcc-winvista-oval.xml" name="oval:gov.nist.fdcc.vista:def:8047"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  4 - Security Patches                                                                        *** -->
      <!-- **************************************************************************************************** -->
      <Group id="security_patches">
            <title>Security Patches</title>
            <description>Securing a given computer has become increasingly important. As such, it is essential to keep a host up to current patch levels to eliminate known vulnerabilities and weaknesses. In conjunction with antivirus software and a personal firewall, patching goes a long way to securing a host against outside attacks and exploitation. Microsoft provides two mechanisms for distributing security updates: Automatic Updates and Microsoft Update. In smaller environments, either method may be sufficient for keeping systems current with patches. Other environments typically have a software change management control process or a patch management program that tests patches before deploying them; distribution may then occur through local Windows Update Services (WUS) or Windows Server Update Services (WSUS) servers, which provide approved security patches for use by the Automatic Updates feature.</description>
            <Rule id="security_patches_up_to_date" selected="false" weight="10.0">
                  <title>Security Patches Up-To-Date</title>
                  <description>All known security patches have been installed.</description>
                  <requires idref="CM-6"/>
                  <requires idref="SI-2"/>
                  <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                        <check-content-ref href="http://nvd.nist.gov/scap/content/fdcc-winvista-patches.xml"/>
                        <check-content-ref href="fdcc-winvista-patches.xml"/>
                  </check>
            </Rule>
      </Group>
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
</Benchmark>
