<?xml version="1.0" encoding="UTF-8"?>
<Benchmark id="FDCC-Windows-XP" resolved="0" xml:lang="en"
      xmlns="http://checklists.nist.gov/xccdf/1.1"
      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      xmlns:cdf="http://checklists.nist.gov/xccdf/1.1"
      xmlns:cpe="http://cpe.mitre.org/dictionary/2.0"
      xmlns:dc="http://purl.org/dc/elements/1.1/"
      xmlns:xhtml="http://www.w3.org/1999/xhtml"
      xmlns:dsig="http://www.w3.org/2000/09/xmldsig#"
      xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.1 http://nvd.nist.gov/schema/xccdf-1.1.4.xsd
      http://cpe.mitre.org/dictionary/2.0 http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
      <status date="2009-04-08">accepted</status>
      <title>FDCC: Guidance for Securing Microsoft Windows XP Systems for IT Professional</title>
      <description>This benchmark has been created to assist IT professionals, in particular Windows XP system administrators and information security personnel, in effectively securing Windows XP Professional SP2 systems.</description>
      <notice id="terms-of-use" xml:lang="en">Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment. NIST assumes no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic. NIST would appreciate acknowledgement if the document and template are used.</notice>
      <front-matter xml:lang="en">todo - add text</front-matter>
      <rear-matter xml:lang="en"><xhtml:strong>Trademark Information</xhtml:strong><xhtml:br/><xhtml:br/>Microsoft, Windows, Windows XP, Windows Vista, Internet Explorer, and Windows Firewall are either registered trademarks or trademarks of Microsoft Corporation in the United States and other countries.<xhtml:br/><xhtml:br/>All other names are registered trademarks or trademarks of their respective companies.</rear-matter>
      <reference href="http://nvd.nist.gov/chklst_detail.cfm?config_id=76">
            <dc:publisher>National Institute of Standards and Technology</dc:publisher>
            <dc:identifier>SP 800-68</dc:identifier>
      </reference>
      <platform idref="cpe:/o:microsoft:windows_xp"/>
      <version>v1.2.1.0</version>
      <model system="urn:xccdf:scoring:default"/>
      <model system="urn:xccdf:scoring:flat"/>
      <!-- ==================================================================================================== -->
      <!-- ======================================  NIST 800-53 PROFILES  ====================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following profiles are used to turn on specific controls as definied in 800-53.  These controls  -->
      <!-- help determine the specific rules that will be evaluated as certain rules found in this document     -->
      <!-- require specific controls to be enabled.  This enable FISMA compliance to be achived by combining    -->
      <!-- guidance defined with high level recommendations made in 800-53.                                     -->
      <!--                                                                                                      -->
      <Profile id="low_800_53" abstract="true">
            <title>800-53 Low</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which all three security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of low. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="false"/>
            <select idref="AC-5" selected="false"/>
            <select idref="AC-6" selected="false"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="false"/>
            <select idref="AC-11" selected="false"/>
            <select idref="AC-12" selected="false"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="false"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="false"/>
            <select idref="AC-19" selected="false"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="false"/>
            <select idref="AU-7" selected="false"/>
            <select idref="AU-8" selected="false"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="false"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="false"/>
            <select idref="CM-4" selected="false"/>
            <select idref="CM-5" selected="false"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="false"/>
            <select idref="CP-4" selected="false"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="false"/>
            <select idref="CP-7" selected="false"/>
            <select idref="CP-8" selected="false"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="false"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="false"/>
            <select idref="IR-3" selected="false"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="false"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="false"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="false"/>
            <select idref="MP-4" selected="false"/>
            <select idref="MP-5" selected="false"/>
            <select idref="MP-6" selected="false"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="false"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="false"/>
            <select idref="PE-10" selected="false"/>
            <select idref="PE-11" selected="false"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="false"/>
            <select idref="PE-18" selected="false"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="false"/>
            <select idref="SC-3" selected="false"/>
            <select idref="SC-4" selected="false"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="false"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="false"/>
            <select idref="SC-9" selected="false"/>
            <select idref="SC-10" selected="false"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="false"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="false"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="false"/>
            <select idref="SC-18" selected="false"/>
            <select idref="SC-19" selected="false"/>
            <select idref="SC-20" selected="false"/>
            <select idref="SC-21" selected="false"/>
            <select idref="SC-22" selected="false"/>
            <select idref="SC-23" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="false"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="false"/>
            <select idref="SI-7" selected="false"/>
            <select idref="SI-8" selected="false"/>
            <select idref="SI-9" selected="false"/>
            <select idref="SI-10" selected="false"/>
            <select idref="SI-11" selected="false"/>
            <select idref="SI-12" selected="false"/>
      </Profile>
      <Profile id="moderate_800_53" abstract="true">
            <title>800-53 Moderate</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="false"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="false"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="false"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="false"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="false"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="high_800_53" abstract="true">
            <title>800-53 High</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="false"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="false"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="false"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="false"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="false"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="false"/>
            <select idref="SA-11" selected="false"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="false"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="false"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="all_800_53" abstract="true">
            <title>800-53 All</title>
            <description>This profile selects all the security controls that are recommended by Special Publication 800-53 for information systems. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="true"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="true"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="true"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="true"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="true"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="true"/>
            <select idref="SA-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="true"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="true"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- =========================================  FDCC PROFILES  ========================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- These profiles outline the specific guidance outlined by the Federal Desktop Core Configuration.     -->
      <!-- Each defines the set of XCCDF rules that are applicable for that guidance as well as specific values -->
      <!-- to be used when determining complinace.                                                              -->
      <!--                                                                                                      -->
      <Profile id="federal_desktop_core_configuration_version_1.2.1.0" extends="all_800_53">
            <title>Federal Desktop Core Configuration version 1.2.1.0</title>
            <description>This profile represents guidance outlined in Federal Desktop Core Configuration settings for desktop systems with Windows XP installed.</description>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  2 - FDCC Security Settings                                                            ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- Account Lockout Policy Settings -->
            <select idref="account_lockout_duration" selected="true"/>
            <select idref="account_lockout_threshold" selected="true"/>
            <select idref="account_lockout_reset" selected="true"/>
            <!--  Password Policy Settings  -->
            <select idref="password_history_enforcement" selected="true"/>
            <select idref="maximum_password_age" selected="true"/>
            <select idref="minimum_password_age" selected="true"/>
            <select idref="minimum_password_length" selected="true"/>
            <select idref="password_complexity" selected="true"/>
            <select idref="PasswordStorageReversibleEncryption" selected="true"/>
            <!--  Event Log Policy Settings  -->
            <select idref="maximum_application_log_size" selected="true"/>
            <select idref="maximum_security_log_size" selected="true"/>
            <select idref="maximum_system_log_size" selected="true"/>
            <select idref="retention_application_log" selected="true"/>
            <select idref="retention_security_log" selected="true"/>
            <select idref="retention_system_log" selected="true"/>
            <!--  File System Policy  -->
            <select idref="rcp.exePermissions" selected="true"/>
            <select idref="reg.exePermissions" selected="true"/>
            <select idref="regedt32.exePermissions" selected="true"/>
            <select idref="regedit.exePermissions" selected="true"/>
            <select idref="arp.exePermissions" selected="true"/>
            <select idref="at.exePermissions" selected="true"/>
            <select idref="attrib.exePermissions" selected="true"/>
            <select idref="cacls.exePermissions" selected="true"/>
            <select idref="debug.exePermissions" selected="true"/>
            <select idref="edlin.exePermissions" selected="true"/>
            <select idref="eventcreate.exePermissions" selected="true"/>
            <select idref="eventtriggers.exePermissions" selected="true"/>
            <select idref="mshta.exe-permissions" selected="true"/>
            <select idref="net.exePermissions" selected="true"/>
            <select idref="net1.exePermissions" selected="true"/>
            <select idref="netsh.exePermissions" selected="true"/>
            <select idref="regini.exePermissions" selected="true"/>
            <select idref="regsvr32.exePermissions" selected="true"/>
            <select idref="rexec.exePermissions" selected="true"/>
            <select idref="route.exePermissions" selected="true"/>
            <select idref="rsh.exePermissions" selected="true"/>
            <select idref="sc.exePermissions" selected="true"/>
            <select idref="secedit.exePermissions" selected="true"/>
            <select idref="subst.exePermissions" selected="true"/>
            <select idref="systeminfo.exePermissions" selected="true"/>
            <select idref="tftp.exePermissions" selected="true"/>
            <select idref="tlntsvr.exePermissions" selected="true"/>
            <!-- Audit Policy Settings -->
            <select idref="AuditAccountLogonEvents" selected="true"/>
            <select idref="AuditAccountManagement" selected="true"/>
            <select idref="AuditDirectoryServiceAccess" selected="true"/>
            <select idref="AuditLogonEvents" selected="true"/>
            <select idref="AuditObjectAccess" selected="true"/>
            <select idref="AuditPolicyChange" selected="true"/>
            <select idref="AuditPrivilegeUse" selected="true"/>
            <select idref="AuditProcessTracking" selected="true"/>
            <select idref="AuditSystemEvents" selected="true"/>
            <!-- Security Options Settings -->
            <!--<select idref="AdministratorAccountStatus" selected="true"/>-->
            <select idref="GuestAccountStatus" selected="true"/>
            <select idref="LimitBlankPassword" selected="true"/>
            <select idref="RenameAdministrator" selected="true"/>
            <select idref="RenameGuest" selected="true"/>
            <select idref="AuditAccessToGlobalObjects" selected="true"/>
            <select idref="AuditBackupAndRestorePrivilege" selected="true"/>
            <select idref="ShutDownIfUnableToLogSecurityAudits" selected="true"/>
            <select idref="AllowFormatEjectRemovableMedia" selected="true"/>
            <select idref="PreventUsersFromInstallingPrinterDrivers" selected="true"/>
            <select idref="RestrictCDROMAccess" selected="true"/>
            <select idref="RestrictFloppyAccess" selected="true"/>
            <select idref="UnsignedDriverInstallationBehavior" selected="true"/>
            <select idref="always_digitally_encrypt_secure_channel_data" selected="true"/>
            <select idref="WhenPossibleDigitallyEncryptSecureChannelData" selected="true"/>
            <select idref="WhenPossibleDigitallySignSecureChannelData" selected="true"/>
            <select idref="MachineAccountPasswordChanges" selected="true"/>
            <select idref="maximum_machine_account_password_age" selected="true"/>
            <select idref="require_strong_session_key" selected="true"/>
            <select idref="LastUserNameNotDisplayedForLogon" selected="true"/>
            <select idref="RequireCTRL_ALT_DEL" selected="true"/>
            <select idref="LogonMessageText" selected="true"/>
            <select idref="LogonMessageTitle" selected="true"/>
            <select idref="previous_logons_cached" selected="true"/>
            <select idref="password_expiration_prompt" selected="true"/>
            <select idref="domain_controller_authentication_required" selected="true"/>
            <select idref="smart_card_removal" selected="true"/>
            <select idref="client_always_sign_communications" selected="true"/>
            <select idref="SignCommunicationsIfServerAgrees" selected="true"/>
            <select idref="unencrypted_smb_passwords" selected="true"/>
            <select idref="session_timeout" selected="true"/>
            <select idref="server_always_sign_communications" selected="true"/>
            <select idref="SignCommunicationsIfClientAgrees" selected="true"/>
            <select idref="LogonTimeExpiration" selected="true"/>
            <select idref="AutomaticLogonDisabled" selected="true"/>
            <select idref="IPSourceRoutingProtectionLevel" selected="true"/>
            <select idref="AutomaticDetectionOfDeadGWs" selected="true"/>
            <select idref="AllowICMPRedirectsDisabled" selected="true"/>
            <select idref="KeepAliveTime" selected="true"/>
            <select idref="DisableAutorunForAllDrives" selected="true"/>
            <select idref="NameReleaseRequests" selected="true"/>
            <select idref="Disable8Dot3NameCreation" selected="true"/>
            <select idref="RouterDiscovery" selected="true"/>
            <select idref="SafeDLLSearchMode" selected="true"/>
            <select idref="ScreenSaverGracePeriod" selected="true"/>
            <select idref="SynAttackProtectionLevel" selected="true"/>
            <select idref="TCPConnectionResponses" selected="true"/>
            <select idref="TCPMaxDataRetransmissions" selected="true"/>
            <select idref="EventLogThresholdWarning" selected="true"/>
            <select idref="anonymous_sid_name_translation" selected="true"/>
            <select idref="AnonymousEnumerationOfAccounts" selected="true"/>
            <select idref="AnonymousEnumerationOfAccountsAndShares" selected="true"/>
            <select idref="CredentialsStorage" selected="true"/>
            <select idref="AnonymousUsersPermissions" selected="true"/>
            <select idref="AnonymouslyAccessedNamedPipes" selected="true"/>
            <select idref="RemotelyAccessibleRegistryPaths" selected="true"/>
            <select idref="AnonymouslyAccessedShares" selected="true"/>
            <select idref="LocalAccountsSecurityModel" selected="true"/>
            <select idref="LANManagerHashStorage" selected="true"/>
            <select idref="ForceLogoff" selected="true"/>
            <select idref="LANManagerAuthenticationLevel-RefuseLM_NTLM" selected="true"/>
            <select idref="LDAPClientSigningRequirements" selected="true"/>
            <select idref="ntlm_ssp_based_client_session_security" selected="true"/>
            <select idref="ntlm_ssp_based_servers_session_security" selected="true"/>
            <select idref="RecoveryConsoleAutoLogon" selected="true"/>
            <select idref="RecoveryConsoleFullSystemAccess" selected="true"/>
            <select idref="shutdown_without_logon" selected="true"/>
            <select idref="ClearPagefileOnShutdown" selected="true"/>
            <select idref="FIPSCompliantEncryption" selected="true"/>
            <select idref="AdministratorsGroupObjectCreatorOwner" selected="true"/>
            <select idref="RequireCaseInsensitivity" selected="true"/>
            <select idref="InternalSystemObjectsPermissions" selected="true"/>
            <!-- User Rights Assignments -->
            <select idref="AccessComputerFromNetwork_Administrators" selected="true"/>
            <select idref="ActAsPartOfOperatingSystem_None" selected="true"/>
            <select idref="AdjustMemoryQuotas_Administrators-LOCAL_SERVICE-NETWORK_SERVICE" selected="true"/>
            <select idref="AllowLogOnThroughTerminalServices_Administrators-RemoteDesktopUsers" selected="true"/>
            <select idref="BackUpFilesAndDirectories_Administrators" selected="true"/>
            <select idref="BypassTraverseChecking_Administrators_Users" selected="true"/>
            <select idref="ChangeSystemTime_Administrators" selected="true"/>
            <select idref="CreatePagefile_Administrators" selected="true"/>
            <select idref="CreateTokenObject_None" selected="true"/>
            <select idref="Create-Global-Objects_Administrators-SERVICE-LocalService-NetworkService" selected="true"/>
            <select idref="CreatePermanentSharedObjects_None" selected="true"/>
            <select idref="DebugPrograms_Administrators" selected="true"/>
            <select idref="DenyAccessFromNetwork-Guests-SUPPORT_388945a0" selected="true"/>
            <select idref="DenyLogonAsBatchJob-Guests-SUPPORT_388945a0" selected="true"/>
            <select idref="deny_logon_as_service_none" selected="true"/>
            <select idref="DenyLogonLocally-Guests-SUPPORT_388945a0" selected="true"/>
            <select idref="DenyLogonThroughTerminalServices-Guests" selected="true"/>
            <select idref="ShutdownFromRemoteSystem_Administrators" selected="true"/>
            <select idref="GenerateSecurityAudits-LOCAL_SERVICE-NETWORK_SERVICE" selected="true"/>
            <select idref="ImpersonateClientAfterAuthentication-SERVICE_Administrators" selected="true"/>
            <select idref="IncreaseSchedulingPriority_Administrators" selected="true"/>
            <select idref="LoadAndUnloadDeviceDrivers_Administrators" selected="true"/>
            <select idref="LockPagesInMemory_None" selected="true"/>
            <select idref="LogOnAsBatchJob_None" selected="true"/>
            <select idref="LogOnAsService-LOGON_SERVICE-NETWORK_SERVICE" selected="true"/>
            <select idref="LogOnLocally_Administrators_Users" selected="true"/>
            <select idref="ManageAuditingAndSecurityLog_Administrators" selected="true"/>
            <select idref="ModifyFirmwareEnvironmentValues_Administrators" selected="true"/>
            <select idref="PerformVolumeMaintenanceTasks_Administrators" selected="true"/>
            <select idref="ProfileSingleProcess_Administrators" selected="true"/>
            <select idref="ProfileSystemPerformance_Administrators" selected="true"/>
            <select idref="RemoveComputerFromDockingStation_Administrators_Users" selected="true"/>
            <select idref="ReplaceProcessLevelToken-LOGON_SERVICE-NETWORK_SERVICE" selected="true"/>
            <select idref="RestoreFilesAndDirectories_Administrators" selected="true"/>
            <select idref="ShutDownSystem_Administrators_Users" selected="true"/>
            <select idref="SynchronizeDirectoryServiceData_None" selected="true"/>
            <select idref="TakeOwnershipOfFiles_Administrators" selected="true"/>
            <!-- System Services Group -->
            <select idref="AlerterService" selected="true"/>
            <select idref="BITSService" selected="true"/>
            <select idref="ClipBookService" selected="true"/>
            <select idref="ComputerBrowserService" selected="true"/>
            <select idref="ErrorReportingService" selected="true"/>
            <select idref="FastUserSwitchingCompatibilityService" selected="true"/>
            <select idref="FaxService" selected="true"/>
            <select idref="FTPPublishingService" selected="true"/>
            <select idref="IndexingService" selected="true"/>
            <select idref="MessengerService" selected="true"/>
            <select idref="NetMeetingRemoteDesktopSharingService" selected="true"/>
            <select idref="NetworkDDEService" selected="true"/>
            <select idref="NetworkDDEdsdmService" selected="true"/>
            <select idref="RoutingAndRemoteAccessService" selected="true"/>
            <select idref="SSDPService" selected="true"/>
            <select idref="TelnetService" selected="true"/>
            <select idref="TerminalServicesService" selected="true"/>
            <select idref="UniversalPlugAndPlayDeviceHostService" selected="true"/>
            <select idref="WebClientService" selected="true"/>
            <select idref="Wireless-Zero-Configuration" selected="true"/>
            <select idref="WMIPerformanceAdapter" selected="true"/>
            <select idref="WWWPublishingServicesService" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  3 - FDCC Other Settings                                                               ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <select idref="turn_off_microsoft_peer_to_peer_networking_services" selected="true"/>
            <select idref="prohibit_installation_network_bridge" selected="true"/>
            <select idref="prohibit_internet_connection_firewall" selected="true"/>
            <select idref="prohibit_internet_connection_sharing" selected="true"/>
            <select idref="display_error_notification" selected="true"/>
            <select idref="registry_policy_processing" selected="true"/>
            <select idref="Turn-Off-Automatic-Root-Certificates-Update" selected="true"/>
            <select idref="Turn-off-downloading-of-print-drivers-over-HTTP" selected="true"/>
            <select idref="Turn-Off-Event-Views-Events.asp-Links" selected="true"/>
            <select idref="Turn-Off-Internet-Connection-Wizard-if-URL-Connection-is-Referring-to-Microsoft.com" selected="true"/>
            <select idref="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards" selected="true"/>
            <select idref="Turn-Off-Internet-File-Association-Service" selected="true"/>
            <select idref="Turn-off-printing-over-HTTP" selected="true"/>
            <select idref="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com" selected="true"/>
            <select idref="Turn-off-Search-Companion-content-file-updates" selected="true"/>
            <select idref="Turn-Off-the-Order-Prints-Picture-Task" selected="true"/>
            <select idref="Turn-off-the-Publish-to-Web-task-for-files-and-folders" selected="true"/>
            <select idref="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program" selected="true"/>
            <select idref="turn_off_windows_error_reporting" selected="true"/>
            <select idref="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads" selected="true"/>
            <select idref="Turn-Off-Windows-Movie-Maker-Online-Web-Links" selected="true"/>
            <select idref="turn_off_windows_movie_maker_saving_to_online_video_hosting_provider" selected="true"/>
            <select idref="Turn-off-Windows-Update-device-driver-searching" selected="true"/>
            <select idref="Always-Use-Classic-Logon" selected="true"/>
            <select idref="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon" selected="true"/>
            <select idref="offer_remote_assistance" selected="true"/>
            <select idref="solicited_remote_assistance" selected="true"/>
            <select idref="Restrictions-for-Unauthenticated-RPC-clients" selected="true"/>
            <select idref="rpc_endpoint_mapper_client_authentication" selected="true"/>
            <select idref="Prevent-IIS-Installation" selected="true"/>
            <select idref="disable_remote_desktop_sharing" selected="true"/>
            <select idref="do_not_allow_passwords_to_be_saved" selected="true"/>
            <select idref="set-client-connection-encryption-level" selected="true"/>
            <select idref="set-timelimit-for-disconnected-sessions" selected="true"/>
            <select idref="set-timelimit-for-active-but-idle-TerminalServices-sessions" selected="true"/>
            <select idref="turn_off_shell_protocol_protected_mode" selected="true"/>
            <select idref="Disable-IE-security-prompt-Windows-Installer-scripts" selected="true"/>
            <select idref="Enable-User-Control-over-installs" selected="true"/>
            <select idref="prohibit_non_administrators_install_signed_updates" selected="true"/>
            <select idref="do_not_show_first_use_dialog_boxes" selected="true"/>
            <select idref="prevent_automatic_updates" selected="true"/>
            <select idref="Do-not-allow-Windows-Messenger-to-be-run" selected="true"/>
            <select idref="do_not_automatically_start_windows_messenger_initially" selected="true"/>
            <select idref="password_protect_the_screen_saver" selected="true"/>
            <select idref="Screen-Saver-timeout" selected="true"/>
            <select idref="prompt_for_password_on_resume_from_hibernate_suspend" selected="true"/>
            <select idref="do_not_preserve_zone_information_in_file_attachments" selected="true"/>
            <select idref="hide_mechanisms_to_remove_zone_information" selected="true"/>
            <select idref="notify_antivirus_programs_when_opening_attachments" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  4 - Fully Patched System                                                              ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <select idref="security_patches_up_to_date" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <refine-value idref="account_lockout_duration_var" selector="900_seconds"/>
            <refine-value idref="account_lockout_threshold_var" selector="5_attempts"/>
            <refine-value idref="account_lockout_reset_var" selector="900_seconds"/>

            <!-- Enforce user logon restrictions -->
            <!-- Maximum lifetime for service ticket -->
            <!-- Maximum lifetime for user ticket -->
            <!-- Maximum lifetime for user ticket renewal -->
            <!-- Maximum tolerance for computer clock synchronization -->

            <refine-value idref="password_history_enforcement_var" selector="24_passwords"/>
            <refine-value idref="maximum_password_age_var" selector="5184000_seconds"/>
            <refine-value idref="minimum_password_age_var" selector="86400_seconds"/>
            <refine-value idref="minimum_password_length_var" selector="12_characters"/>
            <refine-value idref="password_complexity_var" selector="enabled"/>
            <refine-value idref="PasswordStorageReversibleEncryption_var" selector="disabled"/>

            <refine-value idref="maximum_application_log_size_var" selector="16777216_bytes"/>
            <refine-value idref="maximum_security_log_size_var" selector="83886080_bytes"/>
            <refine-value idref="maximum_system_log_size_var" selector="16777216_bytes"/>
            <refine-value idref="prevent_guest_application_log_access_var" selector="enabled"/>
            <refine-value idref="prevent_guest_security_log_access_var" selector="enabled"/>
            <refine-value idref="prevent_guest_system_log_access_var" selector="enabled"/>
            <refine-value idref="retention_application_log_var" selector="overwrite_as_needed"/>
            <refine-value idref="retention_security_log_var" selector="overwrite_as_needed"/>
            <refine-value idref="retention_system_log_var" selector="overwrite_as_needed"/>

            <!-- File System Group n/a -->

            <refine-value idref="AuditAccountLogonEvents_var" selector="success_failure"/>
            <refine-value idref="AuditAccountManagement_var" selector="success_failure"/>
            <refine-value idref="AuditDirectoryServiceAccess_var" selector="failure"/>
            <refine-value idref="AuditLogonEvents_var" selector="success_failure"/>
            <refine-value idref="AuditObjectAccess_var" selector="failure"/>
            <refine-value idref="AuditPolicyChange_var" selector="success"/>
            <refine-value idref="AuditPrivilegeUse_var" selector="failure"/>
            <refine-value idref="AuditProcessTracking_var" selector="none"/>
            <refine-value idref="AuditSystemEvents_var" selector="success"/>
            <refine-value idref="GuestAccountStatus_var" selector="disabled"/>
            <refine-value idref="LimitBlankPassword_var" selector="enabled"/>
            <refine-value idref="AuditBackupAndRestorePrivilege_var" selector="disabled"/>
            <refine-value idref="ShutDownIfUnableToLogSecurityAudits_var" selector="disabled"/>
            <refine-value idref="AllowFormatEjectRemovableMedia_var" selector="administrator_and_interactiveuser_only"/>
            <refine-value idref="PreventUsersFromInstallingPrinterDrivers_var" selector="disabled"/>
            <refine-value idref="RestrictCDROMAccess_var" selector="disabled"/>
            <refine-value idref="RestrictFloppyAccess_var" selector="not_restricted"/>
            <refine-value idref="UnsignedDriverInstallationWarning_var" selector="block"/>
            <refine-value idref="maximum_machine_account_password_age_var" selector="30_days"/>
            <refine-value idref="require_strong_session_key_var" selector="enabled"/>
            <refine-value idref="previous_logons_cached_var" selector="2_cached"/>
            <refine-value idref="password_expiration_prompt_var" selector="14_days"/>
            <refine-value idref="domain_controller_authentication_required_var" selector="disabled"/>
            <refine-value idref="smart_card_removal_var" selector="lock_workstation"/>
            <refine-value idref="client_always_sign_communications_var" selector="enabled"/>
            <refine-value idref="unencrypted_smb_passwords_var" selector="disabled"/>
            <refine-value idref="session_timeout_var" selector="15_minutes"/>
            <refine-value idref="LogonTimeExpiration_var" selector="enabled"/>
            <refine-value idref="ntlm_ssp_based_client_session_security_var" selector="537395248"/>
            <refine-value idref="ntlm_ssp_based_servers_session_security_var" selector="537395248"/>
            <refine-value idref="AutomaticLogonDisabled_var" selector="disabled"/>
            <refine-value idref="IPSourceRoutingProtectionLevel_var" selector="disabled_completely"/>
            <refine-value idref="AutomaticDetectionOfDeadGWs_var" selector="disabled"/>
            <refine-value idref="AllowICMPRedirectsDisabled_var" selector="disabled"/>
            <refine-value idref="KeepAliveTime_var" selector="300000_seconds"/>
            <refine-value idref="NameReleaseRequests_var" selector="enabled"/>
            <refine-value idref="Disable8Dot3NameCreation_var" selector="disabled"/>
            <refine-value idref="RouterDiscovery_var" selector="disabled"/>
            <refine-value idref="ScreenSaverGracePeriod_var" selector="5_seconds"/>
            <refine-value idref="SynAttackProtectionLevel_var" selector="enabled"/>
            <refine-value idref="TCPMaxDataRetransmissions_var" selector="3_retransmissions"/>
            <refine-value idref="EventLogThresholdWarning_var" selector="90_percent"/>
            <refine-value idref="anonymous_sid_name_translation_var" selector="disabled"/>
            <refine-value idref="always_digitally_encrypt_secure_channel_data_var" selector="enabled"/>
            <refine-value idref="server_always_sign_communications_var" selector="enabled"/>
            <refine-value idref="shutdown_without_logon_var" selector="enabled"/>

            <!-- User Rights Assignments n/a -->

            <refine-value idref="AlerterService_var" selector="disabled"/>
            <refine-value idref="BITSService_var" selector="manual"/>
            <refine-value idref="ClipBookService_var" selector="disabled"/>
            <refine-value idref="ComputerBrowserService_var" selector="disabled"/>
            <refine-value idref="ErrorReportingService_var" selector="disabled"/>
            <refine-value idref="FastUserSwitchingCompatibilityService_var" selector="disabled"/>
            <refine-value idref="FaxService_var" selector="disabled"/>
            <refine-value idref="FTPPublishingService_var" selector="disabled"/>
            <refine-value idref="IndexingService_var" selector="disabled"/>
            <refine-value idref="MessengerService_var" selector="disabled"/>
            <refine-value idref="NetMeetingRemoteDesktopSharingService_var" selector="disabled"/>
            <refine-value idref="NetworkDDEService_var" selector="disabled"/>
            <refine-value idref="NetworkDDEdsdmService_var" selector="disabled"/>
            <refine-value idref="RoutingAndRemoteAccessService_var" selector="disabled"/>
            <refine-value idref="SSDPService_var" selector="disabled"/>
            <refine-value idref="TelnetService_var" selector="disabled"/>
            <refine-value idref="TerminalServicesService_var" selector="manual"/>
            <refine-value idref="UniversalPlugAndPlayDeviceHostService_var" selector="disabled"/>
            <refine-value idref="WebClientService_var" selector="disabled"/>
            <refine-value idref="Wireless-Zero-Configuration_var" selector="disabled"/>
            <refine-value idref="WMIPerformanceAdapter_var" selector="manual"/>
            <refine-value idref="WWWPublishingServicesService_var" selector="disabled"/>

            <refine-value idref="turn_off_microsoft_peer_to_peer_networking_services_var" selector="enabled"/>
            <refine-value idref="prohibit_installation_network_bridge_var" selector="enabled"/>
            <refine-value idref="prohibit_internet_connection_firewall_var" selector="enabled"/>
            <refine-value idref="prohibit_internet_connection_sharing_var" selector="enabled"/>
            <refine-value idref="display_error_notification_var" selector="disabled"/>
            <refine-value idref="registry_policy_processing_var" selector="enabled:nogpolistchanges"/>

            <refine-value idref="Turn-Off-Automatic-Root-Certificates-Update_var" selector="enabled"/>
            <refine-value idref="Turn-off-downloading-of-print-drivers-over-HTTP_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Event-Views-Events.asp-Links_var" selector="disabled"/>
            <refine-value idref="Turn-Off-Internet-Connection-Wizard-if-URL-Connection-is-Referring-to-Microsoft.com_var" selector="enabled"/>
            <refine-value idref="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Internet-File-Association-Service_var" selector="enabled"/>
            <refine-value idref="Turn-off-printing-over-HTTP_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com_var" selector="enabled"/>
            <refine-value idref="Turn-off-Search-Companion-content-file-updates_var" selector="enabled"/>
            <refine-value idref="Turn-Off-the-Order-Prints-Picture-Task_var" selector="enabled"/>
            <refine-value idref="Turn-off-the-Publish-to-Web-task-for-files-and-folders_var" selector="enabled"/>
            <refine-value idref="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program_var" selector="enabled"/>
            <refine-value idref="turn_off_windows_error_reporting_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads_var" selector="enabled"/>
            <refine-value idref="Turn-Off-Windows-Movie-Maker-Online-Web-Links_var" selector="enabled"/>
            <refine-value idref="turn_off_windows_movie_maker_saving_to_online_video_hosting_provider_var" selector="enabled"/>
            <refine-value idref="Turn-off-Windows-Update-device-driver-searching_var" selector="enabled"/>

            <refine-value idref="Always-Use-Classic-Logon_var" selector="enabled"/>
            <refine-value idref="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon_var" selector="enabled"/>
            <refine-value idref="offer_remote_assistance_var" selector="disabled"/>
            <refine-value idref="solicited_remote_assistance_var" selector="disabled"/>
            <refine-value idref="Restrictions-for-Unauthenticated-RPC-clients_var" selector="enabled:authenticated"/>
            <refine-value idref="rpc_endpoint_mapper_client_authentication_var" selector="enabled"/>
            <refine-value idref="Prevent-IIS-Installation_var" selector="enabled"/>
            <refine-value idref="disable_remote_desktop_sharing_var" selector="enabled"/>
            <refine-value idref="do_not_allow_passwords_to_be_saved_var" selector="enabled"/>
            <refine-value idref="set-client-connection-encryption-level_var" selector="enabled:high_level"/>
            <refine-value idref="set-timelimit-for-disconnected-sessions_var" selector="60_seconds"/>
            <refine-value idref="set-timelimit-for-active-but-idle-TerminalServices-sessions_var" selector="900_seconds"/>
            <refine-value idref="turn_off_shell_protocol_protected_mode_var" selector="disabled"/>
            <refine-value idref="Disable-IE-security-prompt-Windows-Installer-scripts_var" selector="disabled"/>
            <refine-value idref="Enable-User-Control-over-installs_var" selector="disabled"/>
            <refine-value idref="prohibit_non_administrators_install_signed_updates_var" selector="enabled"/>
            <refine-value idref="do_not_show_first_use_dialog_boxes_var" selector="enabled"/>
            <refine-value idref="prevent_automatic_updates_var" selector="enabled"/>
            <refine-value idref="Do-not-allow-Windows-Messenger-to-be-run_var" selector="enabled"/>
            <refine-value idref="do_not_automatically_start_windows_messenger_initially_var" selector="enabled"/>
            <refine-value idref="password_protect_the_screen_saver_var" selector="enabled"/>
            <refine-value idref="Screen-Saver-timeout_var" selector="enabled:900_seconds"/>
            <refine-value idref="prompt_for_password_on_resume_from_hibernate_suspend_var" selector="enabled"/>
            <refine-value idref="do_not_preserve_zone_information_in_file_attachments_var" selector="disabled"/>
            <refine-value idref="hide_mechanisms_to_remove_zone_information_var" selector="enabled"/>
            <refine-value idref="notify_antivirus_programs_when_opening_attachments_var" selector="enabled"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- ================================  NIST SP 800-53 (FISMA) Controls  ================================= -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following group contains all the different controls defined by NIST SP 800-53.  These controls   -->
      <!-- are hidden as they should not appear in any document generated from this file pertaining to specific -->
      <!-- security guidance.  These controls are used by the 800-53 profiles to enable high-level guidance     -->
      <!-- that is then passed down to the FDCC profiles and used to enable specific XCCDF Rules.               -->
      <!--                                                                                                      -->
      <Group id="nist_sp80053_controls" hidden="true">
            <title>NIST SP 800-53 Controls</title>
            <Group id="access_control_checks" hidden="true">
                  <title>Applicable 800-53 Access Control Checks</title>
                  <Group id="AC-1" hidden="true">
                        <title>Access Control Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 11.1.1, 11.4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 15, 16</reference>
                        <reference>DOD 8500.2: ECAN-1, ECPA-1, PRAS-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.1.a(1)(b)</reference>
                  </Group>
                  <Group id="AC-2" hidden="true">
                        <title>Account Management</title>
                        <reference>ISO/IEC 17799: 6.2.2, 6.2.3, 8.3.3, 11.2.1, 11.2.2, 11.2.4, 11.7.2</reference>
                        <reference>NIST 800-26: 6.1.8, 15.1.1, 15.1.4, 15.1.15, 15.1.8, 15.2.2, 16.1.3, 16.1.5, 16.2.12</reference>
                        <reference>GAO FISCAM: AC-2.1 AC-2.2, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAAC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)</reference>
                  </Group>
                  <Group id="AC-3" hidden="true">
                        <title>Access Enforcement</title>
                        <reference>ISO/IEC 17799: 11.2.4, 11.4.5</reference>
                        <reference>NIST 800-26: 10.1.2, 15.1.1, 16.1.1, 16.1.2, 16.1.3, 16.1.7, 16.1.9, 16.2.1, 16.2.7, 16.2.10, 16.2.11, 16.2.15</reference>
                        <reference>GAO FISCAM: AC-2, AC-3.2</reference>
                        <reference>DOD 8500.2: DCFA-1, ECAN-1, EBRU-1, PRNK-1, ECCD-1, ECSD-2</reference>
                        <reference>DCID 6/3: Discretionary Access Control (DAC): 4.B.2.a(2), Mandatory Access Control (MAC): 4.B.4.a(3)</reference>
                  </Group>
                  <Group id="AC-4" hidden="true">
                        <title>Information Flow Enforcement</title>
                        <reference>ISO/IEC 17799: 10.6.2, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>DOD 8500.2: EBBD-1, EBBD-2</reference>
                        <reference>DCID 6/3: 4.B.3.a(3), 7.B.3.g</reference>
                  </Group>
                  <Group id="AC-5" hidden="true">
                        <title>Separation of Duties</title>
                        <reference>ISO/IEC 17799: 10.1.3, 10.6.1, 10.10.1</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2, 6.1.3, 15.2.1, 16.1.2, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2, SD-1.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 2.A.1, 4.B.3.a(18)</reference>
                  </Group>
                  <Group id="AC-6" hidden="true">
                        <title>Least Privilege</title>
                        <reference>ISO/IEC 17799: 11.2.2</reference>
                        <reference>NIST 800-26: 16.1.2, 16.1.3, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="AC-7" hidden="true">
                        <title>Unsuccessful Login Attempts</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>NIST 800-26: 15.1.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(c)-(d)</reference>
                  </Group>
                  <Group id="AC-8" hidden="true">
                        <title>System Use Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1, 15.1.5</reference>
                        <reference>NIST 800-26: 16.2.13, 16.3.1, 17.1.9</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECWM-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(6)</reference>
                  </Group>
                  <Group id="AC-9" hidden="true">
                        <title>Previous Logon Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-2</reference>
                  </Group>
                  <Group id="AC-10" hidden="true">
                        <title>Concurrent Session Control</title>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(a)</reference>
                  </Group>
                  <Group id="AC-11" hidden="true">
                        <title>Session Lock</title>
                        <reference>ISO/IEC 17799: 11.3.2</reference>
                        <reference>NIST 800-26: 16.1.4</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: PESL-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(5)</reference>
                  </Group>
                  <Group id="AC-12" hidden="true">
                        <title>Session Termination</title>
                        <reference>ISO/IEC 17799: 11.3.2, 11.5.5</reference>
                        <reference>NIST 800-26: 16.1.4, 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(b)</reference>
                  </Group>
                  <Group id="AC-13" hidden="true">
                        <title>Supervision and Review—Access Control</title>
                        <reference>ISO/IEC 17799: 10.10.2, 11.2.4</reference>
                        <reference>NIST 800-26: 7.1.10, 11.2.2, 16.1.10, 16.2.5, 17.1.6, 17.1.7</reference>
                        <reference>GAO FISCAM: AC-4, AC-4.3, SS-2.2</reference>
                        <reference>DOD 8500.2: ECAT-1, ECAT-2, E3.3.9</reference>
                        <reference>DCID 6/3: 2.B.7.c, 4.B.3.a(8)(b)</reference>
                  </Group>
                  <Group id="AC-14" hidden="true">
                        <title>Permitted Actions without Identification or Authentication</title>
                        <reference>NIST 800-26: 16.2.12</reference>
                        <reference>DCID 6/3: 7.D.3.a</reference>
                  </Group>
                  <Group id="AC-15" hidden="true">
                        <title>Automated Marking</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 8.2.4, 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(11)</reference>
                  </Group>
                  <Group id="AC-16" hidden="true">
                        <title>Automated Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(3), 4.B.4.a(15), 4.B.4.a(16)</reference>
                  </Group>
                  <Group id="AC-17" hidden="true">
                        <title>Remote Access</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.4.4</reference>
                        <reference>NIST 800-26: 16.2.4, 16.2.8</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: EBRP-1, EBRU-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1)(b), 4.B.3.a(11), 7.D.2.e</reference>
                  </Group>
                  <Group id="AC-18" hidden="true">
                        <title>Wireless Access Restrictions</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.7.1, 11.7.2</reference>
                        <reference>DOD 8500.2: ECCT-1, ECWN-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8), 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="AC-19" hidden="true">
                        <title>Access Control for Portable and Mobile Systems</title>
                        <reference>ISO/IEC 17799: 11.7.1</reference>
                        <reference>NIST 800-26: 7.3.1, 7.3.2</reference>
                        <reference>DOD 8500.2: ECWN-1</reference>
                        <reference>DCID 6/3: 8.B.6.c, 9.G.4</reference>
                  </Group>
                  <Group id="AC-20" hidden="true">
                        <title>Use of External Information Systems</title>
                        <reference>ISO/IEC 17799: 6.1.4, 9.2.5, 11.7.1</reference>
                        <reference>NIST 800-26: 10.2.13</reference>
                        <reference>DCID 6/3: 8.B.6.c</reference>
                  </Group>
            </Group>
            <Group id="awareness_and_training" hidden="true">
                  <title>Applicable 800-53 Awareness and Training</title>
                  <Group id="AT-1" hidden="true">
                        <title>Security Awareness and Training Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 8.2.2, 15.1.1</reference>
                        <reference>NIST 800-26: 13</reference>
                        <reference>DOD 8500.2: PRTN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.c, Manual: 2.B.2.b(8); 2.B.4.e(6)</reference>
                  </Group>
                  <Group id="AT-2" hidden="true">
                        <title>Security Awareness</title>
                        <reference>ISO/IEC 17799: 6.2.3, 8.2.2, 10.4.1, 11.7.1, 13.1.1, 14.1.4, 15.1.4</reference>
                        <reference>NIST 800-26: 13.1.4, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-3" hidden="true">
                        <title>Security Training</title>
                        <reference>ISO/IEC 17799: 8.2.2, 10.3.2, 11.7.1, 13.1.1, 14.1.4</reference>
                        <reference>NIST 800-26: 13.1, 13.1.3, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-4" hidden="true">
                        <title>Security Training Records</title>
                        <reference>NIST 800-26: 13.1.2</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-5" hidden="true">
                        <title>Contacts with Security Groups and Associations</title>
                        <reference>ISO/IEC 17799: 6.1.7</reference>
                  </Group>
            </Group>
            <Group id="audit_and_accountablility" hidden="true">
                  <title>Applicable 800-53 Audit and Accountability</title>
                  <Group id="AU-1" hidden="true">
                        <title>Audit and Accountability Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1, 15.1.1</reference>
                        <reference>NIST 800-26: 17</reference>
                        <reference>DOD 8500.2: ECAT-1, ECTB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.d, Manual: 2.B.4.e(5); 4.B.2.a(4)</reference>
                  </Group>
                  <Group id="AU-2" hidden="true">
                        <title>Auditable Events</title>
                        <reference>ISO/IEC 17799: 10.10.1</reference>
                        <reference>NIST 800-26: 17.1.1, 17.1.2, 17.1.4</reference>
                        <reference>DOD 8500.2: ECAR-3</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(d)</reference>
                  </Group>
                  <Group id="AU-3" hidden="true">
                        <title>Content of Audit Records</title>
                        <reference>ISO/IEC 17799: 10.10.1, 10.10.4</reference>
                        <reference>NIST 800-26: 17.1.1</reference>
                        <reference>DOD 8500.2: ECAR-1, ECAR-2, ECAR-3, ECLC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a), 4.B.2.a(5)(a)</reference>
                  </Group>
                  <Group id="AU-4" hidden="true">
                        <title>Audit Storage Capacity</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="AU-5" hidden="true">
                        <title>Response to Audit Processing Failures</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 4.B.4.a(9)(d)</reference>
                  </Group>
                  <Group id="AU-6" hidden="true">
                        <title>Audit Monitoring, Analysis, and Reporting</title>
                        <reference>ISO/IEC 17799: 10.10.2, 10.10.4, 13.2.1</reference>
                        <reference>NIST 800-26: 16.2.5, 17.1.7, 17.1.8</reference>
                        <reference>GAO FISCAM: AC-4.3</reference>
                        <reference>DOD 8500.2: ECAT-1, E3.3.9</reference>
                        <reference>DCID 6/3: 4.B.4.a(10)</reference>
                  </Group>
                  <Group id="AU-7" hidden="true">
                        <title>Audit Reduction and Report Generation</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>NIST 800-26: 17.1.2, 17.1.7</reference>
                        <reference>DOD 8500.2: ECRG-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(6)</reference>
                  </Group>
                  <Group id="AU-8" hidden="true">
                        <title>Time Stamps</title>
                        <reference>ISO/IEC 17799: 10.10.6</reference>
                        <reference>DOD 8500.2: ECAR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a)</reference>
                  </Group>
                  <Group id="AU-9" hidden="true">
                        <title>Protection of Audit Information</title>
                        <reference>ISO/IEC 17799: 10.10.3, 15.1.3, 15.3.2</reference>
                        <reference>NIST 800-26: 17.1.3, 17.1.4</reference>
                        <reference>DOD 8500.2: ECTP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(b)</reference>
                  </Group>
                  <Group id="AU-10" hidden="true">
                        <title>Non-repudiation</title>
                        <reference>ISO/IEC 17799: 10.8.2, 10.9.1, 12.3.1</reference>
                        <reference>NIST 800-26: 15.1.2, 17.1.1</reference>
                        <reference>DOD 8500.2: DCNR-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(8)</reference>
                  </Group>
                  <Group id="AU-11" hidden="true">
                        <title>Audit Record Retention</title>
                        <reference>ISO/IEC 17799: 10.10.1, 15.1.3</reference>
                        <reference>NIST 800-26: 17.1.4</reference>
                        <reference>DOD 8500.2: ECRR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(c)</reference>
                  </Group>
            </Group>
            <Group id="certification_accreditation_and_security_assessment" hidden="true">
                  <title>Applicable 800-53 Certification, Accreditation, and Security Assessment</title>
                  <Group id="CA-1" hidden="true">
                        <title>Certification, Accreditation, and Security Assessment Policies and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1.4, 10.3.2, 15.1.1</reference>
                        <reference>NIST 800-26: 2, 4</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 2.B.2.b(1)</reference>
                  </Group>
                  <Group id="CA-2" hidden="true">
                        <title>Security Assessments</title>
                        <reference>ISO/IEC 17799: 6.1.8, 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 2.1.1, 2.1.3, 2.1.4</reference>
                        <reference>GAO FISCAM: SP-5.1</reference>
                        <reference>DOD 8500.2: DCII-1, ECMT-1, PEPS-1, E3.3.10</reference>
                        <reference>DCID 6/3: DCID: B.2.b; B.3.a, Manual: 4.B.2.b(6); 5.B.1.b(1); 9.B.1; 9.B.4</reference>
                  </Group>
                  <Group id="CA-3" hidden="true">
                        <title>Information System Connections</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.9.1, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>NIST 800-26: 1.1.1, 3.2.9, 4.1.8, 12.2.3</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCID-1, EBCR-1 EBRU-1, EBPW-1, ECIC-1</reference>
                        <reference>DCID 6/3: 9.B.3, 9.D.3.c</reference>
                  </Group>
                  <Group id="CA-4" hidden="true">
                        <title>Security Certification</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 2.1.2, 3.2.3, 3.2.5, 3.2.6, 4.1.1, 4.1.6, 11.2.8. 12.2.5</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCAR-1, 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 4.B.3.b(8); 9.E.2.a(2); 9.E.2.a(3)</reference>
                  </Group>
                  <Group id="CA-5" hidden="true">
                        <title>Plan of Action and Milestones</title>
                        <reference>ISO/IEC 17799: 15.2.1</reference>
                        <reference>NIST 800-26: 1.1.5, 1.2.3, 2.2.1, 4.2.1</reference>
                        <reference>GAO FISCAM: SP-5.1 SP-5.2</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 9.E.2.a(3)(a)</reference>
                  </Group>
                  <Group id="CA-6" hidden="true">
                        <title>Security Accreditation</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 3.2.7, 12.2.5</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 9.D.3; 9.D.4</reference>
                  </Group>
                  <Group id="CA-7" hidden="true">
                        <title>Continuous Monitoring</title>
                        <reference>ISO/IEC 17799: 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 10.2.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, E3.3.9</reference>
                        <reference>DCID 6/3: DCID: B.2.d; Manual: 2.B.4.e(7); 2.B.5.c(10); 5.B.2.b(2); 9.B.1; 9.D.7</reference>
                  </Group>
            </Group>
            <Group id="configuration_management" hidden="true">
                  <title>Applicable 800-53 Configuration Management</title>
                  <Group id="CM-1" hidden="true">
                        <title>Configuration Management Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.4.1, 12.5.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, DCAR-1, E3.3.8</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-2" hidden="true">
                        <title>Baseline Configuration and System Component Inventory</title>
                        <reference>ISO/IEC 17799: 7.1.1, 15.1.2</reference>
                        <reference>NIST 800-26: 1.1.1, 3.1.9, 10.2.7, 10.2.9, 12.1.4</reference>
                        <reference>GAO FISCAM: CC-2.3, CC-3.1, SS-1.2</reference>
                        <reference>DOD 8500.2: DCHW-1, DCSW-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 4.B.2.b(6)</reference>
                  </Group>
                  <Group id="CM-3" hidden="true">
                        <title>Configuration Change Control</title>
                        <reference>ISO/IEC 17799: 10.1.2, 10.2.3, 12.4.1, 12.5.1, 12.5.2, 12.5.3</reference>
                        <reference>NIST 800-26: 3.1.4, 10.2.2, 10.2.3, 10.2.8, 10.2.10, 10.2.11</reference>
                        <reference>GAO FISCAM: SS-3.2, CC-2.2</reference>
                        <reference>DOD 8500.2: DCPR-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7) 4.B.1.c(3), 4.B.2.b(6), 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-4" hidden="true">
                        <title>Monitoring Configuration Changes</title>
                        <reference>ISO/IEC 17799: 10.1.2</reference>
                        <reference>NIST 800-26: 10.2.1, 10.2.4</reference>
                        <reference>GAO FISCAM: SS-3.1, SS-3.2, CC-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, E3.3.8</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 5.B.2.b(2), 8.B.8.c(7)</reference>
                  </Group>
                  <Group id="CM-5" hidden="true">
                        <title>Access Restrictions for Change</title>
                        <reference>ISO/IEC 17799: 11.6.1</reference>
                        <reference>NIST 800-26: 6.1.3, 6.1.4, 10.1.1, 10.1.4, 10.1.5</reference>
                        <reference>GAO FISCAM: SD-1.1, SS-1.2, SS-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, ECSD-2</reference>
                        <reference>DCID 6/3: 5.B.3.a(2)(b)</reference>
                  </Group>
                  <Group id="CM-6" hidden="true">
                        <title>Configuration Settings</title>
                        <reference>NIST 800-26: 10.2.6, 10.3.1, 16.2.2, 16.2.3, 16.2.11</reference>
                        <reference>DOD 8500.2: DCSS-1, ECSC-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="CM-7" hidden="true">
                        <title>Least Functionality</title>
                        <reference>NIST 800-26: 10.3.1</reference>
                        <reference>DOD 8500.2: DCPP-1, ECIM-1, ECVI-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10), 7.D.2.b</reference>
                  </Group>
            </Group>
            <Group id="contingency_planning" hidden="true">
                  <title>Applicable 800-53 Contingency Planning</title>
                  <Group id="CP-1" hidden="true">
                        <title>Contingency Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 10.4.1, 14.1.1, 14.1.3, 15.1.1</reference>
                        <reference>NIST 800-26: 9</reference>
                        <reference>DOD 8500.2: COBR-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 6.B.1.a(1)</reference>
                  </Group>
                  <Group id="CP-2" hidden="true">
                        <title>Contingency Plan</title>
                        <reference>ISO/IEC 17799: 10.3.2, 10.4.1, 10.8.5, 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 4.1.4, 9.1.1, 9.2, 9.2.1, 9.2.2, 9.2.3, 9.2.10, 12.1.8, 12.2.2</reference>
                        <reference>GAO FISCAM: SC-3.1, SC-1.1</reference>
                        <reference>DOD 8500.2: CODP-1, COEF-1</reference>
                        <reference>DCID 6/3: 6.B.2.b(1)</reference>
                  </Group>
                  <Group id="CP-3" hidden="true">
                        <title>Contingency Training</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 9.3.2</reference>
                        <reference>GAO FISCAM: SC-2.3</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="CP-4" hidden="true">
                        <title>Contingency Plan Testing</title>
                        <reference>ISO/IEC 17799: 10.5.1, 14.1.5</reference>
                        <reference>NIST 800-26: 4.1.4, 9.3.3</reference>
                        <reference>GAO FISCAM: SC-3.1</reference>
                        <reference>DOD 8500.2: COED-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)(b)</reference>
                  </Group>
                  <Group id="CP-5" hidden="true">
                        <title>Contingency Plan Update</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.5</reference>
                        <reference>NIST 800-26: 9.3.1, 9.3.3, 10.2.12</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)</reference>
                  </Group>
                  <Group id="CP-6" hidden="true">
                        <title>Alternate Storage Sites</title>
                        <reference>ISO/IEC 17799: 10.5.1</reference>
                        <reference>NIST 800-26: 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: CODB-2</reference>
                        <reference>DCID 6/3: 6.B.2.a(2), 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-7" hidden="true">
                        <title>Alternate Processing Sites</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.1.3, 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: COAS-1, COEB-1, COSP-1, COSP-2</reference>
                        <reference>DCID 6/3: 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-8" hidden="true">
                        <title>Telecommunications Services</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>DCID 6/3: 6.B.2.a(4)</reference>
                  </Group>
                  <Group id="CP-9" hidden="true">
                        <title>Information System Backup</title>
                        <reference>ISO/IEC 17799: 10.5.1, 11.7.1</reference>
                        <reference>NIST 800-26: 9.1.1, 9.2.6, 9.2.9, 9.3.1, 12.1.9</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: CODB-1, CODB-2, COSW-1</reference>
                        <reference>DCID 6/3: 6.B.1.a(2)</reference>
                  </Group>
                  <Group id="CP-10" hidden="true">
                        <title>Information System Recovery and Reconstitution</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.2.8</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: COTR-1, ECND-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(4), 6.B.1.a(1), 6.B.2.a(3)(d)</reference>
                  </Group>
            </Group>
            <Group id="identification_and_authentication" hidden="true">
                  <title>Applicable 800-53 Identification and Authentication</title>
                  <Group id="IA-1" hidden="true">
                        <title>Identification and Authentication Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11.2.3</reference>
                        <reference>DOD 8500.2: IAIA-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="IA-2" hidden="true">
                        <title>User Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.4.2, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1</reference>
                        <reference>DOD 8500.2: IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)</reference>
                  </Group>
                  <Group id="IA-3" hidden="true">
                        <title>Device Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.7.1</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.5.a(14)</reference>
                  </Group>
                  <Group id="IA-4" hidden="true">
                        <title>Identifier Management</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1.1, 15.2.2, 15.1.8</reference>
                        <reference>GAO FISCAM: AC-2.1, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAGA-1, IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(2)</reference>
                  </Group>
                  <Group id="IA-5" hidden="true">
                        <title>Authenticator Management</title>
                        <reference>ISO/IEC 17799: 11.5.2, 11.5.3</reference>
                        <reference>NIST 800-26: 15.1.6, 15.1.7, 15.1.9, 15.1.10, 15.1.11, 15.1.12, 15.1.13, 16.1.3, 16.2.3</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="IA-6" hidden="true">
                        <title>Authenticator Feedback</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)(g)</reference>
                  </Group>
                  <Group id="IA-7" hidden="true">
                        <title>Cryptographic Module Authentication</title>
                        <reference>NIST 800-26: 16.1.7</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
            </Group>
            <Group id="incident_response" hidden="true">
                  <title>Applicable 800-53 Incident Response</title>
                  <Group id="IR-1" hidden="true">
                        <title>Incident Response Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.4.1, 13.1, 13.2.1, 15.1.1</reference>
                        <reference>NIST 800-26: 14</reference>
                        <reference>DOD 8500.2: VIIR-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.c; C.4 Manual: 2.B.4.e(5); 2.B.2.b(6); 2.B.6.c(10); 8.B.7</reference>
                  </Group>
                  <Group id="IR-2" hidden="true">
                        <title>Incident Response Training</title>
                        <reference>ISO/IEC 17799: 13.1.1</reference>
                        <reference>NIST 800-26: 14.1.4</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.1.b(1)(f), 8.B.1.c(1)(e), 8.B.1.c(2)©</reference>
                  </Group>
                  <Group id="IR-3" hidden="true">
                        <title>Incident Response Testing</title>
                        <reference>ISO/IEC 17799: 14.1.5</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-4" hidden="true">
                        <title>Incident Handling</title>
                        <reference>ISO/IEC 17799: 6.1.6, 13.2.1, 13.2.2</reference>
                        <reference>NIST 800-26: 2.1.5, 14.1.1, 14.1.2, 14.1.6</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7, 9.B.2.e</reference>
                  </Group>
                  <Group id="IR-5" hidden="true">
                        <title>Incident Monitoring</title>
                        <reference>NIST 800-26: 14.1.3</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7.a</reference>
                  </Group>
                  <Group id="IR-6" hidden="true">
                        <title>Incident Reporting</title>
                        <reference>ISO/IEC 17799: 6.1.6, 6.2.2, 6.2.3, 13.1.1, 13.1.2</reference>
                        <reference>NIST 800-26: 14.1.2, 14.1.3, 14.2.1, 14.2.2, 14.2.3</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-7" hidden="true">
                        <title>Incident Response Assistance</title>
                        <reference>ISO/IEC 17799: 14.1.3</reference>
                        <reference>NIST 800-26: 8.1.1, 14.1.1</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DCID 6/3: 8.B.7.c</reference>
                  </Group>
            </Group>
            <Group id="maintenance" hidden="true">
                  <title>Applicable 800-53 Maintenance</title>
                  <Group id="MA-1" hidden="true">
                        <title>System Maintenance Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 10</reference>
                        <reference>DOD 8500.2: PRMP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="MA-2" hidden="true">
                        <title>Periodic Maintenance</title>
                        <reference>ISO/IEC 17799: 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3, 10.2.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5), 8.B.8.c</reference>
                  </Group>
                  <Group id="MA-3" hidden="true">
                        <title>Maintenance Tools</title>
                        <reference>NIST 800-26: 10.1.3, 11.2.4</reference>
                        <reference>DCID 6/3: 6.B.3.a(5), 8.B.8.c(4), 8.B.8.c(5)</reference>
                  </Group>
                  <Group id="MA-4" hidden="true">
                        <title>Remote Maintenance</title>
                        <reference>ISO/IEC 17799: 11.4.4</reference>
                        <reference>NIST 800-26: 10.1.1, 17.1.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: EBRP-1</reference>
                        <reference>DCID 6/3: 8.B.8.d</reference>
                  </Group>
                  <Group id="MA-5" hidden="true">
                        <title>Maintenance Personnel</title>
                        <reference>ISO/IEC 17799: 6.2.3, 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: PRMP-1</reference>
                        <reference>DCID 6/3: 8.B.8.a</reference>
                  </Group>
                  <Group id="MA-6" hidden="true">
                        <title>Timely Maintenance</title>
                        <reference>NIST 800-26: 9.1.2</reference>
                        <reference>GAO FISCAM: SC-1.2</reference>
                        <reference>DOD 8500.2: COMS-1, COSP-1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5)</reference>
                  </Group>
            </Group>
            <Group id="media_protection" hidden="true">
                  <title>Applicable 800-53 Media Protection</title>
                  <Group id="MP-1" hidden="true">
                        <title>Media Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 10.7, 15.1.1, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2</reference>
                        <reference>DOD 8500.2: PESP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.6.c(7); 8.B.2</reference>
                  </Group>
                  <Group id="MP-2" hidden="true">
                        <title>Media Access</title>
                        <reference>ISO/IEC 17799: 10.7.3</reference>
                        <reference>NIST 800-26: 8.2.1, 8.2.2, 8.2.3, 8.2.6, 8.2.7</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(1), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-3" hidden="true">
                        <title>Media Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.7.3, 10.8.2, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2.5, 8.2.6, 10.2.9</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 8.B.2.a, 8.B.2.c</reference>
                  </Group>
                  <Group id="MP-4" hidden="true">
                        <title>Media Storage</title>
                        <reference>ISO/IEC 17799: 10.7.1, 10.7.2, 10.7.3, 10.7.4, 15.1.3</reference>
                        <reference>NIST 800-26: 7.1.4, 8.2.1, 8.2.2, 8.2.9, 10.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PESS-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-5" hidden="true">
                        <title>Media Transport</title>
                        <reference>ISO/IEC 17799: 10.8.3</reference>
                        <reference>NIST 800-26: 8.2.2, 8.2.4</reference>
                        <reference>DCID 6/3: 2.B.9.b(4)</reference>
                  </Group>
                  <Group id="MP-6" hidden="true">
                        <title>Media Sanitization</title>
                        <reference>ISO/IEC 17799: 9.2.6, 10.7.1, 10.7.2</reference>
                        <reference>NIST 800-26: 3.2.11, 3.2.12, 3.2.13, 8.2.8, 8.2.9, 8.2.10</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: PECS-1, PEDD-1</reference>
                        <reference>DCID 6/3: 8.B.5, 2.B.9.b(4), 8.B.5.a(4), 8.B.5.d, 8.B.5.e</reference>
                  </Group>
                  <Group id="MP-7" hidden="true">
                        <title>Media Destruction and Disposal</title>
                        <reference>ISO/IEC 17799: </reference>
                        <reference>NIST 800-26: </reference>
                        <reference>GAO FISCAM: </reference>
                        <reference>DOD 8500.2: </reference>
                        <reference>DCID 6/3: </reference>
                  </Group>
            </Group>
            <Group id="physical_and_environmental_protection" hidden="true">
                  <title>Applicable 800-53 Physical and Environmental Protection</title>
                  <Group id="PE-1" hidden="true">
                        <title>Physical and Environmental Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 7</reference>
                        <reference>DOD 8500.2: PETN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.D</reference>
                  </Group>
                  <Group id="PE-2" hidden="true">
                        <title>Physical Access Authorizations</title>
                        <reference>ISO/IEC 17799: 9.1.2, 9.1.6</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PECF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.E</reference>
                  </Group>
                  <Group id="PE-3" hidden="true">
                        <title>Physical Access Control</title>
                        <reference>ISO/IEC 17799: 9.1.1, 9.1.2, 9.1.5, 9.1.6, 10.5.1</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2, 7.1.5, 7.1.6, 7.1.8</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEPF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-4" hidden="true">
                        <title>Access Control for Transmission Medium</title>
                        <reference>ISO/IEC 17799: 9.2.3</reference>
                        <reference>NIST 800-26: 7.2.2, 16.2.9</reference>
                        <reference>DCID 6/3: 8.D.2, 4.B.1.a(8)</reference>
                  </Group>
                  <Group id="PE-5" hidden="true">
                        <title>Access Control for Display Medium</title>
                        <reference>ISO/IEC 17799: 9.1.2, 11.3.3</reference>
                        <reference>NIST 800-26: 7.2.1</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-6" hidden="true">
                        <title>Monitoring Physical Access</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-7" hidden="true">
                        <title>Visitor Control</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.7, 7.1.11</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-8" hidden="true">
                        <title>Access Records</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2, PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-9" hidden="true">
                        <title>Power Equipment and Power Cabling</title>
                        <reference>ISO/IEC 17799: 9.2.2, 9.2.3</reference>
                        <reference>NIST 800-26: 7.1.16</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-10" hidden="true">
                        <title>Emergency Shutoff</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEMS-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-11" hidden="true">
                        <title>Emergency Power</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>NIST 800-26: 7.1.18</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: COPS-1, COPS-2, COPS-3</reference>
                        <reference>DCID 6/3: 6.B.2.a(6), 6.B.2.a(7)</reference>
                  </Group>
                  <Group id="PE-12" hidden="true">
                        <title>Emergency Lighting</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEEL-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-13" hidden="true">
                        <title>Fire Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.12</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEFD-1, PEFS-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-14" hidden="true">
                        <title>Temperature and Humidity Controls</title>
                        <reference>ISO/IEC 17799: 9.2.1, 10.5.1, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.14, 7.1.15</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEHC-1, PETC-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-15" hidden="true">
                        <title>Water Damage Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.17</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-16" hidden="true">
                        <title>Delivery and Removal</title>
                        <reference>ISO/IEC 17799: 9.1.6, 9.2.7, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.3</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DCID 6/3: 8.B.5.e</reference>
                  </Group>
                  <Group id="PE-17" hidden="true">
                        <title>Alternate Work Site</title>
                        <reference>ISO/IEC 17799: 11.7.2</reference>
                        <reference>DOD 8500.2: EBRU-1</reference>
                  </Group>
                  <Group id="PE-18" hidden="true">
                        <title>Location of Information System Components</title>
                        <reference>ISO/IEC 17799: 9.2.1</reference>
                  </Group>
                  <Group id="PE-19" hidden="true">
                        <title>Information Leakage</title>
                  </Group>
            </Group>
            <Group id="planning" hidden="true">
                  <title>Applicable 800-53 Planning</title>
                  <Group id="PL-1" hidden="true">
                        <title>Security Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1, 15.1.1</reference>
                        <reference>NIST 800-26: 5</reference>
                        <reference>DOD 8500.2: DCAR-1, E3.4.6</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="PL-2" hidden="true">
                        <title>System Security Plan</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 4.1.5, 5.1.1, 5.1.2, 12.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: DCSD-1</reference>
                        <reference>DCID 6/3: 1.F.6, 2.B.6.c(3), 2.B.7.c(5), 9.E.2.a(1)(d), 9.F.2.a, Appendix C</reference>
                  </Group>
                  <Group id="PL-3" hidden="true">
                        <title>System Security Plan Update</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 3.2.10, 5.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 2.B.7.c(5)</reference>
                  </Group>
                  <Group id="PL-4" hidden="true">
                        <title>Rules of Behavior</title>
                        <reference>ISO/IEC 17799: 7.1.3, 8.1.3, 15.1.5</reference>
                        <reference>NIST 800-26: 4.1.3, 13.1.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 2.B.9.b</reference>
                  </Group>
                  <Group id="PL-5" hidden="true">
                        <title>Privacy Impact Assessment</title>
                        <reference>ISO/IEC 17799: 15.1.4</reference>
                        <reference>DCID 6/3: DCID: B.3.a; Manual: 8.B.9</reference>
                  </Group>
                  <Group id="PL-6" hidden="true">
                        <title>Security-Related Activity Planning</title>
                        <reference>ISO/IEC 17799: 15.3.1</reference>
                  </Group>
            </Group>
            <Group id="personnel_security" hidden="true">
                  <title>Applicable 800-53 Personnel Security</title>
                  <Group id="PS-1" hidden="true">
                        <title>Personnel Security Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 8.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 6</reference>
                        <reference>DOD 8500.2: PRRB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.E</reference>
                  </Group>
                  <Group id="PS-2" hidden="true">
                        <title>Position Categorization</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2</reference>
                        <reference>GAO FISCAM: SD-1.2</reference>
                        <reference>DCID 6/3: 8.E</reference>
                  </Group>
                  <Group id="PS-3" hidden="true">
                        <title>Personnel Screening</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.2.1, 6.2.3</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRAS-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(2), 2.B.8.b(5), 8.E</reference>
                  </Group>
                  <Group id="PS-4" hidden="true">
                        <title>Personnel Termination</title>
                        <reference>ISO/IEC 17799: 8.1.3, 8.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6), 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
                  <Group id="PS-5" hidden="true">
                        <title>Personnel Transfer</title>
                        <reference>ISO/IEC 17799: 8.3.1, 8.3.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6)</reference>
                  </Group>
                  <Group id="PS-6" hidden="true">
                        <title>Access Agreements</title>
                        <reference>ISO/IEC 17799: 6.1.5, 8.1.3</reference>
                        <reference>NIST 800-26: 6.1.5, 6.2.2</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 1.E.2, 8.E</reference>
                  </Group>
                  <Group id="PS-7" hidden="true">
                        <title>Third-Party Personnel Security</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 8.1.1, 8.1.2, 8.1.3, 8.2.1, 8.2.2, 11.2.1</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.7.10</reference>
                        <reference>DCID 6/3: 1.A.1, 8.D, 8.E</reference>
                  </Group>
                  <Group id="PS-8" hidden="true">
                        <title>Personnel Sanctions</title>
                        <reference>ISO/IEC 17799: 8.2.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.5</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
            </Group>
            <Group id="risk_assessment" hidden="true">
                  <title>Applicable 800-53 Risk Assessment</title>
                  <Group id="RA-1" hidden="true">
                        <title>Risk Assessment Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="RA-2" hidden="true">
                        <title>Security Categorization</title>
                        <reference>ISO/IEC 17799: 7.2.1</reference>
                        <reference>NIST 800-26: 1.1.3, 3.1.1</reference>
                        <reference>GAO FISCAM: SP-1, AC-1.1, AC-1.2</reference>
                        <reference>DOD 8500.2: E3.4.2</reference>
                        <reference>DCID 6/3: 3.C, 3.D, 9.E.2.a(1)(a), 9.E.2.a(1)(d)</reference>
                  </Group>
                  <Group id="RA-3" hidden="true">
                        <title>Risk Assessment</title>
                        <reference>ISO/IEC 17799: 4, 4.1, 4.2, 6.2.1, 10.10.2, 10.10.5, 12.5.1, 12.6.1, 14.1.1, 14.1.2</reference>
                        <reference>NIST 800-26: 1.1.2, 1.1.4, 1.1.5, 1.1.6, 1.2.1, 1.2.2, 1.2.3, 3.1.7, 3.1.8, 4.1.7, 7.1.13, 7.1.19, 12.2.4</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCDS-1, DCII-1, E3.3.10</reference>
                        <reference>DCID 6/3: 9.B</reference>
                  </Group>
                  <Group id="RA-4" hidden="true">
                        <title>Risk Assessment Update</title>
                        <reference>ISO/IEC 17799: 4.1</reference>
                        <reference>NIST 800-26: 1.1.2, 4.1.2</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: 9.B.4.f, 9.D.1.d</reference>
                  </Group>
                  <Group id="RA-5" hidden="true">
                        <title>Vulnerability Scanning</title>
                        <reference>ISO/IEC 17799: 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 14.2.1</reference>
                        <reference>DOD 8500.2: ECMT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(8)(b), 4.B.3.b(6)(b), 9.B.4.e</reference>
                  </Group>
            </Group>
            <Group id="system_and_services_acquisition" hidden="true">
                  <title>Applicable 800-53 System and Services Acquisition</title>
                  <Group id="SA-1" hidden="true">
                        <title>System and Services Acquisition Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.1, 15.1.1</reference>
                        <reference>NIST 800-26: 3</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SA-2" hidden="true">
                        <title>Allocation of Resources</title>
                        <reference>ISO/IEC 17799: 10.3.1</reference>
                        <reference>NIST 800-26: 3.1.2, 3.1.3, 3.1.5, 5.1.3</reference>
                        <reference>DOD 8500.2: DCPB-1, E3.3.4</reference>
                        <reference>DCID 6/3: DCID: C.2.a, Manual: 2.B.4.e(8)</reference>
                  </Group>
                  <Group id="SA-3" hidden="true">
                        <title>Life Cycle Support</title>
                        <reference>NIST 800-26: 3.1</reference>
                        <reference>DOD 8500.2: 5.8.1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 9.E.2</reference>
                  </Group>
                  <Group id="SA-4" hidden="true">
                        <title>Acquisitions</title>
                        <reference>ISO/IEC 17799: 12.1.1</reference>
                        <reference>NIST 800-26: 3.1.6, 3.1.7, 3.1.10, 3.1.11, 3.1.12</reference>
                        <reference>DOD 8500.2: DCAS-1, DCDS-1, DCIT-1, DCMC-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a; C.2.a, Manual: 9.B.4</reference>
                  </Group>
                  <Group id="SA-5" hidden="true">
                        <title>Information System Documentation</title>
                        <reference>ISO/IEC 17799: 10.7.4</reference>
                        <reference>NIST 800-26: 3.2.3, 3.2.4, 3.2.8, 12.1.1, 12.1.2, 12.1.3, 12.1.6, 12.1.7</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCCS-1, DCHW-1, DCID-1, DCSD-1, DCSW-1, ECND-1, DCFA-1</reference>
                        <reference>DCID 6/3: 4.B.2.b(2), 4.B.2.b(3), 4.B.4.b(4), 9.C.3</reference>
                  </Group>
                  <Group id="SA-6" hidden="true">
                        <title>Software Usage Restrictions</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10, 10.2.13</reference>
                        <reference>GAO FISCAM: SS-3.2, SP-2.1</reference>
                        <reference>DOD 8500.2: DCPD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-7" hidden="true">
                        <title>User Installed Software</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10</reference>
                        <reference>GAO FISCAM: SS-3.2</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-8" hidden="true">
                        <title>Security Engineering Principles</title>
                        <reference>ISO/IEC 17799: 12.1</reference>
                        <reference>NIST 800-26: 3.2.1</reference>
                        <reference>DOD 8500.2: DCBP-1, DCCS-1, E3.4.4</reference>
                        <reference>DCID 6/3: 1.H.1</reference>
                  </Group>
                  <Group id="SA-9" hidden="true">
                        <title>Outsourced Information System Services</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 10.2.1, 10.2.2, 10.6.2</reference>
                        <reference>NIST 800-26: 12.2.3</reference>
                        <reference>DOD 8500.2: DCDS-1, DCID-1 DCIT-1, DCPP-1</reference>
                        <reference>DCID 6/3: 1.B.1, 8.C.2, 8.E</reference>
                  </Group>
                  <Group id="SA-10" hidden="true">
                        <title>Developer Configuration Management</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-3</reference>
                        <reference>DCID 6/3: 4.B.4.b(4), 8.C.2.a</reference>
                  </Group>
                  <Group id="SA-11" hidden="true">
                        <title>Developer Security Testing</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>NIST 800-26: 3.2.1, 3.2.2, 10.2.5, 12.1.5</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-2.1</reference>
                        <reference>DOD 8500.2: E3.4.4</reference>
                        <reference>DCID 6/3: 4.B.4.b(4)</reference>
                  </Group>
            </Group>
            <Group id="system_and_communications_protection" hidden="true">
                  <title>Applicable 800-53 System and Communication Protection</title>
                  <Group id="SC-1" hidden="true">
                        <title>System and Communications Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.8.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SC-2" hidden="true">
                        <title>Application Partitioning</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCPA-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-3" hidden="true">
                        <title>Security Function Isolation</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCSP-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(1), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-4" hidden="true">
                        <title>Information Remnants</title>
                        <reference>ISO/IEC 17799: 10.8.1</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: ECRC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(14)</reference>
                  </Group>
                  <Group id="SC-5" hidden="true">
                        <title>Denial of Service Protection</title>
                        <reference>ISO/IEC 17799: 10.8.4, 13.2.1</reference>
                        <reference>DCID 6/3: 6.B.3.a(6)</reference>
                  </Group>
                  <Group id="SC-6" hidden="true">
                        <title>Resource Priority</title>
                        <reference>DCID 6/3: 6.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-7" hidden="true">
                        <title>Boundary Protection</title>
                        <reference>ISO/IEC 17799: 11.4.6</reference>
                        <reference>NIST 800-26: 16.2.2, 16.2.7, 16.2.9, 16.2.10, 16.2.11, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: COEB-1, EBBD-1, ECIM-1, ECVI-1</reference>
                        <reference>DCID 6/3: 4.B.4.a(27), 5.B.3.a(11)(b), 7.A.3, 7.B, 7.C, 7.D</reference>
                  </Group>
                  <Group id="SC-8" hidden="true">
                        <title>Transmission Integrity</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4, 11.2.9, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-9" hidden="true">
                        <title>Transmission Confidentiality</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>DOD 8500.2: ECCT-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8)(a)</reference>
                  </Group>
                  <Group id="SC-10" hidden="true">
                        <title>Network Disconnect</title>
                        <reference>ISO/IEC 17799: 11.5.6</reference>
                        <reference>NIST 800-26: 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)</reference>
                  </Group>
                  <Group id="SC-11" hidden="true">
                        <title>Trusted Path</title>
                        <reference>ISO/IEC 17799: 10.9.2</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.4.a(14)</reference>
                  </Group>
                  <Group id="SC-12" hidden="true">
                        <title>Cryptographic Key Establishment and Mgmt.</title>
                        <reference>ISO/IEC 17799: 12.3.1, 12.3.2</reference>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
                  <Group id="SC-13" hidden="true">
                        <title>Use of Validated Cryptography</title>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 1.G.1</reference>
                  </Group>
                  <Group id="SC-14" hidden="true">
                        <title>Public Access Protections</title>
                        <reference>ISO/IEC 17799: 10.7.4, 10.9.3</reference>
                        <reference>DOD 8500.2: EBPW-1</reference>
                  </Group>
                  <Group id="SC-15" hidden="true">
                        <title>Collaborative Computing</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: 7.G</reference>
                  </Group>
                  <Group id="SC-16" hidden="true">
                        <title>Transmission of Security Parameters</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.8.2, 10.9.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(3)</reference>
                  </Group>
                  <Group id="SC-17" hidden="true">
                        <title>Public Key Infrastructure Certificates</title>
                        <reference>ISO/IEC 17799: 12.3.2</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-18" hidden="true">
                        <title>Mobile Code</title>
                        <reference>ISO/IEC 17799: 10.4.1, 10.4.2</reference>
                        <reference>DOD 8500.2: DCMC-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 7.E</reference>
                  </Group>
                  <Group id="SC-19" hidden="true">
                        <title>Voice Over Internet Protocol</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: DCID 6/3 2.B.4.d, 9.D.1.a</reference>
                  </Group>
                  <Group id="SC-20" hidden="true">
                        <title>Secure Name Address Resolution Service (Authoritative Source)</title>
                  </Group>
                  <Group id="SC-21" hidden="true">
                        <title>Secure Name Address Resolution Service (Resolution)</title>
                  </Group>
                  <Group id="SC-22" hidden="true">
                        <title>Architecture and Provisioning for Name/Address Resolution Service</title>
                  </Group>
                  <Group id="SC-23" hidden="true">
                        <title>Session Authenticity</title>
                  </Group>
            </Group>
            <Group id="system_and_information_integrity" hidden="true">
                  <title>Applicable 800-53 System and Information Integrity</title>
                  <Group id="SI-1" hidden="true">
                        <title>System and Information Integrity Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5), 5.B.1.b(1), 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="SI-2" hidden="true">
                        <title>Flaw Remediation</title>
                        <reference>ISO/IEC 17799: 10.10.5, 12.4.1, 12.5.1, 12.5.2, 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 11.1.1, 11.1.2, 11.2.2, 11.2.7</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSQ-1, DCCT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(3), 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="SI-3" hidden="true">
                        <title>Malicious Code Protection</title>
                        <reference>ISO/IEC 17799: 10.4.1</reference>
                        <reference>NIST 800-26: 11.1.1, 11.1.2</reference>
                        <reference>DOD 8500.2: ECVP-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.1.a(4), 7.B.4.b(1)</reference>
                  </Group>
                  <Group id="SI-4" hidden="true">
                        <title>Information System Monitoring Tools and Techniques</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.10.1, 10.10.2, 10.10.4</reference>
                        <reference>NIST 800-26: 11.2.5, 11.2.6</reference>
                        <reference>DOD 8500.2: EBBD-1, EBVC-1, ECID-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(5)(b), 4.B.3.a(8)(b), 6.B.3.a(8)</reference>
                  </Group>
                  <Group id="SI-5" hidden="true">
                        <title>Security Alerts and Advisories</title>
                        <reference>ISO/IEC 17799: 6.1.7, 10.4.1</reference>
                        <reference>NIST 800-26: 14.1.1, 14.1.2, 14.1.5</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIVM-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="SI-6" hidden="true">
                        <title>Security Functionality Verification</title>
                        <reference>NIST 800-26: 11.2.1, 11.2.2</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSS-1</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.2.b(2)</reference>
                  </Group>
                  <Group id="SI-7" hidden="true">
                        <title>Software and Information Integrity</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.4</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4</reference>
                        <reference>DOD 8500.2: ECSD-2</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.1.a(3), 5.B.2.a(6)</reference>
                  </Group>
                  <Group id="SI-8" hidden="true">
                        <title>Spam Protection</title>
                        <reference>DCID 6/3: 5.B.1.a(4)</reference>
                  </Group>
                  <Group id="SI-9" hidden="true">
                        <title>Information Input Restrictions</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2</reference>
                        <reference>GAO FISCAM: SD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SI-10" hidden="true">
                        <title>Information Accuracy, Completeness, Validity, and Authenticity</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.1, 12.2.2</reference>
                        <reference>DCID 6/3: 7.B.2.h, 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-11" hidden="true">
                        <title>Error Handling</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.3, 12.2.4</reference>
                        <reference>DCID 6/3: 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-12" hidden="true">
                        <title>Information Output Handling and Retention</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.4</reference>
                        <reference>DOD 8500.2: PESP-1</reference>
                        <reference>DCID 6/3: 2.B.4.d, 8.B.9, 8.G</reference>
                  </Group>
            </Group>
      </Group>
      <!-- ==================================================================================================== -->
      <!-- =====================================  FDCC SECURITY GUIDANCE  ===================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following groups represent the collection of FDCC guidance for Microsoft Windows XP.  For        -->
      <!-- specific recommendations regarding which rules to enable and which values to use, please refer to    -->
      <!-- the XCCDF profiles above.                                                                            -->
      <!--                                                                                                      -->
      <!-- **************************************************************************************************** -->
      <!-- ***  1 - Introduction                                                                            *** -->
      <!-- **************************************************************************************************** -->
      <Group id="introduction">
            <title>Introduction</title>
            <description>This guide has been created to assist federal agencies in effectively securing systems with Microsoft Windows XP based on OMB Federal Desktop Core Configuration recommendations.<xhtml:br/><xhtml:br/>Under the direction of OMB and in collaboration with DHS, DISA, NSA, USAF, and Microsoft, NIST has provided the following baseline to help agencies test, implement, and deploy the Microsoft Windows XP Federal Desktop Core Configuration (FDCC) baseline. The Federal Desktop Core Configuration (FDCC) is an OMB-mandated security configuration.<xhtml:br/><xhtml:br/>Please refer to the FDCC home page for additional information. http://fdcc.nist.gov</description>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  2 - Windows XP Security Guide Development                                                   *** -->
      <!-- **************************************************************************************************** -->
      <Group id="security_guide_development">
            <title>Security Guide Development</title>
            <description>In today's computing environment, the security of all computing resources, from network infrastructure devices to users' desktop computers, is essential. There are many threats to users' computers, ranging from remotely launched network service exploits to malware spread through e-mails, Web sites, and file downloads. Increasing the security of individual computers protects them from these threats and reduces the likelihood that a system will be compromised or that data will be disclosed to unauthorized parties. Effective and well-tested security configurations means that less time and money is spent eradicating malware, restoring systems from backups, and reinstalling operating systems and applications. In addition, having stronger host security increases network security (e.g., home, business, government, the Internet); for example, most distributed denial of service attacks against networks use large numbers of compromised hosts.<xhtml:p/>The goal of this
                  guide is to provide security configuration guidance to the users and system administrators of Microsoft Windows XP systems. This advice can be adapted to any environment, from individual SOHO installations to large geographically diverse organizations. Although the guide is primarily targeted toward business environments and Windows XP Professional, some of the guidance is also appropriate for other XP versions, such as Windows XP Home, Windows XP Tablet PC Edition, and Windows XP Media Center Edition. This guide draws on a large body of vendor knowledge and government and security community experience gained over many years of securing computer systems.<xhtml:p/>This section of the guide is based largely on the steps proposed in NIST’s FISMA Implementation Project for achieving more secure information systems. Sections 2.1 and 2.2 address the need to categorize information and information systems. Each Windows XP system can be classified as having one of three roles;
                  each system can also be classified according to the potential impact caused by security breaches. Section 2.3 describes threats and provides examples of security controls that can mitigate threats. Section 2.4 outlines the primary types of environments for information systems - SOHO, Enterprise, Specialized Security-Limited Functionality, and Legacy - and ties each environment to typical threat categories and security controls. Section 2.5 provides a brief overview of the implementation of the security controls and the importance of performing functionality and security testing. Finally, Section 2.6 discusses the need to monitor the security controls and maintain the system. Figure 2-1 shows the six facets to Windows XP security that are covered in Sections 2.1 through 2.6.<xhtml:p/><xhtml:img class="figure" src="2.1.jpg" title="Figure 2-1. The Facets of Windows XP Security"/>
            </description>
            <Group id="system_roles_and_requirements">
                  <title>Windows XP System Roles and Requirements</title>
                  <description>Windows XP security should take into account the role that the system plays. For the purposes of this guide, Windows XP systems can be divided into three roles: inward-facing, outward-facing, and mobile.<xhtml:p/><xhtml:strong>Inward-Facing:</xhtml:strong> An inward-facing XP system is typically a user workstation on the interior of a network that is not directly accessible from the Internet. Physical access is also generally limited in some manner (e.g., only employees have access to the work area). In many environments, inward-facing systems share a common hardware and software configuration because they are centrally deployed and managed (e.g., Microsoft domains, Novell networks). Because an inward-facing system is usually in the same environment all the time (e.g., desktop on the corporate local area network [LAN]), the threats against the system do not change quickly. In general, inward-facing systems are relatively easy to secure, compared to
                        outward-facing and mobile systems.<xhtml:p/><xhtml:strong>Outward-Facing:</xhtml:strong> An outward-facing XP system is one that is directly connected to the Internet. The classic example is a home computer that connects to the Internet through dial-up or broadband access. Such a system is susceptible to scans, probes, and attacks launched against it by remote attackers. It typically does not have the layers of protection that an inward-facing system typically has, such as network firewalls and intrusion detection systems. Outward-facing systems are often at high risk of compromise because they have relatively high security needs, yet are typically administered by users with little or no security knowledge. Also, threats against outward-facing systems may change quickly since anyone can attempt to attack them at any time.<xhtml:p/><xhtml:strong>Mobile:</xhtml:strong> A system with a mobile role typically moves between a variety of environments and physical
                        locations. For network connectivity, this system might use both traditional wired methods (e.g., Ethernet, dialup) and wireless methods (e.g., IEEE 802.11). The mobility of the system makes it more difficult to manage centrally. It also exposes the system to a wider variety of threat environments; for example, in a single day the system might be in a home environment, an office environment, a wireless network hotspot, and a hotel room. An additional threat is the loss or theft of the system. This could lead to loss of productivity at a minimum, but could also include the disclosure of confidential information or the possible opening of a back door into the organization if remote access is not properly secured.</description>
            </Group>
            <Group id="security_categorization">
                  <title>Security Categorization of Information and Information Systems</title>
                  <description>This section discusses the most significant security features inherited from Windows 2000: Kerberos, smart card support, Internet Connection Sharing, Internet Protocol Security, and Encrypting File System. For each security feature, the section includes a brief description, an analysis of the security impact of each feature, and general recommendations for when the feature should or should not be used. It is outside the scope of this document to cover the features in great depth, so pointers to resources with additional information are provided as needed.<xhtml:p/>The classic model for information security defines three objectives of security: maintaining confidentiality, integrity, and availability. Confidentiality refers to protecting information from being accessed by unauthorized parties. Integrity refers to ensuring the authenticity of information—that information is not altered, and that the source of the information is genuine. Availability means
                        that information is accessible by authorized users. Each objective addresses a different aspect of providing protection for information.<xhtml:p/>Determining how strongly a system needs to be protected is based largely on the type of information that the system processes and stores. For example, a system containing medical records probably needs much stronger protection than a computer only used for viewing publicly released documents. This is not to imply that the second system does not need protection; every system needs to be protected, but the level of protection may vary based on the value of the system and its data. To establish a standard for determining the security category of a system, NIST created Federal Information Processing Standards (FIPS) Publication (PUB) 199, Standards for Security Categorization of Federal Information and Information Systems. FIPS PUB 199 establishes three security categories-low, moderate, and high-based on the potential
                        impact of a security breach involving a particular system. The FIPS PUB 199 definitions for each category are as follows:<xhtml:p/>The potential impact is <xhtml:strong>LOW</xhtml:strong> if the loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals. A limited adverse effect means that, for example, the loss of confidentiality, integrity, or availability might (i) cause a degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced; (ii) result in minor damage to organizational assets; (iii) result in minor financial loss; or (iv) result in minor harm to individuals.<xhtml:p/>The potential impact is <xhtml:strong>MODERATE</xhtml:strong> if the loss of confidentiality, integrity, or availability could be expected to have a
                        serious adverse effect on organizational operations, organizational assets, or individuals. A serious adverse effect means that, for example, the loss of confidentiality, integrity, or availability might (i) cause a significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced; (ii) result in significant damage to organizational assets; (iii) result in significant financial loss; or (iv) result in significant harm to individuals that does not involve loss of life or serious life threatening injuries.<xhtml:p/>The potential impact is <xhtml:strong>HIGH</xhtml:strong> if the loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. A severe or catastrophic adverse effect means that, for example, the
                        loss of confidentiality, integrity, or availability might (i) cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions; (ii) result in major damage to organizational assets; (iii) result in major financial loss; or (iv) result in severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.<xhtml:p/>Each system should be protected based on the potential impact to the system of a loss of confidentiality, integrity, or availability. Protection measures (otherwise known as security controls) tend to fall into two categories. First, security weaknesses in the system need to be resolved. For example, if a system has a known vulnerability that attackers could exploit, the system should be patched so that the vulnerability is removed or mitigated. Second, the system should offer only the required functionality to each
                        authorized user, so that no one can use functions that are not necessary. This principle is known as least privilege. Limiting functionality and resolving security weaknesses have a common goal: give attackers as few opportunities as possible to breach a system.<xhtml:p/>Although each system should ideally be made as secure as possible, this is generally not feasible because the system needs to meet the functional requirements of the system’s users. Another common problem with security controls is that they often make systems less convenient or more difficult to use. When usability is an issue, many users will attempt to circumvent security controls; for example, if passwords must be long and complex, users may write them down. Balancing security, functionality, and usability is often a challenge. This guide attempts to strike a proper balance and make recommendations that provide a reasonably secure solution while offering the functionality and usability that
                        users require.<xhtml:p/>Another fundamental principle endorsed by this guide is using multiple layers of security. For example, a host may be protected from external attack by several controls, including a network-based firewall, a host-based firewall, and OS patching. The motivation for having multiple layers is that if one layer fails or otherwise cannot counteract a certain threat, other layers might prevent the threat from successfully breaching the system. A combination of network-based and host-based controls is generally most effective at providing consistent protection for systems.<xhtml:p/>NIST SP 800-53, Recommended Security Controls for Federal Information Systems, proposes minimum baseline management, operational, and technical security controls for information systems. These controls are to be implemented based on the security categorizations proposed by FIPS 199, as described earlier in this section. This guidance should assist agencies in meeting
                        baseline requirements for Windows XP Professional systems deployed in their environments.</description>
            </Group>
            <Group id="baseline_security_controls">
                  <title>Baseline Security Controls and Threat Analysis Refinement</title>
                  <description>To secure a system, it is essential first to define the threats that need to be mitigated. This knowledge of threats is also key to understanding the reasons the various configuration options have been chosen in this guide. Most threats against data and resources are possible because of mistakes—either bugs in operating system and application software that create exploitable vulnerabilities, or errors made by users and administrators. Threats may involve intentional actors (e.g., an attacker who wants to access credit cards on a system) or unintentional actors (e.g., an administrator who forgets to disable user accounts of a terminated employee). Threats can be local, such as a disgruntled employee, or remote, such as an attacker in another country. The following sections describe each major threat category, list possible controls, provide examples of threats, and summarize the potential impact of the threat. The list of threats is not exhaustive; it
                        simply represents the major threat categories that were considered during the selection of the security controls as described in this guide. Organizations should conduct risk assessments to identify the specific threats against their systems and determine the effectiveness of existing security controls in counteracting the threats, then perform risk mitigation to decide what additional measures (if any) should be implemented.<xhtml:p/>This section has describes various types of local and remote threats that can negatively impact systems. The possible controls listed for the threats are primarily technical, as are the controls discussed throughout this document. However, it is important to further reduce the risks of operating a Windows XP system by also using management and operational controls. Examples of important operational controls are restricting physical access to a system; performing contingency planning, backing up the system, storing the backups in a
                        safe and secure location, and testing the backups regularly; and monitoring Microsoft mailing lists for relevant security bulletins. Management controls could include developing policies regarding Windows XP system security and creating a plan for maintaining Windows XP systems. By selecting and implementing management, operational, and technical controls for Windows XP, organizations can better mitigate the threats that Windows XP systems may face.<xhtml:p/>Another reason to use multiple types of controls is to provide better security in situations where one or more controls are circumvented or otherwise violated. This may be done not only by attackers, but also by authorized users with no malicious intent. For example, taping a list of passwords to a monitor for convenience may nullify controls designed to prevent unauthorized local access to that system. Establishing a policy against writing down passwords (management control), educating users on the dangers
                        of password exposure (operational control), and performing periodic physical audits to identify posted passwords (operational control) may all be helpful in reducing the risks posed by writing down</description>
                  <Group id="local_threats">
                        <title>Local Threats</title>
                        <description>Local threats either require physical access to the system or logical access to the system (e.g., an authorized user account). Local threats are grouped into three categories: boot process, unauthorized local access, and privilege escalation.</description>
                        <Group id="boot_process">
                              <title>Boot Process</title>
                              <description>
                                    <xhtml:ul>
                                          <xhtml:li><xhtml:strong>Threat:</xhtml:strong> An unauthorized individual boots a computer from third-party media (e.g., removable drives, Universal Serial Bus [USB] token storage devices). This could permit the attacker to circumvent operating system (OS) security measures and gain unauthorized access to information.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Examples:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>While traveling, an employee misplaces a laptop, and the party that acquires it tries to see what sensitive data it contains.</xhtml:li>
                                                      <xhtml:li>A disgruntled employee boots a computer off third-party media to circumvent other security controls so the employee can access sensitive files (e.g., confidential data stored locally, local password file).</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                          <xhtml:li><xhtml:strong>Impact:</xhtml:strong> Unauthorized parties could cause a loss of confidentiality, integrity, and availability.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Possible Controls:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>Implement physical security measures (e.g., locked doors, badge access) to restrict access to equipment.</xhtml:li>
                                                      <xhtml:li>Enable a strong and difficult-to-guess password for the Basic Input Output System (BIOS), and configure the BIOS to boot the system from the local hard drive only, assuming that the case containing the OS and data is physically secure. This will help protect the data unless the hard drive is removed from the computer.</xhtml:li>
                                                      <xhtml:li>Secure local files via encryption to prevent access to data in the event the physical media is placed in another computer.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                    </xhtml:ul>
                              </description>
                        </Group>
                        <Group id="unauthorized_local_access">
                              <title>Unauthorized Local Access</title>
                              <description>
                                    <xhtml:ul>
                                          <xhtml:li><xhtml:strong>Threat:</xhtml:strong> An individual who is not permitted to access a system gains local access.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Examples:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>A visitor to a company sits down at an unattended computer and logs in by guessing a weak password for a default user account.</xhtml:li>
                                                      <xhtml:li>A former employee gains physical access to facilities and uses old credentials to log in and gain access to company resources.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                          <xhtml:li><xhtml:strong>Impact:</xhtml:strong> Because the unauthorized person is masquerading as an authorized user, this could cause a loss of confidentiality and integrity; if the user has administrative rights, this could also cause a loss of availability.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Possible Controls:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>Require valid username and password authentication before allowing any access to system resources, and enable a password-protected screen saver. These actions help to prevent an attacker from walking up to a computer and immediately gaining access.</xhtml:li>
                                                      <xhtml:li>Enable a logon banner containing a warning of the possible legal consequences of misuse.</xhtml:li>
                                                      <xhtml:li>Implement a password policy to enforce stronger passwords, so that it is more difficult for an attacker to guess passwords.</xhtml:li>
                                                      <xhtml:li>Do not use or reuse a single password across multiple accounts; for example, the password for a personal free e-mail account should not be the same as that used to gain access to the Windows XP host.</xhtml:li>
                                                      <xhtml:li>Establish and enforce a checkout policy for departing employees that includes the immediate disabling of their user accounts.</xhtml:li>
                                                      <xhtml:li>Physically secure removable storage devices and media, such as CD-ROMs, that contain valuable information. An individual who gains access to a workspace may find it easier to take removable media than attempt to get user-level access on a system.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                    </xhtml:ul>
                              </description>
                        </Group>
                        <Group id="privilege_escalation">
                              <title>Privilege Escalation</title>
                              <description>
                                    <xhtml:ul>
                                          <xhtml:li><xhtml:strong>Threat:</xhtml:strong> An authorized user with normal user-level rights escalates the account’s privileges to gain administrator-level access.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Examples:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>A user takes advantage of a vulnerability in a service to gain administrator-level privileges and access another user’s files.</xhtml:li>
                                                      <xhtml:li>A user guesses the password for an administrator-level account, gains full access to the system, and disables several security controls.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                          <xhtml:li><xhtml:strong>Impact:</xhtml:strong> Because the user is gaining full privileges on the system, this could cause a loss of confidentiality, integrity, and availability.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Possible Controls:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>Restrict access to all administrator-level accounts and administrative tools, configuration files, and settings. Use strong, difficult-to-guess passwords for all administrator-level accounts. Do not use the domain administrator accounts from non-administrative client hosts. These actions will make it more difficult for users to escalate their privileges.</xhtml:li>
                                                      <xhtml:li>Disable unused local services. Vulnerabilities in these services may permit users to escalate their privileges.</xhtml:li>
                                                      <xhtml:li>Install application and OS updates (e.g., hotfixes, service packs, patches). These updates will resolve system vulnerabilities, reducing the number of attack vectors that can be used.</xhtml:li>
                                                      <xhtml:li>Encrypt sensitive data. Even administrator-level access would not permit a user to access data in encrypted files.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                    </xhtml:ul>
                              </description>
                        </Group>
                  </Group>
                  <Group id="remote_threats">
                        <title>Remote Threats</title>
                        <description>Unlike local threats, remote threats do not require physical or logical access to the system. The categories of remote threats described in this section are network services, data disclosure, and malicious payloads.</description>
                        <Group id="network_services">
                              <title>Network Services</title>
                              <description>
                                    <xhtml:ul>
                                          <xhtml:li><xhtml:strong>Threat:</xhtml:strong> Remote attackers exploit vulnerable network services on a system. This includes gaining unauthorized access to services and data, and causing a denial of service (DoS) condition.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Examples:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>A worm searches for systems with an unsecured service listening on a particular port, and then uses the service to gain full control of the system.</xhtml:li>
                                                      <xhtml:li>An attacker gains access to a system through a service that did not require authentication.</xhtml:li>
                                                      <xhtml:li>An attacker impersonates a user by taking advantage of a weak remote access protocol.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                          <xhtml:li><xhtml:strong>Impact:</xhtml:strong> Depending on the type of network service that is being exploited, this could cause a loss of confidentiality, integrity, and availability.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Possible Controls:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>Disable unused services. This provides attackers with fewer chances to breach the system.</xhtml:li>
                                                      <xhtml:li>Test and install application and OS updates (e.g., hotfixes, service packs, patches). These updates will resolve system software vulnerabilities, reducing the number of attack vectors that can be used.</xhtml:li>
                                                      <xhtml:li>Require strong authentication before allowing access to the service. Implement a password policy to enforce stronger passwords that are harder to guess. Establish and enforce a checkout policy for departing employees that includes the immediate disabling of their user accounts. These actions help to ensure that only authorized users can access each service.</xhtml:li>
                                                      <xhtml:li>Do not use weak remote access protocols and applications; instead, use only accepted, industry standard strong protocols (e.g., Internet Protocol Security [IPsec], Secure Shell [SSH], Transport Layer Security [TLS]) for accessing and maintaining systems remotely.</xhtml:li>
                                                      <xhtml:li>Use firewalls or packet filters to restrict access to each service to the authorized hosts only. This prevents unauthorized hosts from gaining access to the services and also prevents worms from propagating from one host to other hosts on the network.</xhtml:li>
                                                      <xhtml:li>Enable logon banners containing a warning of the possible legal consequences of misuse.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                    </xhtml:ul>
                              </description>
                        </Group>
                        <Group id="data_disclosure">
                              <title>Data Disclosure</title>
                              <description>
                                    <xhtml:ul>
                                          <xhtml:li><xhtml:strong>Threat:</xhtml:strong> A third party intercepts confidential data sent over a network.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Examples:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>On a nonswitched network, a third party is running a network monitoring utility. When a legitimate user transmits a file in an insecure manner, the third party captures the file and accesses its data.</xhtml:li>
                                                      <xhtml:li>An attacker intercepts usernames and passwords sent in plaintext over a local network segment.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                          <xhtml:li><xhtml:strong>Impact:</xhtml:strong> The interception of data could lead to a loss of confidentiality. If authentication data (e.g., passwords) are intercepted, it could cause a loss of confidentiality and integrity, and possibly a loss of availability, if the intercepted credentials have administrator-level privileges.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Possible Controls:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>Use switched networks, which make it more difficult to sniff packets.</xhtml:li>
                                                      <xhtml:li>Use a secure user identification and authentication system, such as NT LanManager version 2 (NTLMv2) or Kerberos. Section 3.2.1 contains a discussion of the choices that Windows XP provides.</xhtml:li>
                                                      <xhtml:li>Encrypt network communications or application data through the use of various protocols (e.g., TLS, IPsec, SSH). This protects the data from being accessed by a third party.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                    </xhtml:ul>
                              </description>
                        </Group>
                        <Group id="malicious_payloads">
                              <title>Malicious Payloads</title>
                              <description>
                                    <xhtml:ul>
                                          <xhtml:li><xhtml:strong>Threat:</xhtml:strong> Malicious payloads such as viruses, worms, Trojan horses, and active content attack systems through many vectors. End users of the system may accidentally trigger malicious payloads.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Examples:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>A user visits a Web site and downloads a free game that includes a Trojan horse. When the user installs the game on her computer, the Trojan horse is also installed, which compromises the system.</xhtml:li>
                                                      <xhtml:li>A user with administrative-level privileges surfs the Web and accidentally visits a malicious Web site, which successfully infects the user’s system.</xhtml:li>
                                                      <xhtml:li>A user installs and operates peer-to-peer (P2P) file sharing software to download music files, and the P2P software installs spyware programs onto the system.</xhtml:li>
                                                      <xhtml:li>A user opens and executes a payload that was attached to a spam or spoofed message.</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                          <xhtml:li><xhtml:strong>Impact:</xhtml:strong> Malware often gains full administrative-level privileges to the system, or inadvertently crashes the system. Malware may cause a loss of confidentiality, integrity, and availability.</xhtml:li>
                                          <xhtml:li>
                                                <xhtml:strong>Possible Controls:</xhtml:strong>
                                                <xhtml:ul>
                                                      <xhtml:li>Educate users on avoiding malware infections, and make them aware of local policy regarding the use of potential transmission methods such as instant messaging (IM) software and P2P file sharing services. Users who are familiar with the techniques for spreading malware should be less likely to infect their systems.</xhtml:li>
                                                      <xhtml:li>Use antivirus software and spyware detection and removal utilities as an automated way of preventing most infections and detecting the infections that were not prevented.</xhtml:li>
                                                      <xhtml:li>Use e-mail clients that support spam filtering—automatically detecting and quarantining messages that are known to be spam or have the same characteristics as typical spam.</xhtml:li>
                                                      <xhtml:li>Do not install or use non-approved applications (e.g., P2P, IM) to connect to unknown servers. Educate users regarding the potential impact caused by the use of P2P, IM, and other untrusted software applications.</xhtml:li>
                                                      <xhtml:li>Operate the system on a daily basis with a limited user account. Only use administrator-level accounts when needed for specific maintenance tasks. Many instances of malware cannot successfully infect a system unless the current user has administrative privileges.</xhtml:li>
                                                      <xhtml:li>Configure server and client software such as e-mail servers and clients, Web proxy servers and clients, and productivity applications to reduce exposure to malware. For example, email servers and clients could be configured to block e-mail attachments with certain file extensions. This should help to reduce the likelihood of infections.</xhtml:li>
                                                      <xhtml:li>Configure systems, particularly in specialized security-limited functionality environments, so that the default file associations prevent automatic execution of active content files (e.g., Java, JavaScript, ActiveX).</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                    </xhtml:ul>
                              </description>
                        </Group>
                  </Group>
            </Group>
            <Group id="environments_and_security_controls_documentation">
                  <title>Environments and Security Controls Documentation</title>
                  <description>The section describes the types of environments in which a Windows XP host may be deployed - SOHO, enterprise, and custom - as described in the NIST Security Configuration Checklists Program for IT Products. The two typical custom environments for Windows XP are specialized security-limited functionality, which is for systems at high risk of attack or data exposure, with security taking precedence over functionality, and legacy, which is intended for situations in which the Windows XP system has special needs that do not fit into the other profiles, such as a requirement for backward compatibility with legacy applications or servers. Each environment description also summarizes the primary threats and controls that are typically part of the environment. In addition to documenting controls, every environment should have other various security-related documentation, such as acceptable use policies and security awareness materials, that affects configuration
                        and usage of systems and applications. The last part of this section lists some common types of security-related documentation.</description>
                  <Group id="soho">
                        <title>SOHO</title>
                        <description>SOHO, sometimes called standalone, describes small, informal computer installations that are used for home or business purposes. SOHO encompasses a variety of small-scale environments and devices, ranging from laptops, mobile devices, and home computers, to telecommuting systems located on broadband networks, to small businesses and small branch offices of a company. Figure 2-2 shows a typical SOHO network architecture. Historically, SOHO environments are the least secured and most trusting. Generally, the individuals performing SOHO system administration are less knowledgeable about security. This often results in environments that are less secure than they need to be because the focus is generally on functionality and ease of use. A SOHO system might not use any security software (e.g., antivirus software, personal firewall). In some instances, there are no network-based controls such as firewalls, so SOHO systems may be directly exposed to
                              external attacks. Therefore, SOHO environments are frequently targeted for exploitation—not necessarily to acquire information, but more commonly to be used for attacking other computers, or incidentally as collateral damage from the propagation of a worm.<xhtml:p/><xhtml:img class="figure" src="2.2.jpg" title="Figure 2-2. Typical SOHO Network Architecture"/><xhtml:p/>Because the primary threats in SOHO environments are external, and SOHO computers generally have less restrictive security policies than enterprise or specialized security-limited functionality computers, they tend to be most vulnerable to attacks from remote threat categories. (Although remote threats are the primary concern for SOHO environments, it is still important to protect against other threats.) SOHO systems are typically threatened by attacks against network services and by malicious payloads (e.g., viruses, worms). These attacks are most likely to affect availability (e.g.,
                              crashing the system, consuming all network bandwidth, breaking functionality) but may also affect integrity (e.g., infecting data files) and confidentiality (e.g., providing remote access to sensitive data, e-mailing data files to others).<xhtml:p/>SOHO security is improving with the proliferation of small, inexpensive, hardware-based firewall routers that protect to some degree the SOHO machines behind them. The adoption of personal firewalls (e.g., BlackICE, ZoneAlarm, Windows Firewall) is also helping to better secure SOHO environments. Another key to SOHO security is strengthening the hosts on the SOHO network by patching vulnerabilities and altering settings to restrict unneeded functionality.</description>
                  </Group>
                  <Group id="enterprise">
                        <title>Enterprise</title>
                        <description>The enterprise environment, also known as a managed environment, is typically comprised of large organizational systems with defined, organized suites of hardware and software configurations, usually consisting of centrally managed workstations and servers protected from threats on the Internet with firewalls and other network security devices. Figure 2-3 shows a typical enterprise network architecture. Enterprise environments generally have a group dedicated to supporting users and providing security. The combination of structure and skilled staff allows better security practices to be implemented during initial system deployment and in ongoing support and maintenance. Enterprise installations typically use a domain model to effectively manage a variety of settings and allow the sharing of resources (e.g., file servers, printers). The enterprise can enable only the services needed for normal business operations, with other possible avenues of
                              exploit removed or disabled. Authentication, account, and policy management can be administered centrally to maintain a consistent security posture across an organization.<xhtml:p/>The enterprise environment is more restrictive and provides less functionality than the SOHO environment. Managed environments typically have better control on the flow of various types of traffic, such as filtering traffic based on protocols and ports at the enterprise’s connections with external networks. Because of the supported and largely homogeneous nature of the enterprise environment, it is typically easier to use more functionally restrictive settings than it is in SOHO environments. Enterprise environments also tend to implement several layers of defense (e.g., firewalls, antivirus servers, intrusion detection systems, patch management systems, e-mail filtering), which provides greater protection for systems. In many enterprise environments, interoperability with
                              legacy systems may not be a major requirement, further facilitating the use of more restrictive settings. In an enterprise environment, this guide should be used by advanced users and system administrators. The enterprise environment settings correspond to an enterprise security posture that will protect the information in a moderate risk environment.<xhtml:p/>In the enterprise environment, systems are typically susceptible to local and remote threats. In fact, threats often encompass all the categories of threats defined in Section 2.3. Local attacks, such as unauthorized usage of another user’s workstation, most often lead to a loss of confidentiality (e.g., unauthorized access to data) but may also lead to a loss of integrity (e.g., data modification) or availability (e.g., theft of a system). Remote threats may be posed not only by attackers outside the organization, but also by internal users who are attacking other internal systems across the
                              organization’s network. Most security breaches caused by remote threats involve malicious payloads sent by external parties, such as viruses and worms acquired via e-mail or infected Web sites. Threats against network services tend to payloads and network service attacks are most likely to affect availability (e.g., crashing the system, consuming all network bandwidth, breaking functionality) but may also affect integrity (e.g., infecting data files) and confidentiality (e.g., providing remote access to sensitive data). Data disclosure threats tend to come from internal parties who are monitoring traffic on local networks, and they primarily affect confidentiality.<xhtml:p/><xhtml:img class="figure" src="2.3.jpg" title="Figure 2-3. Typical Enterprise Network Architecture"/>
                        </description>
                  </Group>
                  <Group id="specialized_security_limited_functionality">
                        <title>Specialized Security-Limited Functionality</title>
                        <description>A specialized security-limited functionality environment is any environment, networked or standalone, that is at high risk of attack or data exposure. Figure 2-4 shows examples of systems that are often found in specialized security-limited functionality environments, including outward-facing Web, e-mail, and DNS servers, and firewalls. Typically, providing sufficiently strong protection for these systems involves a significant reduction in system functionality. It assumes systems have limited or specialized functionality in a highly threatened environment such as an outward facing firewall or public Web server, or whose data content or mission purpose is of such value that aggressive trade-offs in favor of security outweigh the potential negative consequences to other useful system attributes such as legacy applications or interoperability with other systems. The specialized security-limited functionality environment encompasses computers that
                              contain highly confidential information (e.g., personnel records, medical records, financial information) and perform vital organizational functions (e.g., accounting, payroll processing, air traffic control). These computers might be targeted by third parties for exploitation, but also might be targeted by trusted parties inside the organization.<xhtml:p/>A specialized security-limited functionality environment could be a subset of a SOHO or enterprise environment. For example, three desktops in an enterprise environment that hold confidential employee data could be thought of as a specialized security-limited functionality environment within an enterprise environment. In addition, a laptop used by a mobile worker might be a specialized security-limited functionality environment within a SOHO environment. A specialized security-limited functionality environment might also be a self-contained environment outside any other environment—for instance, a
                              government security installation dealing in sensitive data.<xhtml:p/>Systems in specialized security-limited functionality environments face the same threats as systems in enterprise environments. Threats from both insiders and external parties are a concern. Because of the risks and possible consequences of a compromise in a specialized security-limited functionality environment, it usually has the most functionally restrictive and secure configuration. The suggested configuration is complex and provides the greatest protection at the expense of ease of use, functionality, and remote system management. In a specialized security-limited functionality environment, this guide is targeted at experienced security specialists and seasoned system administrators who understand the impact of implementing these strict requirements.<xhtml:p/><xhtml:img class="figure" src="2.4.jpg" title="Figure 2-4. Examples of Specialized Security-Limited Functionality Systems"/>
                        </description>
                  </Group>
                  <Group id="legacy" selected="true">
                        <title>Legacy</title>
                        <description>A legacy environment contains older systems or applications that use outdated communication mechanisms. This most often occurs when machines operating in a legacy environment need more open security settings so they can communicate to the appropriate resources. For example, a system may need to use services and applications that require insecure authentication mechanisms such as null user sessions or open pipes. Because of these special needs, the system does not fit into any of the standard environments; therefore, it should be classified as a legacy environment system. Legacy environments may exist within SOHO and enterprise environments, and in rare cases within specialized security-limited functionality environments as well. Depending on the situation, a legacy environment may face any combination of internal and external threats. The potential impact of the threats should be determined by considering the threats that the system faces (as
                              described in the previous three sections) and then considering what additional risk the system has because of the legacy accommodations.</description>
                  </Group>
                  <Group id="security_documentation">
                        <title>SecurityDocumentation</title>
                        <description>An organization typically has many documents related to the security of Windows XP systems. Foremost among the documents is a Windows XP security configuration guide that specifies how Windows XP systems should be configured and secured. As mentioned in Section 2.2, NIST SP 800-53 proposes management, operational, and technical security controls for systems, each of which should have associated documentation. In addition to documenting procedures for implementing and maintaining various controls, every environment should also have other security-related policies and documentation that affect the configuration, maintenance, and usage of systems and applications. Examples of such documents are as follows:<xhtml:p/>
                              <xhtml:ul>
                                    <xhtml:li>Rules of behavior and acceptable use policy</xhtml:li>
                                    <xhtml:li>Configuration management policy, plan, and procedures</xhtml:li>
                                    <xhtml:li>Authorization to connect to the network</xhtml:li>
                                    <xhtml:li>IT contingency plans</xhtml:li>
                                    <xhtml:li>Security awareness and training for end users and administrators.</xhtml:li>
                              </xhtml:ul>
                        </description>
                  </Group>
            </Group>
            <Group id="implementation_and_testing_of_security_controls">
                  <title>Implementation and Testing of Security Controls</title>
                  <description>Implementing security controls can be a daunting task. As described in Section 2.2, many security controls have a negative impact on system functionality and usability. In some cases, a security control can even have a negative impact on other security controls. For example, installing a patch could inadvertently break another patch, or enabling a firewall could inadvertently block antivirus software from automatically updating its signatures or disrupt patch management software, remote management software and other security and maintenance-related utilities. Therefore, it is important to perform testing for all security controls to determine what impact they have on system security, functionality, and usability, and to take appropriate steps to address any significant issues.<xhtml:p/>As described in Section 5, NIST has compiled a set of security templates, as well as additional recommendations for security-related configuration changes. The controls
                        proposed in this guide and the NIST Windows XP security templates are consistent with the FISMA controls, as discussed in Section 2.2. The NIST template for Specialized Security-Limited Functionality environments represents the consensus settings from CIS, DISA, Microsoft, NIST, NSA, and USAF; the other NIST templates are based on Microsoft’s templates and recommendations.<xhtml:p/>Although the guidance presented in this document has undergone considerable testing, every system is unique, so it is certainly possible for certain settings to cause unexpected problems. System administrators should perform their own testing, especially for the applications used by their organizations, to identify any functionality or usability problems before the guidance is deployed throughout organizations. It is also critical to confirm that the desired security settings have been implemented properly and are working as expected. See Section 4.4 for information on tools that can
                        identify security-related misconfigurations and vulnerabilities on Windows XP systems.</description>
            </Group>
            <Group id="monitoring_and_maintenance">
                  <title>Monitoring and Maintenance</title>
                  <description>Every system needs to be monitored and maintained on a regular basis so that security issues can be identified and mitigated promptly, reducing the likelihood of a security breach. However, no matter how carefully systems are monitored and maintained, incidents may still occur, so organizations should be prepared to respond to them. Depending on the environment, some preventative actions may be partially or fully automated. Guidance on performing various monitoring and maintenance activities is provided in subsequent sections of this document or other NIST publications. Recommended actions include the following:<xhtml:p/>
                        <xhtml:ul>
                              <xhtml:li>Subscribing to and monitoring various vulnerability notification mailing lists (e.g., Microsoft Security Notification Service)</xhtml:li>
                              <xhtml:li>Acquiring and installing software updates (e.g., OS and application patches, antivirus signatures)</xhtml:li>
                              <xhtml:li>Monitoring event logs to identify problems and suspicious activity</xhtml:li>
                              <xhtml:li>Providing remote system administration and assistance</xhtml:li>
                              <xhtml:li>Monitoring changes to OS and software settings</xhtml:li>
                              <xhtml:li>Protecting and sanitizing media</xhtml:li>
                              <xhtml:li>Responding promptly to suspected incidents</xhtml:li>
                              <xhtml:li>Assessing the security posture of the system through vulnerability assessments</xhtml:li>
                              <xhtml:li>Disabling unneeded user accounts and deleting accounts that have been disabled for some time</xhtml:li>
                              <xhtml:li>Maintaining system, peripheral, and accessory hardware (periodically and as needed), and logging all hardware maintenance activities.</xhtml:li>
                        </xhtml:ul>
                  </description>
            </Group>
            <Group id="summary_recommendations_2">
                  <title>Summary of Recommendations</title>
                  <description>
                        <xhtml:ul>
                              <xhtml:li>Protect each system based on the potential impact to the system of a loss of confidentiality, integrity, or availability.</xhtml:li>
                              <xhtml:li>Reduce the opportunities that attackers have to breach a system by resolving security weaknesses and limiting functionality according to the principle of least privilege.</xhtml:li>
                              <xhtml:li>Select security controls that provide a reasonably secure solution while supporting the functionality and usability that users require.</xhtml:li>
                              <xhtml:li>Use multiple layers of security so that if one layer fails or otherwise cannot counteract a certain threat, other layers might prevent the threat from successfully breaching the system.</xhtml:li>
                              <xhtml:li>Conduct risk assessments to identify threats against systems and determine the effectiveness of existing security controls in counteracting the threats. Perform risk mitigation to decide what additional measures (if any) should be implemented.</xhtml:li>
                              <xhtml:li>Document procedures for implementing and maintaining security controls. Maintain other security-related policies and documentation that affect the configuration, maintenance, and usage of systems and applications, such as acceptable use policy, configuration management policy, and IT contingency plans.</xhtml:li>
                              <xhtml:li>Test all security controls, including the settings in the NIST security templates, to determine what impact they have on system security, functionality, and usability. Take appropriate steps to address any significant issues before applying the controls to production systems.</xhtml:li>
                              <xhtml:li>Monitor and maintain systems on a regular basis so that security issues can be identified and mitigated promptly. Actions include acquiring and installing software updates, monitoring event logs, providing remote system administration and assistance, monitoring changes to OS and software settings, protecting and sanitizing media, responding promptly to suspected incidents, performing vulnerability assessments, disabling and deleting unused user accounts, and maintaining hardware.</xhtml:li>
                        </xhtml:ul>
                  </description>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  3 - Windows XP Security Components Overview                                                 *** -->
      <!-- **************************************************************************************************** -->
      <Group id="security_components_overview">
            <title>Windows XP Security Components Overview</title>
            <description>This section presents an overview of the various security features offered by the Windows XP Professional operating system (OS). Many of the components have been inherited from Windows 2000, often with improvements and enhancements. Windows XP also includes several new security features. This guide provides general descriptions of most of these features, with pointers or links to more detailed information whenever possible.</description>
            <Group id="new_features">
                  <title>New Features in Windows XP</title>
                  <description>Windows XP comes with several new security features. Each new security feature is briefly described below, and most also include a reference to a Microsoft Web page that contains more detailed information. This section also includes an analysis of the security impact of each feature and general recommendations for when the feature should or should not be used. The new security features in Windows XP are as follows:</description>
                  <Group id="networking_features">
                        <title>Networking Features</title>
                        <description>Networking Features</description>
                        <Group id="windows_firewall">
                              <title>Windows Firewall</title>
                              <description>Windows Firewall is a stateful personal firewall. When properly configured, it limits the access that other computers have to the Windows XP machine through the network. This significantly reduces the exposure of the machine to network-based attacks such as the Blaster worm. Windows Firewall can also be used to protect shares when a mobile computer is used outside its normal secure and trusted environment, or to protect access to network shares on an untrusted network. Domain administrators can disable the use of Windows Firewall through Group Policy, but this is generally not recommended unless it is interfering with required functionality or a third party firewall is already in use. Administrators can also use Group Policy to set any Windows Firewall configuration option. Windows Firewall can add another layer to a network security model in enterprise and specialized security-limited functionality environments, and it is sometimes the only
                                    layer of network defense in SOHO environments.</description>
                        </Group>
                        <Group id="network_bridging">
                              <title>Network Bridging</title>
                              <description>A network bridge allows two dissimilar networks (e.g., Ethernet and dialup, wireless, or token ring) to be joined without using expensive, dedicated hardware. The connection between the two networks is transparent, meaning that no network address translation occurs between the networks and the actual assigned addresses on each network are visible on the other network. While bridging does permit two networks to be joined with a minimal amount of work, it has serious security implications. If a personal firewall such as Windows Firewall is not enabled and configured correctly, the bridge will provide no network security protection to either of the networks that it connects, exposing them to attacks from each other. A network bridge can expose systems on multiple networks to additional threats, so NIST does not recommend implementing a bridge using a Windows XP computer unless it is specifically needed for a task, and risk assessment and
                                    mitigation have been performed.</description>
                        </Group>
                        <Group id="remote_assistance">
                              <title>Remote Assistance</title>
                              <description>RA provides a way to get remote technical support assistance when running into problems with a computer. RA sessions can be initiated through the Windows Messenger facility, e-mail requests, and via a Web e-mail service (filling out a form to request assistance). Unfortunately, if RA is configured improperly, unauthorized parties could use it to gain remote access to a system. Therefore, RA should be used only if experienced security administrators are available to configure it to strictly limit its usage, and if the network perimeter (e.g., firewall) is configured to prevent external parties from using RA to access internal machines. Otherwise, RA should be disabled.</description>
                        </Group>
                        <Group id="remote_desktop">
                              <title>Remote Desktop</title>
                              <description>The Remote Desktop feature allows a user to remotely access a Windows XP Professional system from another computer. This provides another method for remote attackers to attempt to gain access to the computer by guessing passwords for default accounts. In general, Remote Desktop should only be used if several other layers of security controls are in place, preventing the system from being directly exposed to attackers. Even then, administrators should carefully consider the business need for having remote access to the system and should think of possible alternatives that will not expose the system to attack.</description>
                        </Group>
                        <Group id="wireless_auto_configuration">
                              <title>Wireless Auto Configuration</title>
                              <description>When a wireless network interface card (NIC) is present, the computer will automatically attempt to join any wireless networks it detects in an established list of preferred networks. This allows a computer to easily roam from access point (AP) to access point without reconfiguration, which is beneficial. However, the system may reveal service set identifier (SSID) information for preferred and previously connected access points, which could be captured by an attacker and used to set up a rogue access point. Because Wireless Auto Configuration can be set to connect to any wireless network, a rogue access point could fool the computer into connecting to a hostile network, which could attack the computer or capture data from it. NIST recommends that systems not be set to attempt to connect to any wireless network automatically.</description>
                        </Group>
                        <Group id="wireless_security">
                              <title>Wireless Security</title>
                              <description>To provide a better solution for wireless security, an industry group called the Wi-Fi Alliance has created a product certification called Wi-Fi Protected Access (WPA). In Windows XP SP2, hosts with WPA-supporting wireless NICs can use the features provided by WPA, such as using Advanced Encryption Security (AES) for encrypting network communications. Section 7.8 provides recommendations for wireless security, including the use of WPA.</description>
                        </Group>
                        <Group id="tcpip_raw_socket_restrictions">
                              <title>TCP/IP Raw Socket Restrictions</title>
                              <description>A change introduced in Windows XP SP2 that may impact some users is a restriction on raw sockets for the TCP/IP stack. Some security tools, such as network vulnerability scanners, use raw sockets to craft packets. Windows XP SP2 limits the number of incomplete outbound packets per second, which may break such security tools.</description>
                        </Group>
                  </Group>
                  <Group id="authentication_and_authorization">
                        <title>Authentication and Authorization</title>
                        <description>todo - description needed</description>
                  </Group>
                  <Group id="other_new_features">
                        <title>Other</title>
                        <description>todo - description needed</description>
                  </Group>
            </Group>
            <Group id="security_features_inherited">
                  <title>Security Features Inherited from Windows 2000</title>
                  <description>This section discusses the most significant security features inherited from Windows 2000: Kerberos, smart card support, Internet Connection Sharing, Internet Protocol Security, and Encrypting File System. For each security feature, the section includes a brief description, an analysis of the security impact of each feature, and general recommendations for when the feature should or should not be used. It is outside the scope of this document to cover the features in great depth, so pointers to resources with additional information are provided as needed.</description>
                  <Group id="kerberos">
                        <title>Kerberos</title>
                        <description>In a domain, Windows XP Professional provides support for MIT Kerberos v.5 authentication, as defined in Internet Engineering Task Force (IETF) Request for Comment (RFC) 1510. The Kerberos protocol is composed of three subprotocols: Authentication Service (AS) Exchange, Ticket-Granting Service (TGS) Exchange, and Client/Server (CS) Exchange. The Kerberos v.5 standard can be used only in pure Windows domain environments. Windows domain members use Kerberos as the default network client/server authentication protocol, replacing the older and less secure NTLM and LanManager (LM) authentication methods. The older methods are still supported to allow legacy Windows clients to authenticate to a Windows domain environment. Windows XP Professional standalone workstations and members of NT domains do not use Kerberos to perform local authentication; they use the traditional NTLM. Because Kerberos provides stronger protection for logon credentials than older
                              authentication methods, it should be used whenever possible. NIST recommends disabling LM and NTLM v1 in specialized security-limited functionality environments, and disabling LM in the other environments.</description>
                  </Group>
                  <Group id="smart_sard_support">
                        <title>Smart Card Support</title>
                        <description>In the past, interactive logon meant an ability to authenticate a user to a network by using a form of a shared credential, such as a hashed password. Windows XP Professional supports public-key interactive logon by using a X.509 v.3 certificate stored on a smart card. (This can be used only to log on to domain accounts, not local accounts, unless third party software has replaced the built-in graphical identification and authentication [GINA].) Instead of a password, the user types a personal identification number (PIN) to the GINA, and the PIN authenticates the user to the card. This process is fully integrated with the Microsoft implementation of Kerberos. Smart card-based authentication is appropriate for specialized security-limited functionality environments in which strong authentication is required, and one-factor authentication (username and password) is insufficient. Smart cards provide two-factor authentication, because users must possess
                              the physical smart card and must know the PIN. If smart cards or other types of authentication tokens are being used, the organization should have a policy and procedures in place to educate users on properly using tokens (e.g., not sharing them with other users) and protecting them (e.g., immediately reporting a lost or stolen token).</description>
                  </Group>
                  <Group id="InternetConnectionSharing" selected="true">
                        <title>Internet Connection Sharing</title>
                        <description>Internet Connection Sharing (ICS) allows a Windows XP system to share an Internet connection with other computers. ICS is most often used in SOHO environments (e.g., Internet connectivity provided by a modem on one system). ICS can provide Network Address Translation (NAT) services to the other systems, which essentially hides them from public view. In a corporate environment, domain administrators can prevent systems from using ICS through Group Policy. Portable Windows XP Professional systems do not need to be reconfigured to use ICS on a SOHO network and not use ICS on a corporate network; Group Policy takes care of it automatically. Generally, ICS should not be used on enterprise networks, but it is a solution for SOHO environments with limited connectivity. It is recommended to use a host-based firewall such as Windows Firewall on the host that is running ICS. Not only can the firewall provide protection for the ICS host, but it can also help
                              to protect the systems behind the ICS from attacks by external parties.</description>
                  </Group>
                  <Group id="InternetProtocolSecurity" selected="true">
                        <title>Internet Protocol Security</title>
                        <description>Windows XP includes an implementation of the IETF Internet Protocol Security (IPsec) standard called Windows IP Security. It provides network-level support for confidentiality and integrity. Confidentiality is achieved by encrypting packets, which prevents unauthorized parties from gaining access to data as it passes over networks. Integrity is supported by calculating a hash for each packet based partially on a secret key shared by the sender and receiver, and sending the hash in the packet. The recipient will recalculate the hash, and if it matches the original hash, then the packet was not altered in transit. Windows IP Security also offers packet filtering capabilities, such as limiting traffic based on the source or destination IP address. Windows IP Security provides a solution for protecting data traversing public networks (e.g., the Internet) and for protecting sensitive data on private networks (e.g., an enterprise LAN). It is also commonly
                              used to protect wireless network communications in enterprise and SOHO environments. Using Windows IP Security in conjunction with a personal firewall such as Windows Firewall can provide protection against network-based attacks by limiting both inbound and outbound packets.</description>
                  </Group>
                  <Group id="EncryptingFileSystem" selected="true">
                        <title>Encrypting File System</title>
                        <description>The Encrypting File System (EFS) provides users a method to transparently encrypt or decrypt files and folders residing on an NTFS-formatted volume. In the original release of Windows XP, EFS could use either the Triple Data Encryption Standard (3DES) algorithm, which is a stronger variant of the Data Encryption Standard (DES), or the Extended Data Encryption Standard (DESX). Windows XP Service Pack 1 (SP1) added support for the Advanced Encryption Standard (AES) algorithm, and SP1 and SP2 systems use AES by default for EFS. This is a change from Windows 2000, which used DESX by default. In addition, EFS now maintains encryption persistence, which means that any file or folder that has been designated as encrypted will remain encrypted when moved to another NTFS-formatted filesystem. Another major change from Windows 2000 is that EFS-encrypted files can now be shared among multiple users over a network. However, files are still transmitted
                              unencrypted across the network (except when Web Distributed Authoring and Versioning [WebDAV] is used, which will transmit encrypted files across networks), so users should transfer the files through a separate encrypting protocol, such as TLS or IPsec. EFS is best used to provide local encryption for files and is particularly useful for laptops and other systems at high risk of physical attack.</description>
                  </Group>
                  <Group id="Subsystems" selected="true">
                        <title>Subsystems</title>
                        <description>Windows NT and Windows 2000 provide support for the OS/2 and POSIX subsystems. However, Windows XP no longer includes these subsystems. POSIX support is now included in a separate package as part of Microsoft Windows Interix 2.2. Refer to http://www.microsoft.com/windows2000/Interix for more information on Interix.</description>
                  </Group>
            </Group>
            <Group id="SummaryRecommendations-3" selected="true">
                  <title>Summary of Recommendations</title>
                  <description>
                        <xhtml:ul>
                              <xhtml:li>Do not implement a network bridge using a Windows XP computer unless it is specifically needed for a task, and risk assessment and mitigation have been performed.</xhtml:li>
                              <xhtml:li>Enable Remote Assistance only if it is configured so its usage is strictly limited and if the network perimeter is configured to prevent external parties from using it to access internal machines.</xhtml:li>
                              <xhtml:li>Only use Remote Desktop if several other layers of security controls are in place, preventing the system from being directly exposed to attackers, and administrators have carefully considered the business need for remote access to the system and have not found a viable alternative that will not expose the system to attack.</xhtml:li>
                              <xhtml:li>Do not configure Wireless Auto Configuration to attempt to connect to any wireless network automatically.</xhtml:li>
                              <xhtml:li>Only allow users with a legitimate need to access a system remotely.</xhtml:li>
                              <xhtml:li>Configure systems to store OS and application passwords only in environments in which there is a minimal physical threat or for passwords that have trivial value.</xhtml:li>
                              <xhtml:li>Disable UPnP unless its dynamic updating feature is needed for compatibility with other devices, such as SOHO firewalls.</xhtml:li>
                              <xhtml:li>Disable LM and NTLM v1 in specialized security-limited functionality environments.</xhtml:li>
                              <xhtml:li>Use host-based firewalls on systems running ICS.</xhtml:li>
                              <xhtml:li>As appropriate, use Windows IP Security to protect data traversing public networks and sensitive data on private networks.</xhtml:li>
                        </xhtml:ul>
                  </description>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  4 - Installation, Backup, and Patching                                                      *** -->
      <!-- **************************************************************************************************** -->
      <Group id="installation_backup_patching">
            <title>Installation, Backup, and Patching</title>
            <description>This section of the guide contains advice on performing Windows XP installations, and backing up and patching Windows XP systems. It discusses the risks of installing a new system on a network and the factors to consider when partitioning Windows XP hard drives. It also describes various installation techniques and provides pointers to more information on performing them. Another important topic is the ability of Windows XP to back up and restore data and system configuration information. This section also discusses how to update existing systems through Microsoft Update and other means to ensure that they are running the latest service packs and hotfixes. Advice is also presented on identifying missing patches and security misconfigurations on systems.<xhtml:p/>Organizations should have sound configuration management policies that govern changes made to operating systems and applications, such as applying patches to an operating system or modifying application
                  configuration settings to provide greater security. Configuration management policies should also address the initial installation of the operating system, the installation of each application, and the roles, responsibilities, and processes for performing and documenting system changes caused by upgrades, patches, and other methods of modification.</description>
            <Group id="PerformingNewInstallation" selected="true">
                  <title>Performing a New Installation</title>
                  <description>This guide assumes that a new Windows XP installation is being performed from scratch. If an administrator or user is upgrading an existing Windows installation, some of the advice in this guide may be inappropriate and could possibly cause problems. Because a machine is unsecured and very vulnerable to exploitation through the network during installation, it is recommended that all installations and initial patching be done with the computer not connected to any network. If a computer must be connected to a network, then it is recommended that the network be isolated and strongly protected (e.g., shielded by a firewall on a trusted network segment) to minimize exposure to any network attacks during installation. If possible, the latest service pack and critical hotfixes should be downloaded from Microsoft’s Web site, archived to read-only media, such as CD-ROMs, and kept physically secure.</description>
                  <Group id="PartitioningAdvice" selected="true">
                        <title>Partitioning Advice</title>
                        <description>One of the major decisions during installation is how to partition hard drives. The primary consideration is how large the disk drive is; for example, partitioning is not recommended for drives under 6 gigabytes (GB). For larger drives, the following factors should be considered:<xhtml:p/>
                              <xhtml:ul>
                                    <xhtml:li>How large is the drive?</xhtml:li>
                                    <xhtml:li>How many physical drives does the machine have?</xhtml:li>
                                    <xhtml:li>If the system only has one drive, is there a desire to logically separate the OS and applications from data? An example of the benefit of this is that if the OS needs to be upgraded or reinstalled, the data can easily be preserved.</xhtml:li>
                                    <xhtml:li>What is the purpose of this computer? For example, if a computer will be used to share files within a workgroup, it may be useful to have a separate partition for the file share.</xhtml:li>
                                    <xhtml:li>Is there a need for redundancy (e.g., mirroring a data partition onto a second drive)?</xhtml:li>
                              </xhtml:ul>
                              <xhtml:p/>Windows XP Professional provides a feature known as dynamic disks. On a dynamic disk, partition sizes can be changed as needed. For example, an administrator could create an OS and applications partition and a data partition on a large drive, leaving much of the drive space available for future allocation. As needed, the administrator can use the free space to create new partitions and to expand the existing partitions. This provides considerable flexibility for future growth. Users are cautioned that, as with any other new feature, dynamic disks should be tested before deploying them on production systems.<xhtml:p/>Another important consideration during installation is which type of filesystem to use for each partition. NIST recommends using NTFS for each partition unless there is a particular need to use another type of filesystem. Section 7.1 contains more information on NTFS and other filesystem options.</description>
                  </Group>
                  <Group id="InstallationMethods" selected="true">
                        <title>Installation Methods</title>
                        <description>There are several ways to perform Windows XP installations. This section covers three primary methods: local installations, cloning through Sysprep, and the Remote Installation Services (RIS).</description>
                        <Group id="LocalInstallation" selected="true">
                              <title>Local Installation</title>
                              <description>The local installation approach refers to traditional methods of installing Windows, such as using a Microsoft CD. This is effective only for installing a small number of computers at a time because it requires user attention throughout the installation. When installing Windows XP from a CD, follow the default steps, except for the following:<xhtml:p/>
                                    <xhtml:ul>
                                          <xhtml:li>For the Network Setting configuration, select Custom and disable all network clients, services, and protocols that are not required. Although this will help to limit the computer’s exposure to network-based attacks, consider the implications of disabling each service because this may inadvertently break required functionality (e.g., connecting to remote servers and printers). See Section 7.5 for more information on network clients, services, and protocols. Consider disabling the following services: <xhtml:ul>
                                                      <xhtml:li>Client for Microsoft Networks (most users will require this service)</xhtml:li>
                                                      <xhtml:li>Client Service for NetWare</xhtml:li>
                                                      <xhtml:li>File and Printer Sharing for Microsoft Networks</xhtml:li>
                                                      <xhtml:li>QoS Packet Scheduler</xhtml:li>
                                                      <xhtml:li>NWLink IPX/SPX/NetBIOS Compatible Transport Protocol</xhtml:li>
                                                </xhtml:ul>
                                          </xhtml:li>
                                          <xhtml:li>If possible, assign an Internet Protocol (IP) address, default gateway, and domain name system (DNS) server.</xhtml:li>
                                          <xhtml:li>Even if the computer will be joining a domain, choose to be in only a workgroup, and change the workgroup name to something other than the default of WORKGROUP.</xhtml:li>
                                          <xhtml:li>Set all environment-specific settings, such as the time zone.</xhtml:li>
                                    </xhtml:ul>
                                    <xhtml:p/>When the installation prompts for accounts to be added, only one account should be added initially. Other accounts can always been added later once the system is fully patched and configured. By default, the account created during the installation and the built-in Administrator account both belong to the Administrators group. After the initial post-installation boot, assign both accounts strong passwords. The next task is to install the latest service pack and hotfixes. Only after the machine has been brought up to current patch levels should it be connected to a regular network. Then, the networking configuration can be changed, such as joining the workstation to a domain, or assigning a workgroup to enable sharing of workgroup resources (e.g., shared directories, printers). Other services that were disabled during installation can be enabled if needed. It is also helpful to scan through the list of installed Windows components, determine
                                    which applications and utilities (e.g., Internet games) are not needed, and remove them.</description>
                        </Group>
                        <Group id="Sysprep" selected="true">
                              <title>Sysprep</title>
                              <description>Sysprep is a tool that permits an image from a single Windows XP computer installation, known as a gold system, to be cloned onto multiple systems in conjunction with a cloning software program such as Ghost or Disk Image. This technique reduces user involvement in the installation process to approximately 5 to 10 minutes at the start of the installation. The Sysprep approach has several benefits. Because the standard image can be created with a strong security configuration, Sysprep reduces the possibility of human error during the installation process. In addition, the Windows XP installation occurs more quickly with Sysprep. This is beneficial not only for building new systems, but also for reinstalling and reconfiguring the operating system and applications much more quickly when needed - for example, as a result of hardware failure or a virus infection. In preparing the “gold” image for Sysprep, the same guidelines used for a local
                                    installation should be used, with the addition of enabling any needed services and patching the system. It is also important to physically secure image media so that it is not inadvertently or purposely altered.</description>
                        </Group>
                        <Group id="RemoteInstallationServices" selected="true">
                              <title>Remote Installation Services</title>
                              <description>The Remote Installation Services (RIS) allow a computer to be booted from the network and then to automatically install an instance of Windows XP. RIS can be configured to perform either a completely automated and unattended installation with RISetup, or one that requires minimal user attendance (similar to the Sysprep tool) with RIPrep. Several hardware and software dependencies exist; therefore, Microsoft's documentation on the tool should be consulted for detailed instructions regarding how to configure this installation method.<xhtml:p/>The RIS method has the same advantages as Sysprep. RIS has the additional advantage of not needing the machine to be installed to have direct access to the physical install media (e.g., a CD-ROM). This can be ideal in a specialized security-limited functionality environment in which machines might not have CD-ROM drives. The primary disadvantage of RIS is that the machine must be connected to a network
                                    while it is being installed. This could open up a window of opportunity to exploit a security weakness before installation is completed.</description>
                        </Group>
                  </Group>
            </Group>
            <Group id="BackingUpSystems" selected="true">
                  <title>Backing Up Systems</title>
                  <description>To increase the availability of data in case of a system failure or data corruption caused by a power failure or other event, Windows XP has built-in capabilities to back up and restore data and systems. By default, users run the Backup or Restore Wizard, which automates most of the backup and restore processes. For example, during a backup the user is presented with several options, including backing up the current user’s files and settings, backing up all users’ files and settings, and backing up the whole system. This allows the user to back up data and systems without having to manually indicate which files and directories should be backed up, if the user’s files are where the backup program expects them to be. To run the Backup or Restore Wizard, perform the following steps:<xhtml:p/>
                        <xhtml:ol>
                              <xhtml:li>Open My Computer. Right-click on the drive that contains the data to be backed up, and select Properties.</xhtml:li>
                              <xhtml:li>Click on the Tools tab. Click on the Backup Now… button. This launches the Backup or Restore Wizard.</xhtml:li>
                        </xhtml:ol>
                        <xhtml:p/>When a backup is performed, the result is a .bkf file (Backup.bkf by default). If a full system backup is performed, the Automated System Recovery Wizard will prompt the user to insert a floppy disk, which will be turned into a recovery disk that can be used with the .bkf file to restore the system in case of failure. As the name indicates, the Backup or Restore Wizard can also be used to restore a backup from a .bkf file. It is very important to verify periodically that backups and restores can be performed successfully; backing up a system regularly may not be beneficial if the backups are corrupt or the wrong files are being backed up, for example. Organizations should have policies and procedures that address the entire backup and recovery process, as well as the protection and storage of backup media and recovery disks. Because backups may contain sensitive user data as well as system configuration and security information (e.g., passwords),
                        backup media should be properly protected to prevent unauthorized access.<xhtml:p/>When the Backup or Restore Wizard is run, it presents an option to select Advanced Mode. This switches to the Backup Utility interface, which is not as user-friendly but provides greater customizability and more features. For example, the Backup Utility can be used to schedule backups. In general, system administrators are more likely to use the Backup Utility mode, while end users are more likely to use the Backup or Restore Wizard mode.<xhtml:p/>Besides the backup wizards and utilities provided by Windows XP, there are also various third-party utilities for backing up and restoring files and systems. It is important to verify that the third-party software can properly back up and restore Windows XP-specific resources, such as the Windows registry and EFS-encrypted files and folders. Windows XP’s built-in utilities also use a shadow copy backup technique when possible, which
                        means that they essentially take a snapshot of the system and then perform a backup on that snapshot. This avoids problems with attempting to back up open files. Third-party backup utilities used on Windows XP systems should have good mechanisms for handling open files.</description>
            </Group>
            <Group id="UpdatingExistingSystems" selected="true">
                  <title>Updating Existing Systems</title>
                  <description>Host security - securing a given computer - has become increasingly important. As such, it is essential to keep a host up to current patch levels to eliminate known vulnerabilities and weaknesses. In conjunction with antivirus software and a personal firewall, patching goes a long way to securing a host against outside attacks and exploitation. Microsoft provides two mechanisms for distributing security updates: Automatic Updates and Microsoft Update. In smaller environments, either method may be sufficient for keeping systems current with patches. Other environments typically have a software change management control process or a patch management program that tests patches before deploying them; distribution may then occur through local Windows Update Services (WUS) or Windows Server Update Services (WSUS) servers, which provide approved security patches for use by the Automatic Updates feature. This section discusses Automatic Updates and Microsoft
                        Update, as well as patch management considerations for managed environments. This section also defines the types of updates that Microsoft typically provides.</description>
                  <Group id="UpdateNotification" selected="true">
                        <title>Update Notification</title>
                        <description>As described later in this section, it is possible to configure Windows XP systems to download critical updates automatically. However, this still leaves other updates that can only be downloaded manually. Therefore, it is important for Windows XP system administrators to be notified of new updates that Microsoft releases. The Microsoft Security Notification Service is a mailing list that notifies subscribers of new security issues and the availability of all types of Microsoft updates. Microsoft security bulletins are also available online from the TechNet Security Resource Center. Individual bulletins are issued for each new vulnerability and are incorporated into monthly bulletins that list the vulnerabilities in order of potential severity (e.g., critical, important, moderate). Each bulletin provides guidance regarding under what circumstances the suggested mitigation strategy (e.g., patch) should be applied.</description>
                  </Group>
                  <Group id="MicrosoftUpdateTypes" selected="true">
                        <title>Microsoft Update Types</title>
                        <description>Microsoft releases updated code for Windows XP-related security issues through three mechanisms: hotfixes, security rollups, and service packs. <xhtml:ul>
                                    <xhtml:li>A hotfix is a patch that fixes a specific problem. When a new vulnerability is discovered in Windows XP or a Microsoft application (e.g., Internet Explorer), Microsoft develops a hotfix that will resolve the problem. Hotfixes are released on an individual basis as needed. Hotfixes should be applied as soon as practical for vulnerabilities that are likely to be exploited. (Whenever possible, hotfixes should first be tested on a nonproduction system to ensure that they do not inadvertently break functionality or introduce a new security problem by breaking a previous hotfix.)</xhtml:li>
                                    <xhtml:li>A security rollup is a collection of several hotfixes. The security rollup makes the same changes to the system that would be performed if each hotfix were installed separately. However, it is easier to download and install a single security rollup than 10 hotfixes. Microsoft releases security rollups on occasion when merited. Security rollups are most useful for updating existing systems that have not been maintained and for patching new systems.</xhtml:li>
                                    <xhtml:li>A service pack (SP) is a major upgrade to the operating system that resolves dozens of functional and security problems and often introduces some new features or makes significant configuration changes to systems. Service packs incorporate previously released hotfixes, so once an SP has been applied to a system, there is no need to install the hotfixes that were included in the service pack. Service packs are released every year or two; for example, Windows XP was released in the fall of 2001, SP1 in the fall of 2002, and SP2 in the summer of 2004. Because SPs often make major changes to the operating system, organizations should test the SP thoroughly before deploying it in production. In SOHO environments, the best approach is to delay installation of the SP for at least a few weeks so that early adopters can identify any bugs or issues. However, if the SP provides a fix for a major security issue, and the fix is not available through
                                          hotfixes, it may be less risky to install the SP immediately than to let the system remain unpatched.</xhtml:li>
                              </xhtml:ul>
                        </description>
                  </Group>
                  <Group id="AutomaticUpdates" selected="true">
                        <title>Automatic Updates</title>
                        <description>One facility that is available to patch systems with little to no user intervention is the Automatic Updates feature. When enabled, it will automatically check the Microsoft update servers for OS and Microsoft application updates, including service packs, security roll-ups, and hotfixes, as well as updated hardware drivers. Automatic Updates has a prioritization feature that ensures the most critical security updates are installed before less important updates.<xhtml:p/>Automatic Updates provides three configuration options to users:<xhtml:ul>
                                    <xhtml:li>Notifies the user before downloading or installing any updates</xhtml:li>
                                    <xhtml:li>Downloads updates automatically but notifies the user before installing updates</xhtml:li>
                                    <xhtml:li>Downloads all updates and automatically installs them according to a specified schedule.</xhtml:li>
                              </xhtml:ul>
                              <xhtml:p/>Generally, it is best to configure the system to download updates automatically, unless bandwidth usage is a concern. For example, downloading patches could adversely affect the functionality of a computer that is connected to the Internet on a slow link. In this case, it would be preferable for Automatic Updates to be configured to notify the user that new patches are available. The user should then make arrangements to download the patch at the next possible time when the computer is not needed for normal functionality. Choosing whether to install updates automatically or prompt the user is dependent upon the situation. If the user is likely to ignore the notifications, then it may be more effective to install the updates on a schedule. If the system is in use at unpredictable days and times, then it may be difficult to set a schedule that will not interfere with system usage. Another issue to consider is that many updates require the system to
                              be rebooted before the update takes effect. Windows XP offers an <xhtml:strong>Install updates and shutdown</xhtml:strong> option as part of its Shut Down dialog box, which may be helpful in reminding users to launch the update installation process.<xhtml:p/>It is highly recommended that the Automatic Updates service be enabled to keep the OS and key Microsoft applications (e.g., Internet Explorer, Outlook Express) fully patched. To enable Automatic Updates, perform the following steps: <xhtml:ol>
                                    <xhtml:li>Click the <xhtml:strong>Start</xhtml:strong> menu and select <xhtml:strong>Control Panel</xhtml:strong>.</xhtml:li>
                                    <xhtml:li>Double-click <xhtml:strong>Automatic Updates</xhtml:strong>.</xhtml:li>
                                    <xhtml:li>Choose the appropriate radio button (such as <xhtml:strong>Download updates for me, but let me choose when to install them</xhtml:strong>). Click <xhtml:strong>OK</xhtml:strong>.</xhtml:li>
                              </xhtml:ol>
                              <xhtml:p/>Some organizations do not want the latest updates applied immediately to their Windows systems. For example, in a managed environment it may be undesirable for hotfixes to be deployed to production systems until they have been tested by Windows administrators and security administrators. In addition, in large environments, many systems may need to download the same hotfix simultaneously. This could cause a serious impact on network bandwidth. Organizations with such concerns often establish a local WUS or WSUS update server that contains approved updates. The Automatic Updates feature on Windows XP systems should then be configured to point to the local update server. Unfortunately, although WUS and WSUS provide a method for distributing Microsoft updates, they cannot be used to distribute third party software updates.</description>
                  </Group>
                  <Group id="MicrosoftUpdate" selected="true">
                        <title>Microsoft Update</title>
                        <description>Users with local administrator privileges can also manually update their systems by visiting the Microsoft Update Web site. The Microsoft Update site will check the computer to determine what security and functionality updates are available and produce a list of updates. The user can then select which updates should be installed at this time, and tell Microsoft Update to perform the installations. To use Microsoft Update, perform the following steps:<xhtml:p/>
                              <xhtml:ol>
                                    <xhtml:li>Run Internet Explorer.</xhtml:li>
                                    <xhtml:li>From the <xhtml:strong>Tools</xhtml:strong> menu, select <xhtml:strong>Windows Update</xhtml:strong>. If a prompt appears asking to install and run Windows Update, click <xhtml:strong>Yes</xhtml:strong>.</xhtml:li>
                                    <xhtml:li>If a prompt appears saying that a new version of the Windows Update or Microsoft Update software is available, click on <xhtml:strong>Install Now</xhtml:strong> or <xhtml:strong>Download and Install Now</xhtml:strong> to install the new version. Multiple updates may be needed. If prompted to do so, close Internet Explorer or reboot the computer so that the new version of the update software takes effect. (If a reboot is needed, restart these instructions at step 1 after the reboot completes.)</xhtml:li>
                                    <xhtml:li>Click on the <xhtml:strong>Custom</xhtml:strong> button to identify available updates.</xhtml:li>
                                    <xhtml:li>Microsoft Update checks for updates and lists the available updates. Depending on the service pack level of the computer, either Service Pack 2 or non-service pack updates should be displayed. Follow the appropriate step:<xhtml:ol type="a">
                                                <xhtml:li>Non-service pack updates are grouped by high priority updates, optional software updates, and optional hardware updates.<xhtml:ol type="i">
                                                            <xhtml:li>Review the list of available updates, select the desired ones (or accept the default setting), then click <xhtml:strong>Review and install updates</xhtml:strong>. In some cases, one patch may need to be installed by itself; therefore, it may not be possible to install all desired patches at once.</xhtml:li>
                                                            <xhtml:li>Confirm that the correct updates are listed, and click the <xhtml:strong>Install Updates</xhtml:strong> button to perform the installations. Review any licensing agreements that are displayed and click on the appropriate button for each.</xhtml:li>
                                                            <xhtml:li>The download and installation process will begin. Depending on the number of updates and the network bandwidth available, it may take from a few minutes to a few hours to download and install the updates. When the installations are done, Microsoft Update should report which updates were successfully installed. It will also prompt the user to reboot the computer if any of the updates require a reboot to complete the installation. Click on <xhtml:strong>OK</xhtml:strong> to reboot immediately or <xhtml:strong>Cancel</xhtml:strong> to manually reboot the computer later.</xhtml:li>
                                                      </xhtml:ol></xhtml:li>
                                                <xhtml:li>Service Pack 2 can be installed through Microsoft Update using the following steps:<xhtml:ol type="i">
                                                            <xhtml:li>Click on <xhtml:strong>Download and Install Now</xhtml:strong>.</xhtml:li>
                                                            <xhtml:li>Review the license agreement and click on the appropriate button.</xhtml:li>
                                                            <xhtml:li>Service Pack 2 should be downloaded and installed. This may take considerable time, depending primarily on the size of the service pack and the type of Internet connectivity and bandwidth available. The Windows XP Service Pack 2 Setup Wizard may prompt the user at some point; click <xhtml:strong>Next</xhtml:strong> to continue.</xhtml:li>
                                                            <xhtml:li>Once the installation has ended, a summary should be displayed that reports the installation was successful. Click <xhtml:strong>Restart Now</xhtml:strong> to reboot the computer.</xhtml:li>
                                                            <xhtml:li>After the reboot, the <xhtml:strong>Help protect your PC</xhtml:strong> screen appears. The Automatic Updates setting is configured later in the instructions, so at this time, choose the <xhtml:strong>Not right now</xhtml:strong> option and click <xhtml:strong>Next</xhtml:strong>.</xhtml:li>
                                                            <xhtml:li>The <xhtml:strong>Security Center</xhtml:strong> opens and displays the status of security programs. Since antivirus software and other security programs have not yet been installed on the computer, the current status is irrelevant. Close the <xhtml:strong>Security Center</xhtml:strong>.</xhtml:li>
                                                      </xhtml:ol></xhtml:li>
                                          </xhtml:ol></xhtml:li>
                                    <xhtml:li>Repeat all of these steps until no more updates are available. Depending on which service pack was on the computer, and the number of additional updates that need to be applied, it may take several rounds of updating the computer and rebooting it to bring a new Windows XP installation completely up to date.</xhtml:li>
                              </xhtml:ol>
                              <xhtml:p/>Because Windows Update requires local administrative privileges and is run manually, its use is generally not recommended within enterprise and specialized security-limited functionality environments. As described in Section 4.3.5, it is recommended that all updates be tested and verified before coordinated deployment, which the use of Microsoft Update could circumvent. Microsoft Update has additional complications in enterprise environments because it is typically unrealistic to run any application manually on every workstation in the enterprise on a regular basis, and individual users may not have the necessary local administrative rights.</description>
                  </Group>
                  <Group id="PatchingInManagedEnvironments" selected="true">
                        <title>Patching in Managed Environments</title>
                        <description>Enterprise and specialized security-limited functionality environments, especially those that are considered managed environments, should have a patch management program that is responsible for acquiring, testing, and verifying each patch, then arranging for its distribution to systems throughout the organization. NIST SP 800-40 version 2, Creating a Patch and Vulnerability Management Program, provides in-depth advice on establishing patching processes and testing and applying patches. For each patch that is released, the patch management team should research the associated vulnerabilities and prioritize the patch appropriately. It is not uncommon for several patches to be released in a relatively short time, and typically one or two of the patches are much more important to the organization than the others. Each patch should be tested with system configurations that are representative of the organization’s systems. Once the team determines that the
                              patch is suitable for deployment, the patch needs to be distributed through automated or manual means for installation on all appropriate systems. (There are several third-party applications available for patch management and distribution, which support many types of platforms and offer functionality that supports enterprise requirements.) Finally, the team needs to check systems periodically to confirm that the patch has been installed on each system, and to take actions to ensure that missing patches are applied.<xhtml:p/>Microsoft offers the following command-line tools that may be helpful in hotfix deployment, as follows: <xhtml:ul>
                                    <xhtml:li>The <xhtml:strong>qchain.exe</xhtml:strong> tool allows multiple hotfixes to be installed at one time, instead of installing a hotfix, rebooting, then installing another hotfix.</xhtml:li>
                                    <xhtml:li>The <xhtml:strong>qfecheck.exe</xhtml:strong> tool can be used to track and verify installed hotfixes.</xhtml:li>
                              </xhtml:ul>
                        </description>
                  </Group>
            </Group>
            <Group id="IdentifyingSecurityIssues" selected="true">
                  <title>Identifying Security Issues</title>
                  <description>Host security is largely dependent upon staying up to date with security patches as well as identifying and remediating other security weaknesses. The Microsoft Baseline Security Analyzer (MBSA) is a utility that can scan the local computer and remote computers to identify security issues. MBSA must have local administrator-level access on each computer that it is scanning. MBSA offers both graphical user interface (GUI) and command-line interfaces. MBSA can identify which updates are missing from the operating system and common Microsoft applications (e.g., Internet Explorer, Media Player, Internet Information Services [IIS], Exchange Server, Structured Query Language [SQL] Server) on each system. For the operating system and a few applications (e.g., Internet Explorer, IIS, SQL Server, Office), it can also identify other security issues, such as insecure configurations and settings. MBSA only identifies the problems; it has no ability to change settings
                        or download and install updates onto systems. The methods discussed in Section 4.3 should be used to download and apply patches.<xhtml:p/>Another popular free tool for checking the patch status of computers is HFNetChk, made by Shavlik. HFNetChk offers the same functionality as the command-line version of MBSA; it can scan systems and report which patches are present and absent for the operating system and various Microsoft applications. Shavlik also makes HFNetChkPro, a commercial utility that provides a GUI for administrators. Unlike MBSA, HFNetChkPro also provides a mechanism for distributing and installing patches that are identified as being missing from systems.<xhtml:p/>Individual systems can also monitor their own security state and alert users of potential problems. Windows XP offers the Windows Security Center, which is a service that can be configured to monitor the state of the system’s firewall (either Windows Firewall or a third-party firewall) and
                        antivirus software, as well as the settings for Automatic Updates. Windows Security Center can generate alerts if the firewall, antivirus software, or Automatic Updates feature is not enabled, and also if certain major configuration settings are insecure, such as not setting antivirus software to perform real-time scanning, and not setting Automatic Updates to download and install updates automatically. Windows Security Center can monitor several types of third-party firewall and antivirus software. Windows Security Center is most helpful in SOHO environments, so that users can monitor the security state of their systems. In an enterprise environment, systems might be updated through methods other than Automatic Updates, and the status of systems' firewalls and antivirus software might already be monitored centrally.</description>
            </Group>
            <Group id="SummaryRecommendations-4" selected="true">
                  <title>Summary of Recommendations</title>
                  <description>
                        <xhtml:ul>
                              <xhtml:li>Use the recommendations presented in this guide only on new Windows XP systems, not systems upgraded from previous versions of Windows. For upgraded systems, some of the advice in this guide may be inappropriate and could possibly cause problems.</xhtml:li>
                              <xhtml:li>Have sound configuration management policies that govern changes made to operating systems and applications, such as applying patches and modifying configuration settings.</xhtml:li>
                              <xhtml:li>Until a new system has been fully installed and patched, either keep it disconnected from all networks, or connect it to an isolated, strongly protected network.</xhtml:li>
                              <xhtml:li>Use NTFS for each hard drive partition unless there is a particular need to use another type of filesystem.</xhtml:li>
                              <xhtml:li>Disable all network clients, services, and protocols that are not required.</xhtml:li>
                              <xhtml:li>Assign strong passwords to the built-in administrator account and the user account created during installation.</xhtml:li>
                              <xhtml:li>Keep systems up to current patch levels to eliminate known vulnerabilities and weaknesses.</xhtml:li>
                              <xhtml:li>Use MBSA, HFNetChk, or other similar utilities on a regular basis to identify patch status issues.</xhtml:li>
                        </xhtml:ul>
                  </description>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  5 - FDCC Security Settings                                                                  *** -->
      <!-- **************************************************************************************************** -->
      <Group id="fdcc_security_settings">
            <title>FDCC Security Settings</title>
            <description>FDCC has identified the following controls that must be checked in order to verify compliance.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Account Policies Group                                                                    -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="account_policies_group">
                  <title>Account Policies Group</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Account Lockout Policy Settings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="account_lockout_policy_settings">
                        <title>Account Lockout Policy Settings</title>
                        <description>Attackers often attempt to gain access to user accounts by guessing passwords. Windows XP can be configured to lock out (disable) an account when too many failed login attempts occur for a single user account in a certain time period. The following account lockout parameters are set in the NIST templates:<xhtml:p/>One of the main challenges in setting account policies is balancing security, functionality, and usability. For example, locking out user accounts after only a few failed logon attempts in a long time period may make it more difficult to gain unauthorized access to accounts by guessing passwords, but may also sharply increase the number of calls to the help desk to unlock accounts accidentally locked by failed attempts from legitimate users. This could also cause more users to write down their passwords or choose easier-to-remember passwords. Organizations should carefully think out such issues before setting Windows XP account policies.</description>
                        <Value id="account_lockout_duration_var" type="number" operator="greater than or equal">
                              <title>Account Lockout Duration</title>
                              <description>The amount of time in seconds that an account is locked before it is automatically unlocked by the system. 15 minutes = 900 seconds A value of 0 means that an administrator must unlock the account.</description>
                              <value>900</value>
                              <value selector="admin_unlock">0</value>
                              <value selector="900_seconds">900</value>
                              <value selector="86400_seconds">86400</value>
                        </Value>
                        <Value id="account_lockout_threshold_var" type="number" operator="less than or equal">
                              <title>Account Lockout Threshold</title>
                              <description>The maximum number of failed attempts that can occur before the account is locked out</description>
                              <value>50</value>
                              <value selector="3_attempts">3</value>
                              <value selector="5_attempts">5</value>
                              <value selector="10_attempts">10</value>
                              <value selector="50_attempts">50</value>
                        </Value>
                        <Value id="account_lockout_reset_var" type="number" operator="greater than or equal">
                              <title>Reset Account Lockout Counter After</title>
                              <description>The time period in seconds to be used with the lockout threshold value. For example, if the threshold is set to 10 attempts and the duration is set to 15 minutes, then if more than 10 failed login attempts occur with a single user account within a 15-minute period, the account will be disabled. 15 minutes = 900 seconds</description>
                              <value>900</value>
                              <value selector="900_seconds">900</value>
                              <value selector="3600_seconds">3600</value>
                              <value selector="86400_seconds">86400</value>
                        </Value>
                        <Rule id="account_lockout_duration" selected="false" weight="10.0">
                              <title>Account Lockout Duration</title>
                              <description>The lockout duration specifies how long the user account should be locked out after too many bad logon attempts. This is often set to a low but substantial value (e.g., 15 minutes), for two reasons. First, a legitimate user that is accidentally locked out only has to wait 15 minutes to regain access, instead of asking an administrator to unlock the account. Second, an attacker who is guessing passwords using brute force methods will only be able to try a small number of passwords at a time, then wait 15 minutes before trying any more. This greatly reduces the chances that the brute force attack will be successful.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-7"/>
                              <ident system="http://cce.mitre.org">CCE-2928-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-980</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="account_lockout_duration_var" export-name="oval:gov.nist.fdcc.xp:var:15"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:23"/>
                              </check>
                        </Rule>
                        <Rule id="account_lockout_threshold" selected="false" weight="10.0">
                              <title>Account Lockout Threshold</title>
                              <description>The threshold value specifies the maximum number of failed attempts that can occur before the account is locked out.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-7"/>
                              <ident system="http://cce.mitre.org">CCE-2986-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-658</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="account_lockout_threshold_var" export-name="oval:gov.nist.fdcc.xp:var:10"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:24"/>
                              </check>
                        </Rule>
                        <Rule id="account_lockout_reset" selected="false" weight="10.0">
                              <title>Reset Account Lockout Counter After</title>
                              <description>This specifies the time period to be used with the lockout threshold value. For example, if the threshold is set to 10 attempts and the duration is set to 15 minutes, then if more than 10 failed login attempts occur with a single user account within a 15-minute period, the account will be disabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-7"/>
                              <ident system="http://cce.mitre.org">CCE-2466-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-733</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="account_lockout_reset_var" export-name="oval:gov.nist.fdcc.xp:var:115"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:26"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Kerberos Policy Settings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="kerberos_policy_settings">
                        <title>Kerberos Policy Settings</title>
                        <description>todo - description needed</description>
                        <Value id="kerberos_maximum_lifetime_service_ticket_var" operator="less than or equal" type="number">
                              <title>Kerberos: Maximum lifetime for service ticket</title>
                              <description>todo</description>
                              <value>600</value>
                        </Value>
                        <Value id="kerberos_maximum_lifetime_user_ticket_var" operator="less than or equal" type="number">
                              <title>Kerberos: Maximum lifetime for user ticket</title>
                              <description>todo</description>
                              <value>10</value>
                        </Value>
                        <Value id="kerberos_maximum_lifetime_user_ticket_renewal_var" operator="less than or equal" type="number">
                              <title>Kerberos: Maximum lifetime for user ticket renewal</title>
                              <description>todo</description>
                              <value>7</value>
                        </Value>
                        <Value id="kerberos_maximum_tolerance_computer_clock_synchronization_var" operator="less than or equal" type="number">
                              <title>Kerberos: Maximum tolerance for computer clock synchronization</title>
                              <description>todo</description>
                              <value>5</value>
                        </Value>
                        <Rule id="kerberos_enforce_user_logon_restrictions" selected="false" weight="10.0" role="unchecked">
                              <title>Enforce user logon restrictions</title>
                              <description>This security setting determines whether the Kerberos V5 Key Distribution Center (KDC) validates every request for a session ticket against the user rights policy of the user account. Validation of each request for a session ticket is optional, because the extra step takes time and it may slow network access to services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3188-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-227</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:987651"/>
                              </check>
                        </Rule>
                        <Rule id="kerberos_maximum_lifetime_service_ticket" selected="false" weight="10.0" role="unchecked">
                              <title>Maximum lifetime for service ticket</title>
                              <description>This security setting determines the maximum amount of time (in minutes) that a granted session ticket can be used to access a particular service.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2708-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-6</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:987652" value-id="kerberos_maximum_lifetime_service_ticket_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:987652"/>
                              </check>
                        </Rule>
                        <Rule id="kerberos_maximum_lifetime_user_ticket" selected="false" weight="10.0" role="unchecked">
                              <title>Maximum lifetime for user ticket</title>
                              <description>This security setting determines the maximum amount of time (in hours) that a user's ticket-granting ticket (TGT) may be used. When a user's TGT expires, a new one must be requested or the existing one must be "renewed."</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2803-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-37</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:987653" value-id="kerberos_maximum_lifetime_user_ticket_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:987653"/>
                              </check>
                        </Rule>
                        <Rule id="kerberos_maximum_lifetime_user_ticket_renewal" selected="false" weight="10.0" role="unchecked">
                              <title>Maximum lifetime for user ticket renewal</title>
                              <description>This security setting determines the period of time (in days) during which a user's ticket-granting ticket (TGT) may be renewed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3063-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-33</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:987654" value-id="kerberos_maximum_lifetime_user_ticket_renewal_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:987654"/>
                              </check>
                        </Rule>
                        <Rule id="kerberos_maximum_tolerance_computer_clock_synchronization" selected="false" weight="10.0" role="unchecked">
                              <title>Maximum tolerance for computer clock synchronization</title>
                              <description>This security setting determines the maximum time difference (in minutes) that Kerberos V5 tolerates between the time on the client clock and the time on the domain controller running Windows Server 2003 that provides Kerberos authentication.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3208-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-588</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:987655" value-id="kerberos_maximum_tolerance_computer_clock_synchronization_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:987655"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Password Policy Settings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="password_policy_settings">
                        <title>Password Policies</title>
                        <description>In addition to educating users regarding the selection and use of good passwords, it is also important to set password parameters so that passwords are sufficiently strong. This reduces the likelihood of an attacker guessing or cracking passwords to gain unauthorized access to the system. As described in Section 3.2.1, NIST recommends the use of NTLM v2 or Kerberos instead of LM or NTLM v1 for authentication. Windows XP offers the same password parameters as Windows 2000. The following parameters are specified in the NIST templates:</description>
                        <Value id="password_history_enforcement_var" type="number" operator="greater than or equal">
                              <title>Enforce Password History</title>
                              <description>The number of passwords remembered</description>
                              <value>24</value>
                              <value selector="5_passwords">5</value>
                              <value selector="24_passwords">24</value>
                        </Value>
                        <Value id="maximum_password_age_var" type="number" operator="less than or equal">
                              <title>Maximum Password Age</title>
                              <description>The maximum age in seconds before a password expires. (90 days = 7776000 seconds; 60 days = 5184000)</description>
                              <value>7776000</value>
                              <value selector="5184000_seconds">5184000</value>
                              <value selector="7776000_seconds">7776000</value>
                        </Value>
                        <Value id="minimum_password_age_var" type="number" operator="greater than or equal">
                              <title>Minimum Password Age</title>
                              <description>The minimum age in seconds before a password may be changed. 1 day = 86400 seconds</description>
                              <value>86400</value>
                              <value selector="86400_seconds">86400</value>
                              <value selector="172800_seconds">172800</value>
                              <value selector="432000_seconds">432000</value>
                        </Value>
                        <Value id="minimum_password_length_var" type="number" operator="greater than or equal">
                              <title>Minimum Password Length</title>
                              <description>The minimum number of characters required for a password</description>
                              <value>8</value>
                              <value selector="8_characters">8</value>
                              <value selector="9_characters">9</value>
                              <value selector="12_characters">12</value>
                        </Value>
                        <Value id="password_complexity_var" type="boolean" operator="equals">
                              <title>Enforce Password Complexity</title>
                              <description>This value determines whether Windows XP implements a minimum level of strong password filtering. 1 = enabled</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="PasswordStorageReversibleEncryption_var" type="boolean" operator="equals">
                              <title>Enforce Reversible Encryption When Storing Passwords</title>
                              <description>This value determines whether Windows XP is configured to prevent passwords from being stored using a two-way hash. 1 = enabled</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="password_history_enforcement" selected="false" weight="10.0">
                              <title>Enforce Password History</title>
                              <description>This setting determines how many old passwords the system will remember for each account. Users will be prevented from reusing any of the old passwords. For example, if this is set to 24, then the system will not allow users to reuse any of their last 24 passwords. Old passwords may have been compromised, or an attacker may have taken a long time to crack encrypted passwords. Reusing an old password could inadvertently give attackers access to the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2994-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-60</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="password_history_enforcement_var" export-name="oval:gov.nist.fdcc.xp:var:24"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:16"/>
                              </check>
                        </Rule>
                        <Rule id="maximum_password_age" selected="false" weight="10.0">
                              <title>Maximum Password Age</title>
                              <description>This forces users to change their passwords regularly. The lower this value is set, the more likely users will be to choose poor passwords that are easier for them to remember (e.g., Mypasswd1, Mypasswd2, Mypasswd3). The higher this value is set, the more likely the password will be compromised and used by unauthorized parties.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2920-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-871</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="maximum_password_age_var" export-name="oval:gov.nist.fdcc.xp:var:90"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:17"/>
                              </check>
                        </Rule>
                        <Rule id="minimum_password_age" selected="false" weight="10.0">
                              <title>Minimum Password Age</title>
                              <description>This setting requires users to wait for a certain number of days before changing their password again. The setting prevents a user from changing a password when it reaches the maximum age and then immediately changing it back to the previous password. Unfortunately, this setting also prevents users who inadvertently reveal a new password to others from changing it immediately without administrator intervention.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2439-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-324</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="minimum_password_age_var" export-name="oval:gov.nist.fdcc.xp:var:101"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:18"/>
                              </check>
                        </Rule>
                        <Rule id="minimum_password_length" selected="false" weight="10.0">
                              <title>Minimum Password Length</title>
                              <description>This setting specifies the minimum length of a password in characters. The rationale behind this setting is that longer passwords are more difficult to guess and crack than shorter passwords. The downside is that longer passwords are often more difficult for users to remember. Organizations that want to set a relatively large minimum password length should encourage their users to use passphrases, which may be easier to remember than conventional passwords.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2981-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-100</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="minimum_password_length_var" export-name="oval:gov.nist.fdcc.xp:var:12"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:19"/>
                              </check>
                        </Rule>
                        <Rule id="password_complexity" selected="false" weight="10.0">
                              <title>Passwords Must Meet Complexity Requirements</title>
                              <description>Like the Minimum Password Length setting, this setting makes it more difficult to guess or crack passwords. Enabling this setting implements complexity requirements including not having the user account name in the password and using a mixture of character types, including upper case and lower case letters, digits, and special characters such as punctuation marks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2735-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-633</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="password_complexity_var" export-name="oval:gov.nist.fdcc.xp:var:11"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:21"/>
                              </check>
                        </Rule>
                        <Rule id="PasswordStorageReversibleEncryption" selected="false" weight="10.0">
                              <title>Store Passwords Using Reversible Encryption for All Users in the Domain</title>
                              <description>If this setting is enabled, passwords will be stored in a decryptible format, putting them at higher risk of compromise. This setting should be disabled unless it is needed to support a legacy authentication protocol, such as Challenge Handshake Authentication Protocol (CHAP).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-2889-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-479</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="PasswordStorageReversibleEncryption_var" export-name="oval:gov.nist.fdcc.xp:var:13"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:22"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Event Log Policy Group                                                                    -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="event_log_policy_group">
                  <title>Event Log Policy Settings</title>
                  <description>Windows XP records information about significant events in three logs: the Application Log, the Security Log, and the System Log. The logs contain error messages, audit information, and other records of activity on the system. The logs can be used not only to identify suspicious and malicious behavior and investigate security incidents, but also to assist in troubleshooting system and application problems. Therefore, it is important to enable logging for all three types of logs. The NIST templates enable all three logs for all environments, and also specify the maximum log size. This is important because if the maximum log size is very low, the system will not have much room for storing information on system activity. Some organizations may have a logging policy and central log server, so the template settings may need to be adjusted so they comply with the policy.</description>
                  <Value id="maximum_application_log_size_var" type="number" operator="greater than or equal">
                        <title>Maximum Application Log Size</title>
                        <description>The value defines the maximum size (in bytes) of the application log.</description>
                        <value>16777216</value>
                        <value selector="4194240_bytes">4194240</value>
                        <value selector="16777216_bytes">16777216</value>
                        <value selector="33554432_bytes">33554432</value>
                        <value selector="83886080_bytes">83886080</value>
                  </Value>
                  <Value id="maximum_security_log_size_var" type="number" operator="greater than or equal">
                        <title>Maximum Security Log Size</title>
                        <description>The value defines the maximum size (in bytes) of the security log.</description>
                        <value>83886080</value>
                        <value selector="4194240_bytes">4194240</value>
                        <value selector="16777216_bytes">16777216</value>
                        <value selector="33554432_bytes">33554432</value>
                        <value selector="83886080_bytes">83886080</value>
                  </Value>
                  <Value id="maximum_system_log_size_var" type="number" operator="greater than or equal">
                        <title>Maximum System Log Size</title>
                        <description>The value defines the maximum size (in bytes) of the system log.</description>
                        <value>16777216</value>
                        <value selector="4194240_bytes">4194240</value>
                        <value selector="16777216_bytes">16777216</value>
                        <value selector="33554432_bytes">33554432</value>
                        <value selector="83886080_bytes">83886080</value>
                  </Value>
                  <Value id="prevent_guest_application_log_access_var" type="boolean" operator="equals">
                        <title>Restrict Guest Access to Application Log</title>
                        <description>This value determines if the local guests group is prevented from accessing the application log. 1 = enabled/prevented</description>
                        <value>1</value>
                        <value selector="disabled">0</value>
                        <value selector="enabled">1</value>
                  </Value>
                  <Value id="prevent_guest_security_log_access_var" type="boolean" operator="equals">
                        <title>Restrict Guest Access to Security Log</title>
                        <description>This value determines if the local guests group is prevented from accessing the security log. 1 = enabled/prevented</description>
                        <value>1</value>
                        <value selector="disabled">0</value>
                        <value selector="enabled">1</value>
                  </Value>
                  <Value id="prevent_guest_system_log_access_var" type="boolean" operator="equals">
                        <title>Restrict Guest Access to System Log</title>
                        <description>This value determines if the local guests group is prevented from accessing the system log. 1 = enabled/prevented</description>
                        <value>1</value>
                        <value selector="disabled">0</value>
                        <value selector="enabled">1</value>
                  </Value>
                  <Value id="retention_application_log_var" type="number" operator="greater than or equal">
                        <title>Retention Method for Application Log</title>
                        <description>This value determines how the application log handles itself when it reaches its maximum size. The log can be overwritten after a certain number of seconds, overwritten when it becomes full, or have to be cleared manually.</description>
                        <value>0</value>
                        <value selector="overwrite_as_needed">0</value>
                        <value selector="86400_seconds">86400</value>
                        <value selector="604800_seconds">604800</value>
                        <value selector="1209600_seconds">1209600</value>
                        <value selector="do_not_overwrite">16777215</value>
                  </Value>
                  <Value id="retention_security_log_var" type="number" operator="greater than or equal">
                        <title>Retention Method for Security Log</title>
                        <description>This value determines how the security log handles itself when it reaches its maximum size. The log can be overwritten after a certain number of seconds, overwritten when it becomes full, or have to be cleared manually. 1 day = 86400 seconds</description>
                        <value>0</value>
                        <value selector="overwrite_as_needed">0</value>
                        <value selector="86400_seconds">86400</value>
                        <value selector="604800_seconds">604800</value>
                        <value selector="1209600_seconds">1209600</value>
                        <value selector="do_not_overwrite">16777215</value>
                  </Value>
                  <Value id="retention_system_log_var" type="number" operator="greater than or equal">
                        <title>Retention Method for System Log</title>
                        <description>This value determines how the system log handles itself when it reaches its maximum size. The log can be overwritten after a certain number of seconds, overwritten when it becomes full, or have to be cleared manually.</description>
                        <value>0</value>
                        <value selector="overwrite_as_needed">0</value>
                        <value selector="86400_seconds">86400</value>
                        <value selector="604800_seconds">604800</value>
                        <value selector="1209600_seconds">1209600</value>
                        <value selector="do_not_overwrite">16777215</value>
                  </Value>
                  <Rule id="maximum_application_log_size" selected="false" weight="10.0">
                        <title>Maximum Application Log Size</title>
                        <description>Inadequate log size will cause the log to fill up quickly and require frequent clearing by administrative personnel. An exception is for NT workstations that do not share resources. The smaller size should allow sufficient audit information for supporting the investigation of suspicious events, but since it is overwritten, does not require administrator interaction for clearing the file. Microsoft recommends that the combined size of all the event logs (including DNS logs, Directory Services logs, and Replication logs on Servers or Domain Controllers) should not exceed 300 megabytes. Exceeding the recommended value can impact performance.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-2904-1</ident>
                        <ident system="cce.mitre.org/version/4">CCE-185</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="maximum_application_log_size_var" export-name="oval:gov.nist.fdcc.xp:var:16"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:197"/>
                        </check>
                  </Rule>
                  <Rule id="maximum_security_log_size" selected="false" weight="10.0">
                        <title>Maximum Security Log Size</title>
                        <description>Inadequate log size will cause the log to fill up quickly and require frequent clearing by administrative personnel. An exception is for NT workstations that do not share resources. The smaller size should allow sufficient audit information for supporting the investigation of suspicious events, but since it is overwritten, does not require administrator interaction for clearing the file. Microsoft recommends that the combined size of all the event logs (including DNS logs, Directory Services logs, and Replication logs on Servers or Domain Controllers) should not exceed 300 megabytes. Exceeding the recommended value can impact performance.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-2693-0</ident>
                        <ident system="cce.mitre.org/version/4">CCE-757</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="maximum_security_log_size_var" export-name="oval:gov.nist.fdcc.xp:var:81"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:198"/>
                        </check>
                  </Rule>
                  <Rule id="maximum_system_log_size" selected="false" weight="10.0">
                        <title>Maximum System Log Size</title>
                        <description>Inadequate log size will cause the log to fill up quickly and require frequent clearing by administrative personnel. An exception is for NT workstations that do not share resources. The smaller size should allow sufficient audit information for supporting the investigation of suspicious events, but since it is overwritten, does not require administrator interaction for clearing the file. Microsoft recommends that the combined size of all the event logs (including DNS logs, Directory Services logs, and Replication logs on Servers or Domain Controllers) should not exceed 300 megabytes. Exceeding the recommended value can impact performance.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-3006-4</ident>
                        <ident system="cce.mitre.org/version/4">CCE-735</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="maximum_system_log_size_var" export-name="oval:gov.nist.fdcc.xp:var:84"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:199"/>
                        </check>
                  </Rule>
                  <Rule id="prevent_guest_application_log_access" selected="false" weight="10.0">
                        <title>Prevent Local Guests Group From Accessing Application Log</title>
                        <description>By default, the Windows XP event logs may be viewed over the network by an anonymous user. This method of access over the network is communicating through the Server service which has SYSTEM access to the actual log files.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-2116-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-299</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="prevent_guest_application_log_access_var" export-name="oval:gov.nist.fdcc.xp:var:120"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:200"/>
                        </check>
                  </Rule>
                  <Rule id="prevent_guest_security_log_access" selected="false" weight="10.0">
                        <title>Prevent Local Guests Group From Accessing Security Log</title>
                        <description>By default, the Windows XP event logs may be viewed over the network by an anonymous user. This method of access over the network is communicating through the Server service which has SYSTEM access to the actual log files.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-2794-6</ident>
                        <ident system="cce.mitre.org/version/4">CCE-462</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="prevent_guest_security_log_access_var" export-name="oval:gov.nist.fdcc.xp:var:121"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:201"/>
                        </check>
                  </Rule>
                  <Rule id="prevent_guest_system_log_access" selected="false" weight="10.0">
                        <title>Prevent Local Guests Group From Accessing System Log</title>
                        <description>By default, the Windows XP event logs may be viewed over the network by an anonymous user. This method of access over the network is communicating through the Server service which has SYSTEM access to the actual log files.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-2345-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-726</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="prevent_guest_system_log_access_var" export-name="oval:gov.nist.fdcc.xp:var:122"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:202"/>
                        </check>
                  </Rule>
                  <Rule id="retention_application_log" selected="false" weight="10.0">
                        <title>Retention of Events in Application Log</title>
                        <description>The application log should be configured to correctly handle itself when it reaches the maximum size. The log can be overwritten after a certain number of days, overwritten when it becomes full, or have to be cleared manually.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-3014-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-285</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="retention_application_log_var" export-name="oval:gov.nist.fdcc.xp:var:259"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:203"/>
                        </check>
                  </Rule>
                  <Rule id="retention_security_log" selected="false" weight="10.0">
                        <title>Retention of Events in Security Log</title>
                        <description>The security log should be configured to correctly handle itself when it reaches the maximum size. The log can be overwritten after a certain number of days, overwritten when it becomes full, or have to be cleared manually.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-2336-6</ident>
                        <ident system="cce.mitre.org/version/4">CCE-523</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="retention_security_log_var" export-name="oval:gov.nist.fdcc.xp:var:260"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:204"/>
                        </check>
                  </Rule>
                  <Rule id="retention_system_log" selected="false" weight="10.0">
                        <title>Retention of Events in System Log</title>
                        <description>The system log should be configured to correctly handle itself when it reaches the maximum size. The log can be overwritten after a certain number of days, overwritten when it becomes full, or have to be cleared manually.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\Event Log</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AU-4"/>
                        <ident system="http://cce.mitre.org">CCE-2777-1</ident>
                        <ident system="cce.mitre.org/version/4">CCE-664</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export value-id="retention_system_log_var" export-name="oval:gov.nist.fdcc.xp:var:261"/>
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:205"/>
                        </check>
                  </Rule>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  File Permissions Group                                                                    -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="file_permissions_group">
                  <title>File Permission Settings</title>
                  <description>This group checks the permissions of specified files.</description>
                  <Rule id="rcp.exePermissions" selected="false" weight="10.0">
                        <title>rcp.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2784-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-997</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:144"/>
                        </check>
                  </Rule>
                  <Rule id="reg.exePermissions" selected="false" weight="10.0">
                        <title>reg.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2220-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-547</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:145"/>
                        </check>
                  </Rule>
                  <Rule id="regedt32.exePermissions" selected="false" weight="10.0">
                        <title>regedt32.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2833-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-865</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:147"/>
                        </check>
                  </Rule>
                  <Rule id="regedit.exePermissions" selected="false" weight="10.0">
                        <title>regedit.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2175-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-795</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:146"/>
                        </check>
                  </Rule>
                  <Rule id="arp.exePermissions" selected="false" weight="10.0">
                        <title>arp.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2052-9</ident>
                        <ident system="cce.mitre.org/version/4">CCE-600</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:128"/>
                        </check>
                  </Rule>
                  <Rule id="at.exePermissions" selected="false" weight="10.0">
                        <title>at.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2184-0</ident>
                        <ident system="cce.mitre.org/version/4">CCE-393</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:129"/>
                        </check>
                  </Rule>
                  <Rule id="attrib.exePermissions" selected="false" weight="10.0">
                        <title>attrib.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2312-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-166</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:130"/>
                        </check>
                  </Rule>
                  <Rule id="cacls.exePermissions" selected="false" weight="10.0">
                        <title>cacls.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2726-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-977</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:131"/>
                        </check>
                  </Rule>
                  <Rule id="debug.exePermissions" selected="false" weight="10.0">
                        <title>debug.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2699-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-201</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:132"/>
                        </check>
                  </Rule>
                  <Rule id="edlin.exePermissions" selected="false" weight="10.0">
                        <title>edlin.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-1909-1</ident>
                        <ident system="cce.mitre.org/version/4">CCE-20</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:133"/>
                        </check>
                  </Rule>
                  <Rule id="eventcreate.exePermissions" selected="false" weight="10.0">
                        <title>eventcreate.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2145-1</ident>
                        <ident system="cce.mitre.org/version/4">CCE-489</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:134"/>
                        </check>
                  </Rule>
                  <Rule id="eventtriggers.exePermissions" selected="false" weight="10.0">
                        <title>eventtriggers.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2436-4</ident>
                        <ident system="cce.mitre.org/version/4">CCE-917</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:135"/>
                        </check>
                  </Rule>
                  <Rule id="mshta.exe-permissions" selected="false" weight="10.0">
                        <title>mshta.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-4952-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-1225</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:1351"/>
                        </check>
                  </Rule>
                  <Rule id="net.exePermissions" selected="false" weight="10.0">
                        <title>net.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2178-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-731</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:138"/>
                        </check>
                  </Rule>
                  <Rule id="net1.exePermissions" selected="false" weight="10.0">
                        <title>net1.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2672-4</ident>
                        <ident system="cce.mitre.org/version/4">CCE-607</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:139"/>
                        </check>
                  </Rule>
                  <Rule id="netsh.exePermissions" selected="false" weight="10.0">
                        <title>netsh.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-1916-6</ident>
                        <ident system="cce.mitre.org/version/4">CCE-158</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:140"/>
                        </check>
                  </Rule>
                  <Rule id="regini.exePermissions" selected="false" weight="10.0">
                        <title>regini.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2855-5</ident>
                        <ident system="cce.mitre.org/version/4">CCE-543</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:148"/>
                        </check>
                  </Rule>
                  <Rule id="regsvr32.exePermissions" selected="false" weight="10.0">
                        <title>regsvr32.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2894-4</ident>
                        <ident system="cce.mitre.org/version/4">CCE-657</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:149"/>
                        </check>
                  </Rule>
                  <Rule id="rexec.exePermissions" selected="false" weight="10.0">
                        <title>rexec.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2899-3</ident>
                        <ident system="cce.mitre.org/version/4">CCE-274</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:150"/>
                        </check>
                  </Rule>
                  <Rule id="route.exePermissions" selected="false" weight="10.0">
                        <title>route.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2546-0</ident>
                        <ident system="cce.mitre.org/version/4">CCE-168</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:151"/>
                        </check>
                  </Rule>
                  <Rule id="rsh.exePermissions" selected="false" weight="10.0">
                        <title>rsh.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2674-0</ident>
                        <ident system="cce.mitre.org/version/4">CCE-353</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:152"/>
                        </check>
                  </Rule>
                  <Rule id="sc.exePermissions" selected="false" weight="10.0">
                        <title>sc.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2176-6</ident>
                        <ident system="cce.mitre.org/version/4">CCE-516</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:153"/>
                        </check>
                  </Rule>
                  <Rule id="secedit.exePermissions" selected="false" weight="10.0">
                        <title>secedit.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2198-0</ident>
                        <ident system="cce.mitre.org/version/4">CCE-922</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:154"/>
                        </check>
                  </Rule>
                  <Rule id="subst.exePermissions" selected="false" weight="10.0">
                        <title>subst.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2788-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-921</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:155"/>
                        </check>
                  </Rule>
                  <Rule id="systeminfo.exePermissions" selected="false" weight="10.0">
                        <title>systeminfo.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2797-9</ident>
                        <ident system="cce.mitre.org/version/4">CCE-225</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:156"/>
                        </check>
                  </Rule>
                  <Rule id="tftp.exePermissions" selected="false" weight="10.0">
                        <title>tftp.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-2731-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-348</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:158"/>
                        </check>
                  </Rule>
                  <Rule id="tlntsvr.exePermissions" selected="false" weight="10.0">
                        <title>tlntsvr.exe Permissions</title>
                        <description>Failure to properly configure ACL file and directory permissions, allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Windows Settings\Security Settings\File System</dc:source>
                        </reference>
                        <requires idref="CM-6"/>
                        <requires idref="AC-3"/>
                        <ident system="http://cce.mitre.org">CCE-1937-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-718</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:159"/>
                        </check>
                  </Rule>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Local Policies Group                                                                      -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="local_policies_group">
                  <title>Local Policies Group</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                Audit Policy Settings                -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="audit_policy_settings">
                        <title>Audit Policy Settings</title>
                        <description>Windows XP includes powerful system auditing capabilities. The purpose of auditing is to record certain types of actions to a log, so that system administrators can review the logs and detect unauthorized activity. Audit logs may also be helpful when investigating a security incident that has occurred. As shown in Table 6-1, system auditing is available for logon events, account management, directory service access, object access, policy change, privilege use, process tracking, and system events. Each audit policy category can be configured to record successful events, failed events, both successful and failed events, or neither. Section 7.3 describes how file auditing can be configured, as well as how the Event Viewer can be used to review log entries.</description>
                        <Value id="AuditAccountLogonEvents_var" type="string" operator="pattern match">
                              <title>Audit Account Logon Events</title>
                              <description>Audits when a user logs on or off a remote computer from this workstation.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditAccountManagement_var" type="string" operator="pattern match">
                              <title>Audit Account Management</title>
                              <description>Audits when a user account or group is created, changed, or deleted; a user account is renamed, disabled, or enabled; a password is set or changed.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditDirectoryServiceAccess_var" type="string" operator="pattern match">
                              <title>Audit Directory Service Access</title>
                              <description>Audit Directory Service Access</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditLogonEvents_var" type="string" operator="pattern match">
                              <title>Audit Logon Events</title>
                              <description>Audits users logging on, logging off, or making a network connection to the local computer.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditObjectAccess_var" type="string" operator="pattern match">
                              <title>Audit Object Access</title>
                              <description>Audits a user accessing an object (for example, a file, folder, registry key, or printer) that has its own SACL specified.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditPolicyChange_var" type="string" operator="pattern match">
                              <title>Audit Policy Change</title>
                              <description>Audits every change to user rights assignment policies, audit policies, and trust policies.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditPrivilegeUse_var" type="string" operator="pattern match">
                              <title>Audit Privilege Use</title>
                              <description>Audits each instance of a user exercising a user right.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditProcessTracking_var" type="string" operator="pattern match">
                              <title>Audit Process Tracking</title>
                              <description>Audits detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Value id="AuditSystemEvents_var" type="string" operator="pattern match">
                              <title>Audit System Events</title>
                              <description>Audits when a user restarts or shuts down the computer or when an event occurs that affects either the system security or the security log.</description>
                              <value>AUDIT_NONE</value>
                              <value selector="success">AUDIT_(SUCCESS|SUCCESS_FAILURE)</value>
                              <value selector="failure">AUDIT_(FAILURE|SUCCESS_FAILURE)</value>
                              <value selector="success_failure">AUDIT_SUCCESS_FAILURE</value>
                              <value selector="none">AUDIT_NONE</value>
                        </Value>
                        <Rule id="AuditAccountLogonEvents" selected="false" weight="10.0">
                              <title>Audit Account Logon Events</title>
                              <description>Audits when a user logs on or off a remote computer from this workstation.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-3867-0</ident>
                              <ident system="http://cce.mitre.org">CCE-3008-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2628</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2543</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditAccountLogonEvents_var" export-name="oval:gov.nist.fdcc.xp:var:29"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:27"/>
                              </check>
                        </Rule>
                        <Rule id="AuditAccountManagement" selected="false" weight="10.0">
                              <title>Audit Account Management</title>
                              <description>Audits when a user account or group is created, changed, or deleted; a user account is renamed, disabled, or enabled; a password is set or changed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2906-6</ident>
                              <ident system="http://cce.mitre.org">CCE-2902-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2000</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1646</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditAccountManagement_var" export-name="oval:gov.nist.fdcc.xp:var:31"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:29"/>
                              </check>
                        </Rule>
                        <Rule id="AuditDirectoryServiceAccess" selected="false" weight="10.0">
                              <title>Audit Directory Service Access</title>
                              <description>Audits the event of a user accessing an active directory object that has its own System Access Control List (SACL) specified. This setting is not applicable to Windows XP systems.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2933-0</ident>
                              <ident system="http://cce.mitre.org">CCE-2206-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2118</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2390</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditDirectoryServiceAccess_var" export-name="oval:gov.nist.fdcc.xp:var:32"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:30"/>
                              </check>
                        </Rule>
                        <Rule id="AuditLogonEvents" selected="false" weight="10.0">
                              <title>Audit Logon Events</title>
                              <description>Audits users logging on, logging off, or making a network connection to the local computer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2100-6</ident>
                              <ident system="http://cce.mitre.org">CCE-2343-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1686</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1744</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditLogonEvents_var" export-name="oval:gov.nist.fdcc.xp:var:33"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:32"/>
                              </check>
                        </Rule>
                        <Rule id="AuditObjectAccess" selected="false" weight="10.0">
                              <title>Audit Object Access</title>
                              <description>Audits a user accessing an object (for example, a file, folder, registry key, or printer) that has its own SACL specified. Auditing of success or failure of system wide object access will create numerous log entries. Certain object access failures may be normal as a result of applications requesting all access types to objects, even though the application does not require all access types to function properly. Use object access auditing with caution.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2259-0</ident>
                              <ident system="http://cce.mitre.org">CCE-2766-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2640</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1991</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditObjectAccess_var" export-name="oval:gov.nist.fdcc.xp:var:35"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:34"/>
                              </check>
                        </Rule>
                        <Rule id="AuditPolicyChange" selected="false" weight="10.0">
                              <title>Audit Policy Change</title>
                              <description>Audits every change to user rights assignment policies, audit policies, and trust policies.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2971-0</ident>
                              <ident system="http://cce.mitre.org">CCE-2757-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2412</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2347</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditPolicyChange_var" export-name="oval:gov.nist.fdcc.xp:var:36"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:35"/>
                              </check>
                        </Rule>
                        <Rule id="AuditPrivilegeUse" selected="false" weight="10.0">
                              <title>Audit Privilege Use</title>
                              <description>Audits each instance of a user exercising a user right. This is likely to generate a very large number of events.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2913-2</ident>
                              <ident system="http://cce.mitre.org">CCE-2918-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2431</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2584</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditPrivilegeUse_var" export-name="oval:gov.nist.fdcc.xp:var:37"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:36"/>
                              </check>
                        </Rule>
                        <Rule id="AuditProcessTracking" selected="false" weight="10.0">
                              <title>Audit of Process Tracking</title>
                              <description>Audits detailed tracking information for events such as program activation, process exit, handle duplication, and indirect object access. Enabling this setting will generate many events, so it should only be used when absolutely necessary.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2816-7</ident>
                              <ident system="http://cce.mitre.org">CCE-2939-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2529</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2617</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditProcessTracking_var" export-name="oval:gov.nist.fdcc.xp:var:42"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:40"/>
                              </check>
                        </Rule>
                        <Rule id="AuditSystemEvents" selected="false" weight="10.0">
                              <title>Audit System Events</title>
                              <description>Audits when a user restarts or shuts down the computer or when an event occurs that affects either the system security or the security log.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AU-2"/>
                              <ident system="http://cce.mitre.org">CCE-2878-7</ident>
                              <ident system="http://cce.mitre.org">CCE-2843-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2420</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1680</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditSystemEvents_var" export-name="oval:gov.nist.fdcc.xp:var:38"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:37"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Security Options Settings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="security_options_settings">
                        <title>Security Options Settings</title>
                        <description>todo - description needed</description>
                        <Value id="AdministratorAccountStatus_var" type="boolean" operator="equals">
                              <title>Accounts: Administrator account status</title>
                              <description>The Administrator account status is enabled to allow the administrator to perform configuration control of the system.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="GuestAccountStatus_var" type="boolean" operator="equals">
                              <title>Status of Guest Account</title>
                              <description>This value defines the desired status of the built-in Guest account. 1 = enabled</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="LimitBlankPassword_var" type="boolean" operator="equals">
                              <title>Status of Blank Password</title>
                              <description>This value defines the desired status of limiting the use of blank passwords. 1 = enabled</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <!-- RenameAdministrator -->
                        <!-- RenameGuest -->
                        <!-- AuditAccessToGlobalObjects -->
                        <Value id="AuditBackupAndRestorePrivilege_var" type="string" operator="equals">
                              <title>Audit the use of Backup and Restore privilege</title>
                              <description>This value defines the whether use of the Backup and Restore privilege will be audited. 01 = enabled</description>
                              <value>00</value>
                              <value selector="disabled">00</value>
                              <value selector="enabled">01</value>
                        </Value>
                        <Value id="ShutDownIfUnableToLogSecurityAudits_var" operator="equals" type="number">
                              <title>Audit: Shut down system immediately if unable to log security audits</title>
                              <description>If events cannot be written to the security log, the system is halted immediately. If the system halts as a result of a full log, an administrator must log onto the system and clear the log.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <!-- MachineAccessRestrictions -->
                        <!-- AllowUndockWithoutLogin -->
                        <Value id="AllowFormatEjectRemovableMedia_var" operator="less than or equal" type="number">
                              <title>Devices: Allow only administrators to format and eject removable media</title>
                              <description>Verifies that only the correct users are allowed to format and eject removable media 0 - Only Administrator, 1 - Only Administrators and power users, 2 - Only Administrators and Interactive user</description>
                              <value>0</value>
                              <value selector="administrator_only">0</value>
                              <value selector="administrator_and_powerusers_only">1</value>
                              <value selector="administrator_and_interactiveuser_only">2</value>
                        </Value>
                        <Value id="PreventUsersFromInstallingPrinterDrivers_var" type="boolean" operator="equals">
                              <title>Prevent Users From Installing Printer Drivers</title>
                              <description>Defines who is allowed to add and to delete printer drivers on the local system. 0 = disabled</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="RestrictCDROMAccess_var" type="boolean" operator="equals">
                              <title>Restrict Access to CDROM Drive</title>
                              <description>This value determines if access to the CDROM drive is restricted to locally logged-on users. 1 = restricted</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="RestrictFloppyAccess_var" type="boolean" operator="equals">
                              <title>Restrict Access to Floppy Drive</title>
                              <description>This value determines if access to the floppy drive is restricted to locally logged-on users. 1 = restricted</description>
                              <value>0</value>
                              <value selector="not_restricted">0</value>
                              <value selector="restricted">1</value>
                        </Value>
                        <Value id="UnsignedDriverInstallationWarning_var" type="number" operator="equals">
                              <title>Devices: Unsigned driver installation behavior</title>
                              <description>When an attempt is made to install a device driver (by means of the Windows XP device installer) that has not been certified by the Windows Hardware Quality Lab (WHQL), a warning should be issued, but the installation allowed to continue.</description>
                              <value>1</value>
                              <value selector="ignore">0</value>
                              <value selector="warn">1</value>
                              <value selector="block">2</value>
                        </Value>
                        <Value id="maximum_machine_account_password_age_var" type="number" operator="less than or equal">
                              <title>Maximum Machine Account Password Age</title>
                              <description>This setting controls the maximum password age that a machine account may have.</description>
                              <value>30</value>
                              <value selector="7_days">7</value>
                              <value selector="30_days">30</value>
                        </Value>
                        <Value id="require_strong_session_key_var" type="number" operator="equals">
                              <title>Require Strong (Windows 2000 or Later) Session Key</title>
                              <description>This setting controls the required strength of a session key.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="previous_logons_cached_var" type="number" operator="less than or equal">
                              <title>Number of Previous Logons to Cache (in Case Domain Controller Is Not Available)</title>
                              <description>Defines the number of last logon credentials cached for users who log on interactively to a system.</description>
                              <value>2</value>
                              <value selector="0_cached">0</value>
                              <value selector="1_cached">1</value>
                              <value selector="2_cached">2</value>
                              <value selector="5_cached">5</value>
                              <value selector="10_cached">10</value>
                        </Value>
                        <Value id="password_expiration_prompt_var" type="number" operator="greater than or equal">
                              <title>Prompt User to Change Password Before Expiration</title>
                              <description>This setting configures the system to display a warning to users telling them how many days are left before their password expires.</description>
                              <value>14</value>
                              <value selector="14_days">14</value>
                        </Value>
                        <Value id="domain_controller_authentication_required_var" type="boolean" operator="equals">
                              <title>Require Domain Controller Authentication to Unlock Workstation</title>
                              <description>This setting controls the behavior of the system when you attempt to unlock the workstation. If this setting is enabled, the system will pass the credentials to the domain controller (if in a domain) for authentication before allowing the system to be unlocked.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="smart_card_removal_var" type="number" operator="greater than or equal">
                              <title>Smart Card Removal Behavior</title>
                              <description>This value determines the desired behavior when a smart card is removed. 0 - No action 1 - Lock workstation 2 - Force logoff</description>
                              <value>1</value>
                              <value selector="no_action">0</value>
                              <value selector="lock_workstation">1</value>
                              <value selector="force_logoff">2</value>
                        </Value>
                        <Value id="client_always_sign_communications_var" type="boolean" operator="equals">
                              <title>Client Digitally Sign Communications (Always)</title>
                              <description>This check verifies that the client policy is set to always sign packets.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="unencrypted_smb_passwords_var" type="boolean" operator="equals">
                              <title>Send unencrypted password to third-party SMB servers</title>
                              <description>Status of allowing system to send unencrypted password to third-party SMB servers.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="session_timeout_var" type="number" operator="less than or equal">
                              <title>Amount of Idle Time Required Before Suspending Session</title>
                              <description>Administrators should use this setting to control when a computer disconnects an inactive SMB session. If client activity resumes, the session is automatically reestablished.</description>
                              <value>15</value>
                              <value selector="15_minutes">15</value>
                        </Value>
                        <Value id="LogonTimeExpiration_var" type="number" operator="equals">
                              <title>Client Forced to Disconnect</title>
                              <description>Specifies whether the server should force a client to disconnect, even if the client has open files, once the client's logon time has expired.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="ntlm_ssp_based_client_session_security_var" type="number" operator="equals">
                              <title>Minimum session security for NTLM SSP based (including secure RPC) clients</title>
                              <description>This value specifies the minimum required security setting of client-side network connections for applications using the NTLM security support provider (SSP).</description>
                              <value>537395248</value>
                              <value selector="536870912">536870912</value>
                              <value selector="537395200">537395200</value>
                              <value selector="537395248">537395248</value>
                        </Value>
                        <Value id="ntlm_ssp_based_servers_session_security_var" type="number" operator="equals">
                              <title>Minimum session security for NTLM SSP based (including secure RPC) servers</title>
                              <description>This value specifies the minimum required security setting of server-side network connections for applications using the NTLM security support provider (SSP).</description>
                              <value>537395248</value>
                              <value selector="536870912">536870912</value>
                              <value selector="537395200">537395200</value>
                              <value selector="537395248">537395248</value>
                        </Value>
                        <Value id="AutomaticLogonDisabled_var" type="number" operator="equals">
                              <title>Enable Automatic Logon Disabled</title>
                              <description>Enable Automatic Logon Disabled</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="IPSourceRoutingProtectionLevel_var" type="number" operator="equals">
                              <title>IP source routing protection level</title>
                              <description>IP source routing protection level</description>
                              <value>2</value>
                              <value selector="enabled">0</value>
                              <value selector="disabled_when_ip_forwarding_enabled">1</value>
                              <value selector="disabled_completely">2</value>
                        </Value>
                        <Value id="AutomaticDetectionOfDeadGWs_var" type="number" operator="equals">
                              <title>Allow automatic detection of dead network gateways</title>
                              <description>Allow automatic detection of dead network gateways</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="AllowICMPRedirectsDisabled_var" type="number" operator="equals">
                              <title>Allow ICMP redirects to override OSPF generated routes</title>
                              <description>Allow ICMP redirects to override OSPF generated routes</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="EnablePMTUDiscovery_var" type="boolean" operator="equals">
                              <title>EnablePMTUDiscovery</title>
                              <description>EnablePMTUDiscovery</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="KeepAliveTime_var" type="number" operator="less than or equal">
                              <title>How Often Keep-Alive Packets Are Sent in Milliseconds</title>
                              <description>This check verifies that the system is configured to control how often TCP attempts to verify that an idle connection is still intact by sending a keep-alive packet.</description>
                              <value>300000</value>
                              <value selector="300000_seconds">300000</value>
                        </Value>
                        <Value id="NameReleaseRequests_var" type="number" operator="equals">
                              <title>Allow the computer to ignore NetBIOS name release requests except from WINS servers</title>
                              <description>Allow the computer to ignore NetBIOS name release requests except from WINS servers</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="Disable8Dot3NameCreation_var" type="number" operator="equals">
                              <title>Allow the computer to ignore NetBIOS name release requests except from WINS servers</title>
                              <description>Allow the computer to ignore NetBIOS name release requests except from WINS servers</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="RouterDiscovery_var" type="boolean" operator="equals">
                              <title>RouterDiscovery</title>
                              <description>RouterDiscovery value</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="ScreenSaverGracePeriod_var" type="number" operator="equals">
                              <title>ScreenSaverGracePeriod</title>
                              <description>ScreenSaverGracePeriod value</description>
                              <value>0</value>
                              <value selector="5_seconds">5</value>
                        </Value>
                        <Value id="SynAttackProtectionLevel_var" type="number" operator="equals">
                              <title>SynAttackProtectionLevel</title>
                              <description>SynAttackProtectionLevel value</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                              <value selector="enabled_enhanced">2</value>
                        </Value>
                        <Value id="TCPMaxDataRetransmissions_var" type="number" operator="less than or equal">
                              <title>How Many Times Unacknowledged Data Is Retransmitted</title>
                              <description>This check verifies that the system is configured to control the maximum number of times that TCP retransmits unacknowledged data segments before aborting the attempt.</description>
                              <value>3</value>
                              <value selector="3_retransmissions">3</value>
                        </Value>
                        <Value id="EventLogThresholdWarning_var" type="number" operator="less than or equal">
                              <title>Percentage Threshold for the Security Event Log at Which the System Will Generate a Warning</title>
                              <description>This check verifies that the system is configured to generate a warning when the Security Event Log has reached a defined threshold. </description>
                              <value>90</value>
                              <value selector="90_percent">90</value>
                        </Value>
                        <Value id="anonymous_sid_name_translation_var" type="string" operator="equals">
                              <title>Network access: Allow anonymous SID-Name translation</title>
                              <description>Determines if an anonymous user can request security identifier (SID) attributes for another user or use a SID to get the corresponding username.</description>
                              <value>False</value>
                              <value selector="enabled">True</value>
                              <value selector="disabled">False</value>
                        </Value>
                        <Value id="always_digitally_encrypt_secure_channel_data_var" operator="equals" type="number">
                              <title>Domain member: Digitally encrypt or sign secure channel data (always)</title>
                              <description>Domain member: Digitally encrypt or sign secure channel data (always). Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted or signed. If this policy is enabled, outgoing secure channel traffic should be encrypted.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="server_always_sign_communications_var" operator="equals" type="number">
                              <title>Microsoft network server: Digitally sign communications (always)</title>
                              <description>This check verifies that the server policy is set to always sign packets.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="shutdown_without_logon_var" operator="equals" type="number">
                              <title>Shutdown: Allow system to be shut down without having to log on</title>
                              <description>Displaying the shutdown button may allow individuals to shut down a system anonymously. Only authenticated users should be allowed to shut down the system. Preventing display of this button in the logon dialog box, ensures that individuals who shut down the system are authorized and tracked in the systems Security event log.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="AdministratorAccountStatus" selected="false" weight="10.0">
                              <title>Accounts: Administrator account status</title>
                              <description>The Administrator account status is enabled to allow the administrator to perform configuration control of the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2943-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-499</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AdministratorAccountStatus_var" export-name="oval:gov.nist.fdcc.xp:var:50"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:242"/>
                              </check>
                        </Rule>
                        <Rule id="GuestAccountStatus" selected="false" weight="10.0">
                              <title>Accounts: Guest account status</title>
                              <description>A system faces an increased vulnerability threat if the built-in guest account is not disabled. This account is a known account that exists on all Windows systems and cannot be deleted. This account is initialized during the installation of the operating system with no password assigned. This account is a member of the Everyone user group and has all the rights and permissions associated with that group, which could subsequently provide access to system resources to anonymous users. Ensure the built-in guest account is disabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3040-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-332</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="GuestAccountStatus_var" export-name="oval:gov.nist.fdcc.xp:var:51"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:243"/>
                              </check>
                        </Rule>
                        <Rule id="LimitBlankPassword" selected="false" weight="10.0">
                              <title>Accounts: Limit local account use of blank passwords to console logon only</title>
                              <description>In Windows XP Professional, accounts with null or blank passwords can only be used to log on at the physical system’s logon screen. This means that accounts with blank or null passwords cannot be used over networks or with the secondary logon service (RunAs). This feature prevents attackers and malware from gaining remote access through blank passwords. Section 6 contains information on other recommended password settings.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2344-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-533</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="LimitBlankPassword_var" export-name="oval:gov.nist.fdcc.xp:var:52"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:42"/>
                              </check>
                        </Rule>
                        <Rule id="RenameAdministrator" selected="false" weight="10.0">
                              <title>Accounts: Rename administrator account</title>
                              <description>The Administrator account is created by default when installing Windows XP, but is disabled. Associating the Administrator SID with a different name may thwart a potential hacker who is targeting the built-in Administrator account.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3135-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-438</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6022"/>
                              </check>
                        </Rule>
                        <Rule id="RenameGuest" selected="false" weight="10.0">
                              <title>Accounts: Rename guest account</title>
                              <description>The Guest account is created by default when installing Windows XP, but is disabled. Associating the Guest SID with a different name may thwart a potential hacker who is targeting the built-in Guest account.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3025-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-834</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6023"/>
                              </check>
                        </Rule>
                        <Rule id="AuditAccessToGlobalObjects" selected="false" weight="10.0">
                              <title>Audit: Audit the access of global system objects</title>
                              <description>Controls the ability to audit access of global systems objects. When this setting is enabled, system objects such as mutexes, events, semaphores, and DOS devices, are created with a default system access control list (SACL).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3162-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-2</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:45"/>
                              </check>
                        </Rule>
                        <Rule id="AuditBackupAndRestorePrivilege" selected="false" weight="10.0">
                              <title>Audit: Audit the use of Backup and Restore privilege</title>
                              <description>Controls the ability to audit the use of all user privileges, including Backup and Restore. If this policy is disabled, certain user rights will not be audited even if "Audit privilege use" audit policy is enabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2955-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-905</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AuditBackupAndRestorePrivilege_var" export-name="oval:gov.nist.fdcc.xp:var:53"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:52"/>
                              </check>
                        </Rule>
                        <Rule id="ShutDownIfUnableToLogSecurityAudits" selected="false" weight="10.0">
                              <title>Audit: Shut down system immediately if unable to log security audits</title>
                              <description>If events cannot be written to the security log, the system is halted immediately. If the system halts as a result of a full log, an administrator must log onto the system and clear the log.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2851-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-92</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:60271" value-id="ShutDownIfUnableToLogSecurityAudits_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6027"/>
                              </check>
                        </Rule>
                        <Rule id="MachineAccessRestrictions" selected="false" weight="10.0">
                              <title>DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax</title>
                              <description>This check verifies that Windows Server 2003/XP, is configured to restrict DCOM access permissions.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3010-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-458</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:608243"/>
                              </check>
                        </Rule>
                        <Rule id="MachineLaunchRestrictions" selected="false" weight="10.0">
                              <title>DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax</title>
                              <description>This check verifies that Windows Server 2003/XP, is configured to restrict DCOM launch permissions.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2662-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-740</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:608244"/>
                              </check>
                        </Rule>
                        <Rule id="AllowUndockWithoutLogin" selected="false" weight="10.0">
                              <title>Devices: Allow undock without having to log on</title>
                              <description>Since the removal of a computer should be controlled, users should have to log on before undocking the computer to ensure that they have the appropriate rights to undock the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3009-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-186</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:53"/>
                              </check>
                        </Rule>
                        <Rule id="AllowFormatEjectRemovableMedia" selected="false" weight="10.0">
                              <title>Devices: Allowed to format and eject removable media</title>
                              <description>Verifies that only the correct users are allowed to format and eject removable media&gt;</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3111-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-919</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:60291" value-id="AllowFormatEjectRemovableMedia_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6029"/>
                              </check>
                        </Rule>
                        <Rule id="PreventUsersFromInstallingPrinterDrivers" selected="false" weight="10.0">
                              <title>Devices: Prevent users from installing printer drivers</title>
                              <description>This setting determines who is allowed to install a printer driver as part of adding a network printer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2789-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-402</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="PreventUsersFromInstallingPrinterDrivers_var" export-name="oval:gov.nist.fdcc.xp:var:277"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:56"/>
                              </check>
                        </Rule>
                        <Rule id="RestrictCDROMAccess" selected="false" weight="10.0">
                              <title>Devices: Restrict CD-ROM access to locally logged-on user only</title>
                              <description>Removable media devices (CD-ROM) are readable by others on the network if they are not properly configured. A process can remain running in the background after a user logs off, thereby, permitting access to the media, while another user is logged on to the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2974-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-565</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="RestrictCDROMAccess_var" export-name="oval:gov.nist.fdcc.xp:var:281"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:58"/>
                              </check>
                        </Rule>
                        <Rule id="RestrictFloppyAccess" selected="false" weight="10.0">
                              <title>Devices: Restrict floppy access to locally logged-on user only</title>
                              <description>Removable media devices (floppy disks) are readable by others on the network if they are not properly configured. A process can remain running in the background after a user logs off, thereby, permitting access to the media, while another user is logged on to the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2873-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-463</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="RestrictFloppyAccess_var" export-name="oval:gov.nist.fdcc.xp:var:282"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:59"/>
                              </check>
                        </Rule>
                        <Rule id="UnsignedDriverInstallationBehavior" selected="false" weight="10.0">
                              <title>Devices: Unsigned driver installation behavior</title>
                              <description>When an attempt is made to install a device driver (by means of the Windows XP device installer) that has not been certified by the Windows Hardware Quality Lab (WHQL), a warning should be issued, but the installation allowed to continue.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3085-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-413</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="UnsignedDriverInstallationWarning_var" export-name="oval:gov.nist.fdcc.xp:var:287"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:60"/>
                              </check>
                        </Rule>
                        <Rule id="AllowServerOperatorsToScheduleTasks" selected="false" weight="10.0">
                              <title>Domain controller: Allow server operators to schedule tasks</title>
                              <description>This setting determines if Server Operators are allowed to submit jobs using the AT schedule utility.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2968-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-257</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:608240"/>
                              </check>
                        </Rule>
                        <Rule id="LDAPServerSigningRequirements" selected="false" weight="10.0">
                              <title>Domain controller: LDAP server signing requirements</title>
                              <description>Requires signing be negotiated before Lightweight Directory Access Protocol (LDAP) clients can bind with Active Directory LDAP server.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2551-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-710</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:608241"/>
                              </check>
                        </Rule>
                        <Rule id="RefuseMachineAccountPasswordChanges" selected="false" weight="10.0">
                              <title>Domain controller: Refuse machine account password changes</title>
                              <description>Determines whether a domain controller will accept password requests for computer accounts.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3123-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-490</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:608242"/>
                              </check>
                        </Rule>
                        <Rule id="always_digitally_encrypt_secure_channel_data" selected="false" weight="10.0">
                              <title>Domain member: Digitally encrypt or sign secure channel data (always)</title>
                              <description>Domain member: Digitally encrypt or sign secure channel data (always). Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted or signed. If this policy is enabled, outgoing secure channel traffic should be encrypted.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3097-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-549</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="always_digitally_encrypt_secure_channel_data_var" export-name="oval:gov.nist.fdcc.xp:var:6111"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:61"/>
                              </check>
                        </Rule>
                        <Rule id="WhenPossibleDigitallyEncryptSecureChannelData" selected="false" weight="10.0">
                              <title>Domain member: Digitally encrypt secure channel data (when possible)</title>
                              <description>Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but not all information is encrypted. If this policy is enabled, outgoing secure channel traffic should be encrypted.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2996-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-161</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:62"/>
                              </check>
                        </Rule>
                        <Rule id="WhenPossibleDigitallySignSecureChannelData" selected="false" weight="10.0">
                              <title>Domain member: Digitally sign secure channel data (when possible)</title>
                              <description>Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but the channel is not integrity checked. If this policy is enabled, all outgoing secure channel traffic should be signed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3000-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-918</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:63"/>
                              </check>
                        </Rule>
                        <Rule id="MachineAccountPasswordChanges" selected="false" weight="10.0">
                              <title>Domain member: Disable machine account password changes</title>
                              <description>Computer account passwords are changed automatically every seven days. Enabling this policy to disable automatic password changes can make the system more vulnerable to malicious access. Frequent password changes can be a significant safeguard for your system. If this policy is disabled, a new password for the computer account will be generated every week.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2313-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-831</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:64"/>
                              </check>
                        </Rule>
                        <Rule id="maximum_machine_account_password_age" selected="false" weight="10.0">
                              <title>Domain member: Maximum machine account password age</title>
                              <description>This setting controls the maximum password age that a machine account may have. This setting should be set to no more that 30 days, ensuring that the machine changes its password monthly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3018-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-194</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="maximum_machine_account_password_age_var" export-name="oval:gov.nist.fdcc.xp:var:30"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:65"/>
                              </check>
                        </Rule>
                        <Rule id="require_strong_session_key" selected="false" weight="10.0">
                              <title>Domain member: Require strong session key</title>
                              <description>This setting controls the required strength of a session key. Session keys in Windows XP are stronger than those in NT and should be used whenever possible.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3151-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-417</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="require_strong_session_key_var" export-name="oval:gov.nist.fdcc.xp:var:278"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:66"/>
                              </check>
                        </Rule>
                        <Rule id="LastUserNameNotDisplayedForLogon" selected="false" weight="10.0">
                              <title>Interactive logon: Do not display last user name</title>
                              <description>This setting determines whether the name of the last user to log on to the computer will be displayed in the Windows logon dialog box.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2930-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-65</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:68"/>
                              </check>
                        </Rule>
                        <Rule id="RequireCTRL_ALT_DEL" selected="false" weight="10.0">
                              <title>Interactive logon: Do not require CTRL+ALT+DEL</title>
                              <description>Disabling the Ctrl+Alt+Del security attention sequence can compromise system security. Because only Windows responds to the Ctrl+Alt+Del security sequence, you can be assured that any passwords you enter following that sequence are sent only to Windows. If you eliminate the sequence requirement, malicious programs can request and receive your Windows password. Disabling this sequence also suppresses a custom logon banner.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2891-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-133</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:69"/>
                              </check>
                        </Rule>
                        <Rule id="LogonMessageText" selected="false" weight="10.0">
                              <title>Interactive logon: Message text for users attempting to log on</title>
                              <description>Failure to display the logon banner prior to a logon attempt will negate legal proceedings resulting from unauthorized access to system resources.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-8 CM-7 SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2472-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-829</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:70"/>
                              </check>
                        </Rule>
                        <Rule id="LogonMessageTitle" selected="false" weight="10.0">
                              <title>Interactive logon: Message title for users attempting to log on</title>
                              <description>The logon banner should be titled with a warning label containing the name of the owning organization.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-8 CM-7 SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2573-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-23</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:71"/>
                              </check>
                        </Rule>
                        <Rule id="previous_logons_cached" selected="false" weight="10.0">
                              <title>Interactive logon: Number of previous logons cached (in case domain controller is not available)</title>
                              <description>The default Windows XP configuration caches the last logon credentials for users who log on interactively to a system. This feature is provided for system availability reasons such as the users machine is disconnected from the network or domain controllers are not available. Even though the credential cache is well-protected, storing encrypted copies of users passwords on workstations do not always have the same physical protection required for domain controllers. If a workstation is attacked, the unauthorized individual may isolate the password to a domain user account using a password-cracking program, and gain access to the domain.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3106-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-773</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="previous_logons_cached_var" export-name="oval:gov.nist.fdcc.xp:var:102"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:72"/>
                              </check>
                        </Rule>
                        <Rule id="password_expiration_prompt" selected="false" weight="10.0">
                              <title>Interactive logon: Prompt user to change password before expiration.</title>
                              <description>This setting configures the system to display a warning to users telling them how many days are left before their password expires. By giving the user advanced warning, the user has time to construct a sufficiently strong password.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2701-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-814</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="password_expiration_prompt_var" export-name="oval:gov.nist.fdcc.xp:var:14"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:74"/>
                              </check>
                        </Rule>
                        <Rule id="domain_controller_authentication_required" selected="false" weight="10.0">
                              <title>Interactive logon: Require Domain Controller authentication to unlock workstation.</title>
                              <description>This setting controls the behavior of the system when you attempt to unlock the workstation. If this setting is enabled, the system will pass the credentials to the domain controller (if in a domain) for authentication before allowing the system to be unlocked.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3172-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-374</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="domain_controller_authentication_required_var" export-name="oval:gov.nist.fdcc.xp:var:279"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:75"/>
                              </check>
                        </Rule>
                        <Rule id="RequireSmartCard" selected="false" weight="10.0">
                              <title>Interactive logon: Require smart card</title>
                              <description>This setting determines whether smart cards are required.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3186-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-828</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6082"/>
                              </check>
                        </Rule>
                        <Rule id="smart_card_removal" selected="false" weight="10.0">
                              <title>Interactive logon: Smart card removal behavior</title>
                              <description>When the smart card for a logged-on user is removed from the smart card reader, the workstation should be locked.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3133-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-443</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="smart_card_removal_var" export-name="oval:gov.nist.fdcc.xp:var:283"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:78"/>
                              </check>
                        </Rule>
                        <Rule id="client_always_sign_communications" selected="false" weight="10.0">
                              <title>Microsoft network client: Digitally sign communications (always)</title>
                              <description>This check verifies that the client policy is set to always sign packets.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3027-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-576</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="client_always_sign_communications_var" export-name="oval:gov.nist.fdcc.xp:var:280"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:79"/>
                              </check>
                        </Rule>
                        <Rule id="SignCommunicationsIfServerAgrees" selected="false" weight="10.0">
                              <title>Microsoft network client: Digitally sign communications (if server agrees)</title>
                              <description>This check verifies that the client policy is set to sign packets if the server agrees.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2802-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-519</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:81"/>
                              </check>
                        </Rule>
                        <Rule id="unencrypted_smb_passwords" selected="false" weight="10.0">
                              <title>Microsoft network client: Send unencrypted password to third-party SMB servers</title>
                              <description>Some non-Microsoft SMB servers only support unencrypted (plain text) password authentication. Sending plain text passwords across the network, when authenticating to an SMB server, reduces the overall security of the environment. Check with the Vendor of the SMB server to see if there is a way to support encrypted password authentication.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3049-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-228</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="unencrypted_smb_passwords_var" export-name="oval:gov.nist.fdcc.xp:var:214"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:82"/>
                              </check>
                        </Rule>
                        <Rule id="session_timeout" selected="false" weight="10.0">
                              <title>Microsoft network server: Amount of idle time required before suspending session</title>
                              <description>Administrators should use this setting to control when a computer disconnects an inactive SMB session. If client activity resumes, the session is automatically reestablished.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3157-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-222</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="session_timeout_var" export-name="oval:gov.nist.fdcc.xp:var:215"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:83"/>
                              </check>
                        </Rule>
                        <Rule id="server_always_sign_communications" selected="false" weight="10.0">
                              <title>Microsoft network server: Digitally sign communications (always)</title>
                              <description>This check verifies that the server policy is set to always sign packets.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3053-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-171</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="server_always_sign_communications_var" export-name="oval:gov.nist.fdcc.xp:var:8411"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:84"/>
                              </check>
                        </Rule>
                        <Rule id="SignCommunicationsIfClientAgrees" selected="false" weight="10.0">
                              <title>Microsoft network server: Digitally sign communications (if client agrees)</title>
                              <description>Microsoft network server: Digitally sign communications (if client agrees). This check verifies that the server policy is set to sign packets if the client agrees.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2688-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-104</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:85"/>
                              </check>
                        </Rule>
                        <Rule id="LogonTimeExpiration" selected="false" weight="10.0">
                              <title>Microsoft network server: Disconnect clients when logon hours expire</title>
                              <description>Users should not be permitted to remain logged on to the network after they have exceeded their permitted logon hours. In many cases, this indicates that a user forgot to log off before leaving for the day. However, it may also indicate that a user is attempting unauthorized access at a time when the system may be less closely monitored.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2692-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-278</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="LogonTimeExpiration_var" export-name="oval:gov.nist.fdcc.xp:var:216"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:86"/>
                              </check>
                        </Rule>
                        <Rule id="AutomaticLogonDisabled" selected="false" weight="10.0">
                              <title>MSS: (AutoAdminLogon) Enable Automatic Logon Disabled</title>
                              <description>If enabled, this setting will allow a user to directly log on to the system with administrator privileges when the machine is rebooted. This would give full access to any unauthorized individual who reboots the computer. By default this setting is not enabled. If this setting exists, it should be disabled. If this capability exists, the default password will also be present in the registry, and must be removed.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3 CM-7 IA-2 SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2776-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-283</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AutomaticLogonDisabled_var" export-name="oval:gov.nist.fdcc.xp:var:293"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:110"/>
                              </check>
                        </Rule>
                        <Rule id="IPSourceRoutingProtectionLevel" selected="false" weight="10.0">
                              <title>MSS: (DisableIPSourceRouting) IP source routing protection level</title>
                              <description>This setting protects against packet spoofing. Set to 2 to completely disable source routing.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3132-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-564</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="IPSourceRoutingProtectionLevel_var" export-name="oval:gov.nist.fdcc.xp:var:289"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:111"/>
                              </check>
                        </Rule>
                        <Rule id="AutomaticDetectionOfDeadGWs" selected="false" weight="10.0">
                              <title>MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways</title>
                              <description>If this setting is enabled, it could lead to a denial of service.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2718-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-897</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AutomaticDetectionOfDeadGWs_var" export-name="oval:gov.nist.fdcc.xp:var:292"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:112"/>
                              </check>
                        </Rule>
                        <Rule id="AllowICMPRedirectsDisabled" selected="false" weight="10.0">
                              <title>MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes</title>
                              <description>This check determines whether ICMP redirects are allowed to override OSPF generated routes.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2824-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-150</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="AllowICMPRedirectsDisabled_var" export-name="oval:gov.nist.fdcc.xp:var:290"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:113"/>
                              </check>
                        </Rule>
                        <Rule id="EnablePMTUDiscovery" selected="false" weight="10.0">
                              <title>EnablePMTUDiscovery</title>
                              <description>When this parameter is set to 1, TCP attempts to discover the Maximum Transmission Unit (MTU), the size of the largest packet that can be kept intact over the path to a remote host. Setting this parameter to 0 disables the feature and causes an MTU of 576 bytes to be used for all connections that are not made to hosts on the local subnet.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3017-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-998</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="EnablePMTUDiscovery_var" export-name="oval:gov.nist.fdcc.xp:var:407"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:407"/>
                              </check>
                        </Rule>
                        <Rule id="HideFromBrowseList" selected="false" weight="10.0">
                              <title>MSS: (Hidden) Hide Computer From the Browse List</title>
                              <description>This setting is not recommended to be enabled, except for highly secure environments.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2952-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-139</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:114"/>
                              </check>
                        </Rule>
                        <Rule id="KeepAliveTime" selected="false" weight="10.0">
                              <title>MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds</title>
                              <description>This check verifies that the system is configured to control how often TCP attempts to verify that an idle connection is still intact by sending a keep-alive packet.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2559-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-188</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="KeepAliveTime_var" export-name="oval:gov.nist.fdcc.xp:var:5"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:115"/>
                              </check>
                        </Rule>
                        <Rule id="NoDefaultExemptForIPSecFiltering" selected="false" weight="10.0">
                              <title>MSS: (NoDefaultExempt) Enable NoDefaultExempt for IPSec Filtering</title>
                              <description>Setting this to 1 removes exemptions for Kerberos and RSVP traffic, and keeps exemptions for multicast, broadcast, and ISAKMP.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3044-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-501</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:116"/>
                              </check>
                        </Rule>
                        <Rule id="DisableAutorunForAllDrives" selected="false" weight="10.0">
                              <title>MSS: (NoDriveTypeAutoRun) Disable Autorun for all drives</title>
                              <description>This check verifies that the system is configured to turn off the Autorun feature on all drives</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2710-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-44</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:117"/>
                              </check>
                        </Rule>
                        <Rule id="NameReleaseRequests" selected="false" weight="10.0">
                              <title>MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers</title>
                              <description>This check verifies that the system is configured to prevent release of its NetBIOS name when a name-release request is received.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3118-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-817</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="NameReleaseRequests_var" export-name="oval:gov.nist.fdcc.xp:var:291"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:118"/>
                              </check>
                        </Rule>
                        <Rule id="Disable8Dot3NameCreation" selected="false" weight="10.0">
                              <title>MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames</title>
                              <description>This check determines whether the system is allowed to generate 8.3 style filenames.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2683-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-511</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="Disable8Dot3NameCreation_var" export-name="oval:gov.nist.fdcc.xp:var:711"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:119"/>
                              </check>
                        </Rule>
                        <Rule id="RouterDiscovery" selected="false" weight="10.0">
                              <title>MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses</title>
                              <description>This check verifies that the system is configured to disable the Internet Router Discovery Protocol (IDRP), which could lead to a denial of service.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2652-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-952</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="RouterDiscovery_var" export-name="oval:gov.nist.fdcc.xp:var:286"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:121"/>
                              </check>
                        </Rule>
                        <Rule id="SafeDLLSearchMode" selected="false" weight="10.0">
                              <title>MSS: (SafeDllSearchMode) Enable Safe DLL search mode</title>
                              <description>The default search behavior, when an application calls a function in a Dynamic Link Library (DLL), is to search the current directory followed by the directories contained in the systems path environment variable. An unauthorized DLL inserted into an applications working directory could allow malicious code to be run on the system. Creating the SafeDllSearchMode registry key and setting the appropriate value forces the system to search the %Systemroot% for the DLL before searching the current directory or the rest of the path.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2841-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-271</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:122"/>
                              </check>
                        </Rule>
                        <Rule id="ScreenSaverGracePeriod" selected="false" weight="10.0">
                              <title>MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires</title>
                              <description>This check verifies that the system is configured to have password protection take effect immediately when the screen saver becomes active.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2980-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-830</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="ScreenSaverGracePeriod_var" export-name="oval:gov.nist.fdcc.xp:var:299"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:123"/>
                              </check>
                        </Rule>
                        <Rule id="SynAttackProtectionLevel" selected="false" weight="10.0">
                              <title>MSS: (SynAttackProtect) Syn attack protection level</title>
                              <description>This check verifies that the system is configured to protect against Syn attacks. The setting should be set to "Connections time out sooner if a SYN attack is detected."</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2916-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-284</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="SynAttackProtectionLevel_var" export-name="oval:gov.nist.fdcc.xp:var:288"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:124"/>
                              </check>
                        </Rule>
                        <Rule id="TCPConnectionResponses" selected="false" weight="10.0">
                              <title>MSS: (TCPMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged</title>
                              <description>This check verifies that the system is configured to control the maximum number of times that TCP retransmits a SYN before aborting the attempt.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2213-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-577</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:125"/>
                              </check>
                        </Rule>
                        <Rule id="TCPMaxDataRetransmissions" selected="false" weight="10.0">
                              <title>MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted</title>
                              <description>This check verifies that the system is configured to control the maximum number of times that TCP retransmits unacknowledged data segments before aborting the attempt.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2239-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-872</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="TCPMaxDataRetransmissions_var" export-name="oval:gov.nist.fdcc.xp:var:103"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:126"/>
                              </check>
                        </Rule>
                        <Rule id="EventLogThresholdWarning" selected="false" weight="10.0">
                              <title>MSS: (WarningLevel) percentage threshold for the security event log at which the system will generate a warning</title>
                              <description>This check verifies that the system is configured to generate a warning when the Security Event Log has reached a defined threshold. If the system is configured to write to an audit server, or is configured to automatically archive full logs, then this check does not apply.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3061-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-125</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="EventLogThresholdWarning_var" export-name="oval:gov.nist.fdcc.xp:var:91"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:127"/>
                              </check>
                        </Rule>
                        <Rule id="anonymous_sid_name_translation" selected="false" weight="10.0" role="unchecked">
                              <title>Network access: Allow anonymous SID-Name translation</title>
                              <description>Determines if an anonymous user can request security identifier (SID) attributes for another user or use a SID to get the corresponding username.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2973-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-953</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="anonymous_sid_name_translation_var" export-name="oval:gov.nist.fdcc.xp:var:77779"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:77"/>
                              </check>
                        </Rule>
                        <Rule id="AnonymousEnumerationOfAccounts" selected="false" weight="10.0">
                              <title>Network access: Do not allow anonymous enumeration of SAM accounts</title>
                              <description>If this setting is disabled, it allows anonymous logon users (null session connections) to list all account names, thus providing a map of potential points to attack the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2147-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-318</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:87"/>
                              </check>
                        </Rule>
                        <Rule id="AnonymousEnumerationOfAccountsAndShares" selected="false" weight="10.0">
                              <title>Network access: Do not allow anonymous enumeration of SAM accounts and shares</title>
                              <description>If this setting is disabled, it allows anonymous logon users (null session connections) to list all account names and enumerate all shared resources, thus providing a map of potential points to attack the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2804-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-195</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:88"/>
                              </check>
                        </Rule>
                        <Rule id="CredentialsStorage" selected="false" weight="10.0">
                              <title>Network access: Do not allow storage of credentials or .NET Passports for network authentication</title>
                              <description>This setting controls the storage of authentication credentials or .NET passports on the local system. Such credentials should never be stored on the local machine as that may lead to account compromise.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3088-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-542</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:89"/>
                              </check>
                        </Rule>
                        <Rule id="AnonymousUsersPermissions" selected="false" weight="10.0">
                              <title>Network access: Let Everyone permissions apply to anonymous users</title>
                              <description>This setting helps define the permissions that anonymous users have. If this setting is enabled then anonymous users have the same rights and permissions as the built-in Everyone group. Anonymous users should not have these permissions or rights.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3110-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-18</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:90"/>
                              </check>
                        </Rule>
                        <Rule id="AnonymouslyAccessedNamedPipes" selected="false" weight="10.0">
                              <title>Network access: Named Pipes that can be accessed anonymously</title>
                              <description>Network access: Named Pipes that can be accessed anonymously. Pipes are internal system communications processes. They are identified internally by ID numbers that vary between systems. To make access to these processes easier, these pipes are given names that do not vary between systems. This setting controls which of these pipes anonymous users may access.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3150-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-136</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:91"/>
                              </check>
                        </Rule>
                        <Rule id="RemotelyAccessibleRegistryPaths" selected="false" weight="10.0">
                              <title>Network access: Remotely accessible registry paths</title>
                              <description>Network access: Remotely accessible registry paths. This setting controls which registry paths are accessible from a remote computer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3155-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-189</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:92"/>
                              </check>
                        </Rule>
                        <Rule id="AnonymouslyAccessedShares" selected="false" weight="10.0">
                              <title>Network access: Shares that can be accessed anonymously</title>
                              <description>This setting controls which network shares may be accessed by an anonymous user. The default setting includes the shares, DFS$, and COMCFG. It is recommended that they be left as the default setting.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3036-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-942</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:93"/>
                              </check>
                        </Rule>
                        <Rule id="LocalAccountsSecurityModel" selected="false" weight="10.0">
                              <title>Network access: Sharing and security model for local accounts</title>
                              <description>Windows XP includes two network-sharing security models Classic and Guest only. It is recommended that the Classic mode be used.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3058-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-343</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:94"/>
                              </check>
                        </Rule>
                        <Rule id="LANManagerHashStorage" selected="false" weight="10.0">
                              <title>Network security: Do not store LAN Manager hash value on next password change</title>
                              <description>This setting controls whether or not a LAN Manager hash of the password is stored in the SAM the next time the password is changed. The LAN Manager hash is a weak encryption algorithm and there are several tools available that use this hash to retrieve account passwords.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2993-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-233</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:95"/>
                              </check>
                        </Rule>
                        <Rule id="ForceLogoff" selected="false" weight="10.0">
                              <title>Network security: Force logoff when logon hours expire</title>
                              <description>This setting controls whether or not users are forced to log off when their allowed logon hours expire. If logon hours are set for users, then this should be enforced.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3139-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-775</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:244"/>
                              </check>
                        </Rule>
                        <Rule id="LANManagerAuthenticationLevel-RefuseLM_NTLM" selected="false" weight="10.0">
                              <title>Network security: LAN Manager authentication level</title>
                              <description>The Kerberos v5 authentication protocol is the default for authentication of users who are logging on to domain accounts from computers that are running Windows. The Kerberos protocol is the protocol of choice in Windows systems, when there is a choice. The Windows NTLM protocol was the default for authentication in Microsoft Windows NT version 4.0. It is retained in Windows 2000 for compatibility with clients and servers that are running Windows NT version 4.0 and earlier. It is also used to authenticate logons to stand-alone computers that are running Windows 2000.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2926-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-719</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:96"/>
                              </check>
                        </Rule>
                        <Rule id="LDAPClientSigningRequirements" selected="false" weight="10.0">
                              <title>Network security: LDAP client signing requirements</title>
                              <description>This setting controls the signing requirements for LDAP clients. This setting should be set to Negotiate signing or Require signing depending on the environment and type of LDAP server in use.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2991-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-732</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:98"/>
                              </check>
                        </Rule>
                        <Rule id="ntlm_ssp_based_client_session_security" selected="false" weight="10.0">
                              <title>Network security: Minimum session security for NTLM SSP based (including secure RPC) clients</title>
                              <description>Starting with Windows 2000 Microsoft has implemented a variety of security support providers for use with RPC sessions. In a homogenous Windows XP environment, all of the options should be enabled and testing should be performed in a heterogeneous environment to determine the maximum-security level that provides reliable functionality.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3156-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-674</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="ntlm_ssp_based_client_session_security_var" export-name="oval:gov.nist.fdcc.xp:var:284"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:99"/>
                              </check>
                        </Rule>
                        <Rule id="ntlm_ssp_based_servers_session_security" selected="false" weight="10.0">
                              <title>Network security: Minimum session security for NTLM SSP based (including secure RPC) servers</title>
                              <description>Starting with Windows 2000 Microsoft has implemented a variety of security support providers for use with RPC sessions. In a homogenous Windows XP environment, all of the options should be enabled and testing should be performed in a heterogeneous environment to determine the maximum-security level that provides reliable functionality.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2799-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-766</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="ntlm_ssp_based_servers_session_security_var" export-name="oval:gov.nist.fdcc.xp:var:285"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:100"/>
                              </check>
                        </Rule>
                        <Rule id="RecoveryConsoleAutoLogon" selected="false" weight="10.0">
                              <title>Recovery console: Allow automatic administrative logon</title>
                              <description>If this option is enabled, the Recovery Console does not require you to provide a password and will automatically log on to the system, giving Administrator access to system files. By default, the Recovery Console requires you to provide the password for the Administrator account before accessing the system.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2935-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-410</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:101"/>
                              </check>
                        </Rule>
                        <Rule id="RecoveryConsoleFullSystemAccess" selected="false" weight="10.0">
                              <title>Recovery console: Allow floppy copy and access to all drives and all folders</title>
                              <description>Enabling this option enables the Recovery Console SET command, which allows you to set Recovery Console environment variables. This permits floppy copy and access to all drives and folders. It should be disabled.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2957-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-76</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:102"/>
                              </check>
                        </Rule>
                        <Rule id="shutdown_without_logon" selected="false" weight="10.0">
                              <title>Shutdown: Allow system to be shut down without having to log on</title>
                              <description>Displaying the shutdown button may allow individuals to shut down a system anonymously. Only authenticated users should be allowed to shut down the system. Preventing display of this button in the logon dialog box, ensures that individuals who shut down the system are authorized and tracked in the systems Security event log.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2983-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-224</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export value-id="shutdown_without_logon_var" export-name="oval:gov.nist.fdcc.xp:var:10311"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:103"/>
                              </check>
                        </Rule>
                        <Rule id="ClearPagefileOnShutdown" selected="false" weight="10.0">
                              <title>Shutdown: Clear virtual memory pagefile</title>
                              <description>Virtual memory support of Windows XP uses a system page file to swap blocks of memory not actively being used to disk. While Windows XP is running, this file is opened exclusively by the operating system, thus ensuring it is reasonably protected. However, the system page file should be wiped clean of all user data when the system shuts down. This ensures that sensitive information that may be in the page file is not available for retrieval by an anonymous user.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3128-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-422</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:104"/>
                              </check>
                        </Rule>
                        <Rule id="FIPSCompliantEncryption" selected="false" weight="10.0">
                              <title>System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing</title>
                              <description>This setting ensures that the system uses algorithms that are FIPS compliant for encryption, hashing, and signing. FIPS compliant algorithms meet specific standards established by the U.S. Government and should be the algorithms used for all OS encryption functions.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3084-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-55</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:105"/>
                              </check>
                        </Rule>
                        <Rule id="AdministratorsGroupObjectCreatorOwner" selected="false" weight="10.0">
                              <title>System objects: Default owner for objects created by members of the Administrators group</title>
                              <description>Either the object creator or the Administrators group owns objects created by members of the Administrators group. In order to ensure accurate auditing and proper accountability, the default owner should be the object creator.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2842-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-575</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:106"/>
                              </check>
                        </Rule>
                        <Rule id="RequireCaseInsensitivity" selected="false" weight="10.0">
                              <title>System objects: Require case insensitivity for non-Windows subsystems</title>
                              <description>This setting controls the behavior of non-Windows subsystems when dealing with the case of arguments or commands. Case sensitivity could lead to the access of files or commands that should be restricted. To prevent this from happening, case insensitivity should be required.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2987-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-300</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:107"/>
                              </check>
                        </Rule>
                        <Rule id="InternalSystemObjectsPermissions" selected="false" weight="10.0">
                              <title>System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)</title>
                              <description>System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links). Windows systems maintains an internal list of shared system resources such as DOS device names, mutexes, and semaphores. Each type of object is created with a default DACL that specifies who can access the objects with what permissions. If this policy is enabled, the default DACL is stronger, allowing non-admin users to read shared objects, but not modify shared objects that they did not create.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-3005-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-508</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:109"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               User Rights Assignments               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="user_rights_assignments">
                        <title>User Rights Assignment Settings</title>
                        <description>todo - description needed</description>
                        <Rule id="AccessComputerFromNetwork_Administrators" selected="false" weight="10.0">
                              <title>Right To Access This Computer From The Network</title>
                              <description>Verify that the user right 'Access This Computer From The Network' has been granted appropriately.  NOTE: This can break IPSec see Microsoft Knowledge Base article 823659 for further guidance</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <!--<reference href="http://support.microsoft.com/kb/823659">
                                    <dc:publisher>Microsoft Corp.</dc:publisher>
                                    <dc:identifier>KB823659</dc:identifier>
                              </reference>-->
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2379-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-532</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:161"/>
                              </check>
                        </Rule>
                        <Rule id="ActAsPartOfOperatingSystem_None" selected="false" weight="10.0">
                              <title>Right To Act As Part Of The Operating System</title>
                              <description>Verify that the user right 'Act As Part Of The Operating System' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2167-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-162</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:162"/>
                              </check>
                        </Rule>
                        <Rule id="AdjustMemoryQuotas_Administrators-LOCAL_SERVICE-NETWORK_SERVICE" selected="false" weight="10.0">
                              <title>Right To Adjust Memory Quotas For A Process</title>
                              <description>Verify that the user right 'Adjust Memory Quotas For A Process' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2547-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-807</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:164"/>
                              </check>
                        </Rule>
                        <Rule id="AllowLogOnThroughTerminalServices_Administrators-RemoteDesktopUsers" selected="false" weight="10.0">
                              <title>Right To Log On Through Terminal Services</title>
                              <description>Verify that the user right 'Allow Log On Through Terminal Services' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-3004-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-883</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:1662"/>
                              </check>
                        </Rule>
                        <Rule id="BackUpFilesAndDirectories_Administrators" selected="false" weight="10.0">
                              <title>Right To Back Up Files and Directories</title>
                              <description>Verify that the user right 'Back Up Files and Directories' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2299-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-931</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:167"/>
                              </check>
                        </Rule>
                        <Rule id="BypassTraverseChecking_Administrators_Users" selected="false" weight="10.0">
                              <title>Right To Bypass Traverse Checking</title>
                              <description>Verify that the user right 'Bypass Traverse Checking' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2806-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-376</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:168"/>
                              </check>
                        </Rule>
                        <Rule id="ChangeSystemTime_Administrators" selected="false" weight="10.0">
                              <title>Right To Change the System Time</title>
                              <description>Verify that the user right 'Change the System Time' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2846-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-799</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:169"/>
                              </check>
                        </Rule>
                        <Rule id="CreatePagefile_Administrators" selected="false" weight="10.0">
                              <title>Right To Create A Pagefile</title>
                              <description>Verify that the user right 'Create A Pagefile' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2786-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-895</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:170"/>
                              </check>
                        </Rule>
                        <Rule id="CreateTokenObject_None" selected="false" weight="10.0">
                              <title>Right To Create A Token Object</title>
                              <description>Verify that the user right 'Create A Token Object' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2791-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-926</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:171"/>
                              </check>
                        </Rule>
                        <Rule id="Create-Global-Objects_Administrators-SERVICE-LocalService-NetworkService" selected="false" weight="10.0">
                              <title>Right To Create Global Objects</title>
                              <description>Verify that the user right 'Create Global Objects' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-3107-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-383</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6626"/>
                              </check>
                        </Rule>
                        <Rule id="CreatePermanentSharedObjects_None" selected="false" weight="10.0">
                              <title>Right To Create Permanent Shared Objects</title>
                              <description>Verify that the user right 'Create Permanent Shared Objects' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-1969-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-335</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:172"/>
                              </check>
                        </Rule>
                        <Rule id="DebugPrograms_Administrators" selected="false" weight="10.0">
                              <title>Administrators Have Right To Debug Programs</title>
                              <description>Verify that the user right 'Debug Programs' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2864-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-842</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:174"/>
                              </check>
                        </Rule>
                        <Rule id="DenyAccessFromNetwork-Guests-SUPPORT_388945a0" selected="false" weight="10.0">
                              <title>Denied Access To This Computer From The Network</title>
                              <description>Verify that the user right 'Deny Access To This Computer From The Network' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-1978-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-898</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:175"/>
                              </check>
                        </Rule>
                        <Rule id="DenyLogonAsBatchJob-Guests-SUPPORT_388945a0" selected="false" weight="10.0">
                              <title>Denied Logon As A Batch Job</title>
                              <description>Verify that the user right 'Deny Logon As A Batch Job' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2898-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-165</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:176"/>
                              </check>
                        </Rule>
                        <Rule id="deny_logon_as_service_none" selected="false" weight="10.0">
                              <title>Denied Logon As A Service</title>
                              <description>Verify that the user right 'Deny Logon As A Service' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2792-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-597</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:677"/>
                              </check>
                        </Rule>
                        <Rule id="DenyLogonLocally-Guests-SUPPORT_388945a0" selected="false" weight="10.0">
                              <title>Denied Logon Locally</title>
                              <description>Verify that the user right 'Deny Logon Locally' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2700-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-64</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:177"/>
                              </check>
                        </Rule>
                        <Rule id="DenyLogonThroughTerminalServices-Guests" selected="false" weight="10.0">
                              <title>Denied Logon Through Terminal Services</title>
                              <description>Verify that the user right 'Deny Logon Through Terminal Services' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2814-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-108</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:1781"/>
                              </check>
                        </Rule>
                        <Rule id="ShutdownFromRemoteSystem_Administrators" selected="false" weight="10.0">
                              <title>Right To Force Shutdown From A Remote System</title>
                              <description>Verify that the user right 'Force Shutdown From A Remote System' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2886-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-754</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:180"/>
                              </check>
                        </Rule>
                        <Rule id="GenerateSecurityAudits-LOCAL_SERVICE-NETWORK_SERVICE" selected="false" weight="10.0">
                              <title>Right To Generate Security Audits</title>
                              <description>Verify that the user right 'Generate Security Audits' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2767-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-939</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:181"/>
                              </check>
                        </Rule>
                        <Rule id="ImpersonateClientAfterAuthentication-SERVICE_Administrators" selected="false" weight="10.0">
                              <title>Impersonate a Client After Authentication</title>
                              <description>Verify that the user right 'Impersonate a Client After Authentication' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2737-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-304</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6640"/>
                              </check>
                        </Rule>
                        <Rule id="IncreaseSchedulingPriority_Administrators" selected="false" weight="10.0">
                              <title>Right To Increase Scheduling Priority</title>
                              <description>Verify that the user right 'Increase Scheduling Priority' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2944-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-349</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:182"/>
                              </check>
                        </Rule>
                        <Rule id="LoadAndUnloadDeviceDrivers_Administrators" selected="false" weight="10.0">
                              <title>Right To Load And Unload Device Drivers</title>
                              <description>Verify that the user right 'Load And Unload Device Drivers' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2446-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-860</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:183"/>
                              </check>
                        </Rule>
                        <Rule id="LockPagesInMemory_None" selected="false" weight="10.0">
                              <title>Right To Lock Pages In Memory</title>
                              <description>Verify that the user right 'Lock Pages In Memory' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2609-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-749</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:184"/>
                              </check>
                        </Rule>
                        <Rule id="LogOnAsBatchJob_None" selected="false" weight="10.0">
                              <title>Right To Log On As A Batch Job</title>
                              <description>Verify that the user right 'Log On As A Batch Job' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2882-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-177</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:185"/>
                              </check>
                        </Rule>
                        <Rule id="LogOnAsService-LOGON_SERVICE-NETWORK_SERVICE" selected="false" weight="10.0">
                              <title>Right To Log On As A Service</title>
                              <description>Verify that the user right 'Log On As A Service' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2948-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-216</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:186"/>
                              </check>
                        </Rule>
                        <Rule id="LogOnLocally_Administrators_Users" selected="false" weight="10.0">
                              <title>Log On Locally</title>
                              <description>Verify that the user right 'Log On Locally' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2829-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-965</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:165"/>
                              </check>
                        </Rule>
                        <Rule id="ManageAuditingAndSecurityLog_Administrators" selected="false" weight="10.0">
                              <title>Right To Manage Auditing And Security Log</title>
                              <description>Verify that the user right 'Manage Auditing And Security Log' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2247-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-850</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:187"/>
                              </check>
                        </Rule>
                        <Rule id="ModifyFirmwareEnvironmentValues_Administrators" selected="false" weight="10.0">
                              <title>Right To Modify Firmware Environment Values</title>
                              <description>Verify that the user right 'Modify Firmware Environment Values' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2657-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-17</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:188"/>
                              </check>
                        </Rule>
                        <Rule id="PerformVolumeMaintenanceTasks_Administrators" selected="false" weight="10.0">
                              <title>Right To Perform Volume Maintenance Tasks</title>
                              <description>Verify that the user right 'Perform Volume Maintenance Tasks' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2960-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-314</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:189"/>
                              </check>
                        </Rule>
                        <Rule id="ProfileSingleProcess_Administrators" selected="false" weight="10.0">
                              <title>Right To Profile Single Process</title>
                              <description>Verify that the user right 'Profile Single Process' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2807-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-260</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:190"/>
                              </check>
                        </Rule>
                        <Rule id="ProfileSystemPerformance_Administrators" selected="false" weight="10.0">
                              <title>Right To Profile System Performance</title>
                              <description>Verify that the user right 'Profile System Performance' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2675-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-599</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:191"/>
                              </check>
                        </Rule>
                        <Rule id="RemoveComputerFromDockingStation_Administrators_Users" selected="false" weight="10.0">
                              <title>Right To Remove Computer From Docking Station</title>
                              <description>Verify that the user right 'Remove Computer From Docking Station' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2335-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-656</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:192"/>
                              </check>
                        </Rule>
                        <Rule id="ReplaceProcessLevelToken-LOGON_SERVICE-NETWORK_SERVICE" selected="false" weight="10.0">
                              <title>Right To Replace A Process Level Token</title>
                              <description>Verify that the user right 'Replace A Process Level Token' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2860-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-667</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:193"/>
                              </check>
                        </Rule>
                        <Rule id="RestoreFilesAndDirectories_Administrators" selected="false" weight="10.0">
                              <title>Right To Restore Files And Directories</title>
                              <description>Verify that the user right 'Restore Files And Directories' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2847-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-553</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:194"/>
                              </check>
                        </Rule>
                        <Rule id="ShutDownSystem_Administrators_Users" selected="false" weight="10.0">
                              <title>Right To Shut Down The System</title>
                              <description>Verify that the user right 'Shut Down The System' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2366-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-839</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:195"/>
                              </check>
                        </Rule>
                        <Rule id="SynchronizeDirectoryServiceData_None" selected="false" weight="10.0">
                              <title>Right To Synchronize Directory Service Data</title>
                              <description>Verify that the user right 'Synchronize Directory Service Data' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2810-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-381</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:238"/>
                              </check>
                        </Rule>
                        <Rule id="TakeOwnershipOfFiles_Administrators" selected="false" weight="10.0">
                              <title>Right To Take Ownership Of Files Or Other Objects</title>
                              <description>Verify that the user right 'Take Ownership Of Files Or Other Objects' has been granted appropriately.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <ident system="http://cce.mitre.org">CCE-2021-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-492</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:196"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  System Services Group                                                                     -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="system_services_group">
                  <title>System Services Group</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              System Services Settings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="system_services_settings">
                        <title>System Services Settings</title>
                        <description>todo - description needed</description>
                        <Value id="AlerterService_var" operator="equals" type="number">
                              <title>Alerter Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="BITSService_var" operator="equals" type="number">
                              <title>Background Intelligent Transfer Service</title>
                              <description>Transfers files in the background using idle network bandwidth. If the service is disabled, then any applications that depend on BITS, such as Windows Update or MSN Explorer, will be unable to automatically download programs and other information. Impact: Windows Update</description>
                              <value>3</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="ClipBookService_var" operator="equals" type="number">
                              <title>ClipBook Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="ComputerBrowserService_var" operator="equals" type="number">
                              <title>Computer Browser Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="ErrorReportingService_var" operator="equals" type="number">
                              <title>Error Reporting Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="FastUserSwitchingCompatibilityService_var" operator="equals" type="number">
                              <title>Fast User Switching Compatibility Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="FaxService_var" operator="equals" type="number">
                              <title>Fax Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="FTPPublishingService_var" operator="equals" type="number">
                              <title>FTP Publishing Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="IndexingService_var" operator="equals" type="number">
                              <title>Indexing Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="MessengerService_var" operator="equals" type="number">
                              <title>Messenger Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="NetMeetingRemoteDesktopSharingService_var" operator="equals" type="number">
                              <title>NetMeeting Remote Desktop SharingService</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="NetworkDDEService_var" operator="equals" type="number">
                              <title>Network DDE Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="NetworkDDEdsdmService_var" operator="equals" type="number">
                              <title>Network DDE dsdm Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="RasManService_var" operator="equals" type="number">
                              <title>RasMan Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="RoutingAndRemoteAccessService_var" operator="equals" type="number">
                              <title>Routing And Remote Access Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="SSDPService_var" operator="equals" type="number">
                              <title>SSDP Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="TaskSchedulerService_var" operator="equals" type="number">
                              <title>Task Scheduler Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="TelnetService_var" operator="equals" type="number">
                              <title>Telnet Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="TerminalServicesService_var" operator="equals" type="number">
                              <title>Terminal Services Service</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="UniversalPlugAndPlayDeviceHostService_var" operator="equals" type="number">
                              <title>Universal Plug And Play Device Host Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="WebClientService_var" operator="equals" type="number">
                              <title>WebClient Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="Wireless-Zero-Configuration_var" operator="equals" type="number">
                              <title>Wireless Zero Configuration</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="WMIPerformanceAdapter_var" operator="equals" type="number">
                              <title>WMI Performance Adapter</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Value id="WWWPublishingServicesService_var" operator="equals" type="number">
                              <title>WWW Publishing Services Service</title>
                              <description>todo - description needed</description>
                              <value>4</value>
                              <value selector="automatic">2</value>
                              <value selector="manual">3</value>
                              <value selector="disabled">4</value>
                        </Value>
                        <Rule id="AlerterService" selected="false" weight="10.0">
                              <title>Alerter Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3034-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-487</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7771" value-id="AlerterService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:209"/>
                              </check>
                        </Rule>
                        <Rule id="BITSService" selected="false" weight="10.0">
                              <title>Background Intelligent Transfer Service</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2818-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-148</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:613221" value-id="BITSService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6132"/>
                              </check>
                        </Rule>
                        <Rule id="ClipBookService" selected="false" weight="10.0">
                              <title>ClipBook Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2713-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-954</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7773" value-id="ClipBookService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:210"/>
                              </check>
                        </Rule>
                        <Rule id="ComputerBrowserService" selected="false" weight="10.0">
                              <title>Computer Browser Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2880-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-294</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7774" value-id="ComputerBrowserService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:211"/>
                              </check>
                        </Rule>
                        <Rule id="ErrorReportingService" selected="false" weight="10.0">
                              <title>Error Reporting Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3236-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-774</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7775" value-id="ErrorReportingService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:2111"/>
                              </check>
                        </Rule>
                        <Rule id="FastUserSwitchingCompatibilityService" selected="false" weight="10.0">
                              <title>Fast User Switching Compatibility Service</title>
                              <description>todo - description needed</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2950-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-800</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7776" value-id="FastUserSwitchingCompatibilityService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:2121"/>
                              </check>
                        </Rule>
                        <Rule id="FaxService" selected="false" weight="10.0">
                              <title>Fax Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2849-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-78</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7777" value-id="FaxService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:212"/>
                              </check>
                        </Rule>
                        <Rule id="FTPPublishingService" selected="false" weight="10.0">
                              <title>FTP Publishing Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2888-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-712</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7778" value-id="FTPPublishingService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:213"/>
                              </check>
                        </Rule>
                        <Rule id="IndexingService" selected="false" weight="10.0">
                              <title>Indexing Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2910-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-738</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7779" value-id="IndexingService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:215"/>
                              </check>
                        </Rule>
                        <Rule id="MessengerService" selected="false" weight="10.0">
                              <title>Messenger Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2915-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-729</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7780" value-id="MessengerService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:216"/>
                              </check>
                        </Rule>
                        <Rule id="NetMeetingRemoteDesktopSharingService" selected="false" weight="10.0">
                              <title>NetMeeting Remote Desktop Sharing Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2896-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-232</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7781" value-id="NetMeetingRemoteDesktopSharingService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:217"/>
                              </check>
                        </Rule>
                        <Rule id="NetworkDDEService" selected="false" weight="10.0">
                              <title>Network Dynamic Data Exchange (DDE) Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3131-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-217</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7782" value-id="NetworkDDEService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:245"/>
                              </check>
                        </Rule>
                        <Rule id="NetworkDDEdsdmService" selected="false" weight="10.0">
                              <title>Network DDE Share Database Manager (DSDM) Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3122-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-768</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7783" value-id="NetworkDDEdsdmService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:246"/>
                              </check>
                        </Rule>
                        <Rule id="RasManService" selected="false" weight="10.0">
                              <title>Remote Access Connection Manager Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3104-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-750</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7784" value-id="RasManService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:247"/>
                              </check>
                        </Rule>
                        <Rule id="RoutingAndRemoteAccessService" selected="false" weight="10.0">
                              <title>Routing And Remote Access Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3035-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-223</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7785" value-id="RoutingAndRemoteAccessService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:219"/>
                              </check>
                        </Rule>
                        <Rule id="SSDPService" selected="false" weight="10.0">
                              <title>Simple Service Discovery Protocol (SSDP) Discovery Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2661-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-940</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7786" value-id="SSDPService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:223"/>
                              </check>
                        </Rule>
                        <Rule id="TaskSchedulerService" selected="false" weight="10.0">
                              <title>Task Scheduler Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2934-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-40</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7787" value-id="TaskSchedulerService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:224"/>
                              </check>
                        </Rule>
                        <Rule id="TelnetService" selected="false" weight="10.0">
                              <title>Telnet Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2326-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-75</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7789" value-id="TelnetService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:225"/>
                              </check>
                        </Rule>
                        <Rule id="TerminalServicesService" selected="false" weight="10.0">
                              <title>Terminal Services Service</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3043-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-974</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:22611" value-id="TerminalServicesService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:226"/>
                              </check>
                        </Rule>
                        <Rule id="UniversalPlugAndPlayDeviceHostService" selected="false" weight="10.0">
                              <title>Universal Plug And Play Device Host Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3048-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-608</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7791" value-id="UniversalPlugAndPlayDeviceHostService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:227"/>
                              </check>
                        </Rule>
                        <Rule id="WebClientService" selected="false" weight="10.0">
                              <title>WebClient Service</title>
                              <description>todo - description needed</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3291-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-305</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7792" value-id="WebClientService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:2271"/>
                              </check>
                        </Rule>
                        <Rule id="Wireless-Zero-Configuration" selected="false" weight="10.0">
                              <title>Wireless Zero Configuration</title>
                              <description>Disabling the setting will prevent all wireless Wi-Fi interface from working unless a third party management software is used to manage the device. This will not be an issue on managed desktops but will impact mobile device.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2494-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-604</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:28812" value-id="Wireless-Zero-Configuration_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:2881"/>
                              </check>
                        </Rule>
                        <Rule id="WMIPerformanceAdapter" selected="false" weight="10.0">
                              <title>WMI Performance Adapter</title>
                              <description>WMI Performance Adapter</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3265-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-745</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6719" value-id="WMIPerformanceAdapter_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6719"/>
                              </check>
                        </Rule>
                        <Rule id="WWWPublishingServicesService" selected="false" weight="10.0">
                              <title>World Wide Web Publishing Services Service Disabled</title>
                              <description>Unnecessary services should not be running on the system. Services typically run under the local System Account, which generally have more permissions than are required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Windows Settings\Security Settings\System Services</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2942-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-758</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:7795" value-id="WWWPublishingServicesService_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:228"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  6 - FDCC Other Settings                                                                     *** -->
      <!-- **************************************************************************************************** -->
      <Group id="fdcc_other_settings">
            <title>FDCC Other Settings</title>
            <description>FDCC has identified the following additional controls that must be checked in order to verify compliance.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Network Group                                                                             -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="network_group">
                  <title>Computer Configuration - Administrative Templates - Network Settings</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--     Microsoft Peer-to-Peer Networking Services      -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="microsoft_peer_to_peer_networking_services_settings">
                        <title>Microsoft Peer-to-Peer Networking Services</title>
                        <description>todo - description needed</description>
                        <Value id="turn_off_microsoft_peer_to_peer_networking_services_var" operator="equals" type="boolean">
                              <title>Turn Off Microsoft Peer-to-Peer Networking Services</title>
                              <description>This setting turns off Microsoft Peer-to-Peer Networking Services. (Enabled=1; Disabled=0; Not Configured)</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_microsoft_peer_to_peer_networking_services" selected="false" weight="10.0">
                              <title>Turn Off Microsoft Peer-to-Peer Networking Services</title>
                              <description>This setting turns off Microsoft Peer-to-Peer Networking Services in its entirety, and will cause all dependent applications to stop working.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Microsoft Peer-to-Peer Networking Services</dc:source>
                              </reference>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-5194-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-86</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6662" value-id="turn_off_microsoft_peer_to_peer_networking_services_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6662"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Network Connection Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="network_connection_settings">
                        <title>Network Connection Settings</title>
                        <description>The features for implementing and administering small networks are described as follows:<xhtml:p/>-- Internet Connection Sharing (ICS) --<xhtml:p/>ICS provides Internet access for a home or small office network by using one common connection as the Internet gateway. The ICS host is the only computer that is directly connected to the Internet. Multiple ICS clients simultaneously use the common Internet connection and benefit from Internet services as if the clients were directly connected to the Internet service provider (ISP). Security is enhanced when ICS is enabled because only the ICS host computer is visible to the Internet. The addresses of ICS clients are hidden from the Internet rendering ICS clients invisible to the Internet. In addition, ICS simplifies the configuration of small networks by providing local private network services, such as name resolution and addressing.<xhtml:p/>Note: You should not use Internet Connection Sharing in an
                              existing network with Windows 2000 Server domain controllers, Domain Name System (DNS) servers, gateways, Dynamic Host Configuration Protocol (DHCP) servers, or systems configured for static IP addresses.<xhtml:p/>-- Internet Connection Firewall (ICF) --<xhtml:p/>With ICF, the firewall checks all communications that cross the connection between your network and the Internet and is selective about which responses from the Internet it allows. ICF protects only the computer on which it is enabled. If ICF is enabled on the Internet Connection Sharing (ICS) host computer, however, ICS clients that use the shared Internet connection for Internet connectivity are protected because they cannot be seen from outside your network. For this reason, you should always enable ICF on the ICS host computer. In addition, if there are clients on your network with direct Internet connections, or if you have a stand-alone computer that is connected to the Internet, then you
                              should enable ICF on those Internet connections as well.<xhtml:p/>-- Network Bridge --<xhtml:p/>Network Bridge removes the need for routing and bridging hardware in a home or small office network that consists of multiple LAN segments. With Network Bridge, multiple LAN segments become a single IP subnet, even if the LAN segments are of mixed network media types. Network Bridge automates the configuration and management of the address allocation, routing, and name resolution that is typically required in a network that consists of multiple LAN segments.<xhtml:p/>Caution If neither ICF nor ICS is enabled on your network, do not set up Network Bridge between the public Internet connection and the private network connection. Setting up Network Bridge between the public Internet connection and the private network connection creates an unprotected link between your network and the Internet, leaving your network vulnerable to external attacks. When either ICF or
                              ICS is enabled, this risk is mitigated.</description>
                        <Value id="prohibit_installation_network_bridge_var" operator="equals" type="number">
                              <title>Prohibit installation and configuration of Network Bridge on your DNS domain network</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Value id="prohibit_internet_connection_firewall_var" operator="equals" type="number">
                              <title>Prohibit use of Internet Connection Firewall on your DNS domain network</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Value id="prohibit_internet_connection_sharing_var" operator="equals" type="number">
                              <title>Prohibit use of Internet Connection Sharing on your DNS domain network</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Rule id="prohibit_installation_network_bridge" selected="false" weight="10.0">
                              <title>Prohibit installation and configuration of Network Bridge on your DNS domain network</title>
                              <description>Installation and Configuration of Network Bridge on the DNS Domain Network should be properly configured.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections</dc:source>
                              </reference>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-2173-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-896</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:3366991" value-id="prohibit_installation_network_bridge_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:3366991"/>
                              </check>
                        </Rule>
                        <Rule id="prohibit_internet_connection_firewall" selected="false" weight="10.0">
                              <title>Prohibit use of Internet Connection Firewall on your DNS domain network</title>
                              <description>The "Prohibit use of Internet Connection Firewall on your DNS domain network" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections</dc:source>
                              </reference>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-5022-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-241</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:3366992" value-id="prohibit_internet_connection_firewall_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:3366992"/>
                              </check>
                        </Rule>
                        <Rule id="prohibit_internet_connection_sharing" selected="false" weight="10.0">
                              <title>Prohibit use of Internet Connection Sharing on your DNS domain network</title>
                              <description>The "Prohibit use of Internet Connection Sharing on your DNS domain network" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections</dc:source>
                              </reference>
                              <requires idref="CM-7"/>
                              <ident system="http://cce.mitre.org">CCE-3026-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-672</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:3366993" value-id="prohibit_internet_connection_sharing_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:3366993"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  System Group                                                                              -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="system_group">
                  <title>Computer Configuration - Administrative Templates - System Settings</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--              Error Reporting Settings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="error_reporting_settings">
                        <title>Local Computer - Administrative Templates - System Settings - Error Reporting</title>
                        <description>todo - description needed</description>
                        <Value id="display_error_notification_var" operator="equals" type="number">
                              <title>Display Error Notification</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">1</value>
                              <value selector="enabled">0</value>
                        </Value>
                        <Rule id="display_error_notification" selected="false" weight="10.0">
                              <title>Display Error Notification</title>
                              <description>The "Display Error Notification" setting should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Error Reporting</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5136-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-259</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:3366994" value-id="display_error_notification_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:3366994"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Group Policy Settings                -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="group_policy_settings">
                        <title>Local Computer - Administrative Templates - System Settings - Group Policy</title>
                        <description>todo - description needed</description>
                        <Value id="registry_policy_processing_var" operator="equals" type="number">
                              <title>Registry Policy Processing</title>
                              <description>Computer Configuration\Administrative Templates\System: Group Policy - Registry Policy Processing. (Enabled = 0; Disabled = 1)</description>
                              <value>0</value>
                              <value selector="not_configured">-1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled:nobackgroundpolicy">1</value>
                              <value selector="enabled:nogpolistchanges">2</value>
                              <value selector="enabled:nobackgroundpolicy_and_nogpolistchanges">3</value>
                        </Value>
                        <Value id="NoSlowLink_var" operator="equals" type="number">
                              <title>Registry Policy Processing</title>
                              <description>todo</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="NoBackgroundPolicy_var" operator="equals" type="number">
                              <title>Registry Policy Processing</title>
                              <description>todo</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="NoGPOListChanges_var" operator="equals" type="number">
                              <title>Registry Policy Processing</title>
                              <description>todo</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="internet_explorer_maintenance_policy_processing_enabled" selected="false" weight="10.0" role="unchecked">
                              <title>Internet Explorer Maintenance Policy Processing</title>
                              <description>Computer Configuration\Administrative Templates\System: Group Policy - Internet Explorer Maintenance Policy Processing.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Group Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4665-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-365</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:66711" value-id="NoSlowLink_var"/>
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:66712" value-id="NoBackgroundPolicy_var"/>
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:66713" value-id="NoGPOListChanges_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6671"/>
                              </check>
                        </Rule>
                        <Rule id="registry_policy_processing" selected="false" weight="10.0">
                              <title>Registry Policy Processing</title>
                              <description>Computer Configuration\Administrative Templates\System: Group Policy - Registry Policy Processing.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Group Policy</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5053-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-584</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6672" value-id="registry_policy_processing_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6672"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--          Internet Communication Settings           -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="internet_communication_settings">
                        <title>Computer_Configuration - Administrative_Templates - System: Internet Communication Management - Internet Communication settings</title>
                        <description>todo - description needed</description>
                        <Value id="Turn-Off-Automatic-Root-Certificates-Update_var" operator="equals" type="string">
                              <title>Turn Off Automatic Root Certificates Update</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Automatic Root Certificates Update.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-downloading-of-print-drivers-over-HTTP_var" operator="equals" type="string">
                              <title>Turn off downloading of print drivers over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off downloading of print drivers over HTTP.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Event-Views-Events.asp-Links_var" operator="equals" type="string">
                              <title>Turn Off Event Views "Events.asp" Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Event Views "Events.asp" Links.</description>
                              <value>Disabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Internet-Connection-Wizard-if-URL-Connection-is-Referring-to-Microsoft.com_var" operator="equals" type="string">
                              <title>Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards_var" operator="equals" type="string">
                              <title>Turn off Internet download for Web publishing and online ordering wizards</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Internet download for Web publishing and online ordering wizards.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Internet-File-Association-Service_var" operator="equals" type="string">
                              <title>Turn Off Internet File Association Service</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet File Association Service.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-printing-over-HTTP_var" operator="equals" type="string">
                              <title>Turn off printing over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off printing over HTTP.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com_var" operator="equals" type="string">
                              <title>Turn Off Registration if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Registration if URL Connection is Referring to Microsoft.com.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-Search-Companion-content-file-updates_var" operator="equals" type="string">
                              <title>Turn off Search Companion content file updates</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Search Companion content file updates.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-the-Order-Prints-Picture-Task_var" operator="equals" type="string">
                              <title>Turn Off the "Order Prints" Picture Task</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off the "Order Prints" Picture Task.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-the-Publish-to-Web-task-for-files-and-folders_var" operator="equals" type="string">
                              <title>Turn off the "Publish to Web" task for files and folders</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the "Publish to Web" task for files and folders.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program_var" operator="equals" type="string">
                              <title>Turn off the Windows Messenger Customer Experience Improvement Program</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the Windows Messenger Customer Experience Improvement Program.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_off_windows_error_reporting_var" operator="equals" type="string">
                              <title>Turn Off Windows Error Reporting</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Error Reporting.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads_var" operator="equals" type="string">
                              <title>Turn Off Windows Movies Maker Automatic Codec Downloads</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movies Maker Automatic Codec Downloads.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-Off-Windows-Movie-Maker-Online-Web-Links_var" operator="equals" type="string">
                              <title>Turn Off Windows Movie Maker Online Web Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Online Web Links.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="turn_off_windows_movie_maker_saving_to_online_video_hosting_provider_var" operator="equals" type="string">
                              <title>Turn Off Windows Movie Maker Saving to Online Video Hosting Provider</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Saving to Online Video Hosting Provider.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Turn-off-Windows-Update-device-driver-searching_var" operator="equals" type="string">
                              <title>Turn off Windows Update device driver searching</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Windows Update device driver searching.</description>
                              <value>Disabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="Turn-Off-Automatic-Root-Certificates-Update" selected="false" weight="10.0">
                              <title>Turn Off Automatic Root Certificates Update</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Automatic Root Certificates Update.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5054-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-858</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6674" value-id="Turn-Off-Automatic-Root-Certificates-Update_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6674"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-downloading-of-print-drivers-over-HTTP" selected="false" weight="10.0">
                              <title>Turn off downloading of print drivers over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off downloading of print drivers over HTTP.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5200-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-887</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6572" value-id="Turn-off-downloading-of-print-drivers-over-HTTP_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6572"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Event-Views-Events.asp-Links" selected="false" weight="10.0">
                              <title>Turn Off Event Views "Events.asp" Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Event Views "Events.asp" Links.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4953-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-263</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6675" value-id="Turn-Off-Event-Views-Events.asp-Links_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6675"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Internet-Connection-Wizard-if-URL-Connection-is-Referring-to-Microsoft.com" selected="false" weight="10.0">
                              <title>Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet Connection Wizard if URL Connection is Referring to Microsoft.com.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4707-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1055</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6679" value-id="Turn-Off-Internet-Connection-Wizard-if-URL-Connection-is-Referring-to-Microsoft.com_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6679"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards" selected="false" weight="10.0">
                              <title>Turn off Internet download for Web publishing and online ordering wizards</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Internet download for Web publishing and online ordering wizards.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5099-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-691</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6568" value-id="Turn-off-Internet-download-for-Web-publishing-and-online-ordering-wizards_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6568"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Internet-File-Association-Service" selected="false" weight="10.0">
                              <title>Turn Off Internet File Association Service</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Internet File Association Service.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5121-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1064</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6680" value-id="Turn-Off-Internet-File-Association-Service_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6680"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-printing-over-HTTP" selected="false" weight="10.0">
                              <title>Turn off printing over HTTP</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off printing over HTTP.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4513-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-852</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6571" value-id="Turn-off-printing-over-HTTP_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6571"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com" selected="false" weight="10.0">
                              <title>Turn Off Registration if URL Connection is Referring to Microsoft.com</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Registration if URL Connection is Referring to Microsoft.com.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4641-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-88</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6681" value-id="Turn-Off-Registration-if-URL-Connection-is-Referring-to-Microsoft.com_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6681"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-Search-Companion-content-file-updates" selected="false" weight="10.0">
                              <title>Turn off Search Companion content file updates</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Search Companion content file updates.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5055-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-818</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6570" value-id="Turn-off-Search-Companion-content-file-updates_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6570"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-the-Order-Prints-Picture-Task" selected="false" weight="10.0">
                              <title>Turn Off the "Order Prints" Picture Task</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off the "Order Prints" Picture Task.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5072-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-375</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6682" value-id="Turn-Off-the-Order-Prints-Picture-Task_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6682"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-the-Publish-to-Web-task-for-files-and-folders" selected="false" weight="10.0">
                              <title>Turn off the "Publish to Web" task for files and folders</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the "Publish to Web" task for files and folders.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4887-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1009</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6567" value-id="Turn-off-the-Publish-to-Web-task-for-files-and-folders_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6567"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program" selected="false" weight="10.0">
                              <title>Turn off the Windows Messenger Customer Experience Improvement Program</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off the Windows Messenger Customer Experience Improvement Program.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4224-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-722</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6569" value-id="Turn-off-the-Windows-Messenger-Customer-Experience-Improvement-Program_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6569"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_windows_error_reporting" selected="false" weight="10.0">
                              <title>Turn Off Windows Error Reporting</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Error Reporting.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3038-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-592</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6683" value-id="turn_off_windows_error_reporting_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6683"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads" selected="false" weight="10.0">
                              <title>Turn Off Windows Movies Maker Automatic Codec Downloads</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movies Maker Automatic Codec Downloads.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4242-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1040</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6696" value-id="Turn-Off-Windows-Movies-Maker-Automatic-Codec-Downloads_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6696"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-Off-Windows-Movie-Maker-Online-Web-Links" selected="false" weight="10.0">
                              <title>Turn Off Windows Movie Maker Online Web Links</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Online Web Links.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4732-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1062</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6684" value-id="Turn-Off-Windows-Movie-Maker-Online-Web-Links_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6684"/>
                              </check>
                        </Rule>
                        <Rule id="turn_off_windows_movie_maker_saving_to_online_video_hosting_provider" selected="false" weight="10.0">
                              <title>Turn Off Windows Movie Maker Saving to Online Video Hosting Provider</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn Off Windows Movie Maker Saving to Online Video Hosting Provider.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4997-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-93</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6697" value-id="turn_off_windows_movie_maker_saving_to_online_video_hosting_provider_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6697"/>
                              </check>
                        </Rule>
                        <Rule id="Turn-off-Windows-Update-device-driver-searching" selected="false" weight="10.0">
                              <title>Turn off Windows Update device driver searching</title>
                              <description>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings: Turn off Windows Update device driver searching.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5014-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-927</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6573" value-id="Turn-off-Windows-Update-device-driver-searching_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6573"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                   Logon Settings                    -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="logon_settings">
                        <title>Computer_Configuration - Administrative_Templates - System - Logon</title>
                        <description>todo - description needed</description>
                        <Value id="Always-Use-Classic-Logon_var" operator="equals" type="string">
                              <title>Always Use Classic Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Always Use Classic Logon.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Do-Not-Process-Run-Once-List_var" operator="equals" type="string">
                              <title>Do not process the run once list</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Do not process the run once list.</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon_var" operator="equals" type="string">
                              <title>Don’t Display the Getting Started Welcome Screen at Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Don’t Display the Getting Started Welcome Screen at Logon.</description>
                              <value>Enabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="Always-Use-Classic-Logon" selected="false" weight="10.0">
                              <title>Always Use Classic Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Always Use Classic Logon.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Logon</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3100-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-231</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6686" value-id="Always-Use-Classic-Logon_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6686"/>
                              </check>
                        </Rule>
                        <Rule id="Do-Not-Process-Run-Once-List" selected="false" weight="10.0">
                              <title>Do not process the run once list</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Do not process the run once list.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Logon</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5032-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-583</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6561" value-id="Do-Not-Process-Run-Once-List_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6561"/>
                              </check>
                        </Rule>
                        <Rule id="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon" selected="false" weight="10.0">
                              <title>Don’t Display the Getting Started Welcome Screen at Logon</title>
                              <description>Computer Configuration\Administrative Templates\System: Logon - Don’t Display the Getting Started Welcome Screen at Logon.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Logon</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5160-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1020</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6687" value-id="Do-Not-Display-the-Getting-Started-Welcome-Screen-at-Logon_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6687"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Remote Assistance Settings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="remote_assistance_settings">
                        <title>Computer_Configuration - Administrative_Templates - System: Remote Assistance</title>
                        <description>todo - description needed</description>
                        <Value id="offer_remote_assistance_var" operator="equals" type="string">
                              <title>Offer Remote Assistance</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - Offer Remote Assistance.</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="solicited_remote_assistance_var" operator="equals" type="string">
                              <title>Solicited Remote Assistance</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - Solicited Remote Assistance.</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="SSLF-MS-Laptop">Disabled</value>
                              <value selector="SSLF-MS-Desktop">Disabled</value>
                              <value selector="SSLF-rev2-Laptop">Disabled</value>
                              <value selector="SSLF-rev2-Desktop">Disabled</value>
                              <value selector="FDCC-Laptop">Disabled</value>
                              <value selector="FDCC-Desktop">Disabled</value>
                        </Value>
                        <Rule id="offer_remote_assistance" selected="false" weight="10.0">
                              <title>Offer Remote Assistance</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - Offer Remote Assistance.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Assistance</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3012-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-434</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6563" value-id="offer_remote_assistance_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6563"/>
                              </check>
                        </Rule>
                        <Rule id="solicited_remote_assistance" selected="false" weight="10.0">
                              <title>Solicited Remote Assistance</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - Solicited Remote Assistance.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Assistance</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-3007-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-859</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6564" value-id="solicited_remote_assistance_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6564"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Remote Procedure Call Settings            -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="remote_procedure_call_settings">
                        <title>Computer_Configuration - Administrative_Templates - System: Remote Procedure Call</title>
                        <description>todo - description needed</description>
                        <Value id="Restrictions-for-Unauthenticated-RPC-clients_var" operator="greater than or equal" type="number">
                              <title>Restrictions for Unauthenticated RPC clients</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - Restrictions for Unauthenticated RPC clients. (Enabled: Authenticated = 1)</description>
                              <value>1</value>
                              <value selector="enabled:none">0</value>
                              <value selector="enabled:authenticated">1</value>
                              <value selector="enabled:authenticate_without_excpetions">2</value>
                        </Value>
                        <Value id="rpc_endpoint_mapper_client_authentication_var" operator="equals" type="string">
                              <title>RPC Endpoint Mapper Client Authentication</title>
                              <description>Computer Configuration\Administrative Templates\System: Remote Assistance - RPC Endpoint Mapper Client Authentication.</description>
                              <value>Disabled</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="Restrictions-for-Unauthenticated-RPC-clients" selected="false" weight="10.0">
                              <title>Restrictions for Unauthenticated RPC clients</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - Restrictions for Unauthenticated RPC clients.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Procedure Call</dc:source>
                              </reference>
                              <requires idref="IA-2"/>
                              <ident system="http://cce.mitre.org">CCE-3273-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-423</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6565" value-id="Restrictions-for-Unauthenticated-RPC-clients_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6565"/>
                              </check>
                        </Rule>
                        <Rule id="rpc_endpoint_mapper_client_authentication" selected="false" weight="10.0">
                              <title>RPC Endpoint Mapper Client Authentication</title>
                              <description>Computer_Configuration - Administrative_Templates - System: Remote Assistance - RPC Endpoint Mapper Client Authentication.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\System\Remote Procedure Call</dc:source>
                              </reference>
                              <requires idref="IA-2"/>
                              <ident system="http://cce.mitre.org">CCE-2956-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-145</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6566" value-id="rpc_endpoint_mapper_client_authentication_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6566"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Windows Components Group                                                                  -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="windows_components_group">
                  <title>Computer Configuration - Administrative Templates - Windows Components</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--       Internet Information Services Settings        -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="internet-information_services_settings">
                        <title>Internet Information Services</title>
                        <description>Internet Information Services</description>
                        <Value id="Prevent-IIS-Installation_var" operator="equals" type="number">
                              <title>Prevent IIS Installation</title>
                              <description>This blocks even local Administrators from adding local web services to the XP client</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="Prevent-IIS-Installation" selected="false" weight="10.0">
                              <title>Prevent IIS Installation</title>
                              <description>This blocks even local Administrators from adding local web services to the XP client</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Internet Information Services</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-4262-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-474</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:61071" value-id="Prevent-IIS-Installation_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6107"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--                NetMeeting Settings                  -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="netmeeting_settings">
                        <title>NetMeeting</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: NetMeeting</description>
                        <Value id="disable_remote_desktop_sharing_var" operator="equals" type="string">
                              <title>Disable remote Desktop Sharing</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\NetMeeting: Disable remote Desktop Sharing.</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Rule id="disable_remote_desktop_sharing" selected="false" weight="10.0">
                              <title>Disable remote Desktop Sharing</title>
                              <description>Computer Configuration\Administrative Templates\Windows Components\NetMeeting: Disable remote Desktop Sharing.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\NetMeeting</dc:source>
                              </reference>
                              <requires idref="AC-17"/>
                              <ident system="http://cce.mitre.org">CCE-2896-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-232</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6595" value-id="disable_remote_desktop_sharing_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6595"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Terminal Services Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="terminal_services_settings">
                        <title>Terminal Services</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Terminal Services</description>
                        <Value id="do_not_allow_passwords_to_be_saved_var" operator="equals" type="string">
                              <title>Do not allow passwords to be saved</title>
                              <description>Do not allow passwords to be saved</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="SSLF-MS-Laptop">Enabled</value>
                              <value selector="SSLF-MS-Desktop">Enabled</value>
                              <value selector="SSLF-rev2-Laptop">Enabled</value>
                              <value selector="SSLF-rev2-Desktop">Enabled</value>
                              <value selector="FDCC-Laptop">Enabled</value>
                              <value selector="FDCC-Desktop">Enabled</value>
                        </Value>
                        <Value id="set-client-connection-encryption-level_var" operator="equals" type="number">
                              <title>Set client connection encryption level</title>
                              <description>Set client connection encryption level</description>
                              <value>3</value>
                              <value selector="enabled:low_level">1</value>
                              <value selector="enabled:client_compatible">2</value>
                              <value selector="enabled:high_level">3</value>
                        </Value>
                        <Value id="set-timelimit-for-disconnected-sessions_var" operator="less than or equal" type="number">
                              <title>Set a time limit for disconnected sessions</title>
                              <description>You can use this policy setting to specify the maximum amount of time that a disconnected session is kept active on the server. By default, Terminal Services allows users to disconnect from a remote session without logging off and ending the session. (1 min)</description>
                              <value>60</value>
                              <value selector="60_seconds">60000</value>
                        </Value>
                        <Value id="set-timelimit-for-active-but-idle-TerminalServices-sessions_var" operator="less than or equal" type="number">
                              <title>Set a time limit for active but idle Terminal Services sessions</title>
                              <description>This policy setting allows you to specify the maximum amount of time that an active Terminal Services session can be idle (without user input) before it is automatically disconnected. (15 min)</description>
                              <value>900</value>
                              <value selector="900_seconds">900000</value>
                        </Value>
                        <Rule id="do_not_allow_passwords_to_be_saved" selected="false" weight="10.0">
                              <title>Do not allow passwords to be saved</title>
                              <description>The "Do not allow passwords to be saved" setting should be configured correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Client</dc:source>
                              </reference>
                              <requires idref="IA-2"/>
                              <requires idref="IA-5"/>
                              <ident system="http://cce.mitre.org">CCE-4849-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-976</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6596" value-id="do_not_allow_passwords_to_be_saved_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6596"/>
                              </check>
                        </Rule>
                        <Rule id="set-client-connection-encryption-level" selected="false" weight="10.0">
                              <title>Set client connection encryption level</title>
                              <description>The "Set Client connection Encryption Level" policy should be set correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Encryption and Security</dc:source>
                              </reference>
                              <requires idref="SC-13"/>
                              <ident system="http://cce.mitre.org">CCE-3116-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-397</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6600" value-id="set-client-connection-encryption-level_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6600"/>
                              </check>
                        </Rule>
                        <Rule id="set-timelimit-for-disconnected-sessions" selected="false" weight="10.0">
                              <title>Set a time limit for disconnected sessions</title>
                              <description>The "Set time limit for disconnected sessions" policy should be set correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Session</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-2961-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-920</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6726" value-id="set-timelimit-for-disconnected-sessions_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6726"/>
                              </check>
                        </Rule>
                        <Rule id="set-timelimit-for-active-but-idle-TerminalServices-sessions" selected="false" weight="10.0">
                              <title>Set a time limit for active but idle Terminal Services sessions</title>
                              <description>The "Set time limit for idle sessions" policy should be set correctly for Terminal Services.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Terminal Services\Session</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-3124-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-123</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6725" value-id="set-timelimit-for-active-but-idle-TerminalServices-sessions_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6725"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Windows Explorer Settings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_explorer_settings">
                        <title>Windows Explorer</title>
                        <description>Windows Explorer</description>
                        <Value id="turn_off_shell_protocol_protected_mode_var" operator="equals" type="number">
                              <title>Turn off shell protocol protected mode</title>
                              <description>Turn off shell protocol protected mode</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="turn_off_shell_protocol_protected_mode" selected="false" weight="10.0">
                              <title>Turn off shell protocol protected mode</title>
                              <description>Turn off shell protocol protected mode</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Explorer</dc:source>
                              </reference>
                              <requires idref="SI-3"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-4270-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-480</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:61191" value-id="turn_off_shell_protocol_protected_mode_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6119"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Windows Installer Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_installer_settings">
                        <title>Windows Installer</title>
                        <description>Windows Installer</description>
                        <Value id="Disable-IE-security-prompt-Windows-Installer-scripts_var" operator="equals" type="number">
                              <title>Disable IE security prompt for Windows Installer scripts</title>
                              <description>Disable IE security prompt for Windows Installer scripts</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="Enable-User-Control-over-installs_var" operator="equals" type="number">
                              <title>Enable user control over installs</title>
                              <description>Permits users to change installation options that typically are available only to system administrators. This setting bypasses some of the security features of Windows Installer.</description>
                              <value>0</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="prohibit_non_administrators_install_signed_updates_var" operator="equals" type="number">
                              <title>Prohibit non_Administrators from applying vendor signed updates</title>
                              <description>This setting controls the ability of non_Administrators to install updates that have been digitally signed by the application vendor.</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="Disable-IE-security-prompt-Windows-Installer-scripts" selected="false" weight="10.0">
                              <title>Disable IE security prompt for Windows Installer scripts</title>
                              <description>Disable IE security prompt for Windows Installer scripts</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Installer</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2830-8</ident>
                              <ident system="cce.mitre.org/version/4">CCE-261</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:61201" value-id="Disable-IE-security-prompt-Windows-Installer-scripts_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6120"/>
                              </check>
                        </Rule>
                        <Rule id="Enable-User-Control-over-installs" selected="false" weight="10.0">
                              <title>Enable user control over installs</title>
                              <description>Permits users to change installation options that typically are available only to system administrators. This setting bypasses some of the security features of Windows Installer.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Installer</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-3094-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-415</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:61211" value-id="Enable-User-Control-over-installs_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6121"/>
                              </check>
                        </Rule>
                        <Rule id="prohibit_non_administrators_install_signed_updates" selected="false" weight="10.0">
                              <title>Prohibit non_Administrators from applying vendor signed updates</title>
                              <description>This setting controls the ability of non_Administrators to install updates that have been digitally signed by the application vendor.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Installer</dc:source>
                              </reference>
                              <requires idref="AC-6"/>
                              <ident system="http://cce.mitre.org">CCE-5025-2</ident>
                              <ident system="cce.mitre.org/version/4">CCE-612</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:61221" value-id="prohibit_non_administrators_install_signed_updates_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6122"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--           Windows Media Player Settings            -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_media_player_settings">
                        <title>Windows Media Player Settings</title>
                        <description>todo - description needed</description>
                        <Value id="do_not_show_first_use_dialog_boxes_var" type="number" operator="equals">
                              <title>do_not_show_first_use_dialog_boxes</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="prevent_automatic_updates_var" type="number" operator="equals">
                              <title>prevent_automatic_updates</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Value id="prevent_desktop_shortcut_creation_var" type="string" operator="equals">
                              <title>prevent_desktop_shortcut_creation</title>
                              <description>todo - description needed</description>
                              <value>no</value>
                              <value selector="disabled">yes</value>
                              <value selector="enabled">no</value>
                        </Value>
                        <Rule id="do_not_show_first_use_dialog_boxes" selected="false" weight="10.0">
                              <title>Do Not Show First Use Dialog Boxes</title>
                              <description>The "Do Not Show First Use Dialog Boxes" setting for Windows Media Player should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Media Player</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4791-0</ident>
                              <ident system="cce.mitre.org/version/4">CCE-1140</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:612261221" value-id="do_not_show_first_use_dialog_boxes_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:612261221"/>
                              </check>
                        </Rule>
                        <Rule id="prevent_automatic_updates" selected="false" weight="10.0">
                              <title>Prevent Automatic Updates</title>
                              <description>The "Disable Media Player for automatic updates" policy should be set correctly. </description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Media Player</dc:source>
                              </reference>
                              <requires idref="SI-2"/>
                              <ident system="http://cce.mitre.org">CCE-2826-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-455</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:612261222" value-id="prevent_automatic_updates_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:612261222"/>
                              </check>
                        </Rule>
                        <Rule id="prevent_desktop_shortcut_creation" selected="false" weight="10.0">
                              <title>Prevent Desktop Shortcut Creation</title>
                              <description>The "Prevent Desktop Shortcut Creation" setting for Windows Media Player should be configured correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Media Player</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4482-6</ident>
                              <ident system="cce.mitre.org/version/4">CCE-313</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:612261223" value-id="prevent_desktop_shortcut_creation_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:612261223"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Windows Messenger Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="windows_messenger_settings">
                        <title>Windows Messenger</title>
                        <description>Computer Configuration\Administrative Templates\Windows Components: Windows Messenger</description>
                        <Value id="Do-not-allow-Windows-Messenger-to-be-run_var" operator="equals" type="string">
                              <title>Do not allow Windows Messenger to be run</title>
                              <description>Do not allow Windows Messenger to be run</description>
                              <value>Not Configured</value>
                              <value selector="disabled">Disabled</value>
                              <value selector="enabled">Enabled</value>
                        </Value>
                        <Value id="do_not_automatically_start_windows_messenger_initially_var" type="number" operator="equals">
                              <title>do_not_automatically_start_windows_messenger_initially</title>
                              <description>todo - description needed</description>
                              <value>1</value>
                              <value selector="disabled">0</value>
                              <value selector="enabled">1</value>
                        </Value>
                        <Rule id="Do-not-allow-Windows-Messenger-to-be-run" selected="false" weight="10.0">
                              <title>Do not allow Windows Messenger to be run</title>
                              <description>Do not allow Windows Messenger to be run</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Messenger</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2684-9</ident>
                              <ident system="cce.mitre.org/version/4">CCE-802</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6601" value-id="Do-not-allow-Windows-Messenger-to-be-run_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6601"/>
                              </check>
                        </Rule>
                        <Rule id="do_not_automatically_start_windows_messenger_initially" selected="false" weight="10.0">
                              <title>Do not automatically start Windows Messenger initially</title>
                              <description>The "Do Not Automatically Start Windows Messenger" policy should be set correctly.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>Computer Configuration\Administrative Templates\Windows Components\Windows Messenger</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-2455-4</ident>
                              <ident system="cce.mitre.org/version/4">CCE-309</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:612261224" value-id="do_not_automatically_start_windows_messenger_initially_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:612261224"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Local User Policy Group                                                               -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="local-user-policy-group">
                  <title>Local User Policy Settings</title>
                  <description>todo - description needed</description>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--               Control Panel Settings               -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="control_panel_settings">
                        <title>Local User Policy: Control Panel</title>
                        <description>todo - description needed</description>
                        <Value id="password_protect_the_screen_saver_var" operator="equals" type="string">
                              <title>Password protect the screen saver</title>
                              <description>Password protect the screen saver</description>
                              <value>Enabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="disabled">Disabled</value>
                        </Value>
                        <Value id="Screen-Saver-timeout_var" operator="less than or equal" type="number">
                              <title>Screen Saver timeout</title>
                              <description>Specifies how much user idle time must elapse before the screen saver is launched. When configured, this idle time can be set from a minimum of 1 second to a maximum of 86,400 seconds, or 24 hours. If set to zero, the screen saver will not be started.</description>
                              <value>900</value>
                              <value selector="enabled:900_seconds">900</value>
                        </Value>
                        <Rule id="password_protect_the_screen_saver" selected="false" weight="10.0">
                              <title>Password protect the screen saver</title>
                              <description>Determines whether screen savers used on the computer are password protected. If you enable this setting, all screen savers are password protected. If you disable this setting, password protection cannot be set on any screen saver.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Control Panel\Display</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-4500-5</ident>
                              <ident system="cce.mitre.org/version/4">CCE-949</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6707" value-id="password_protect_the_screen_saver_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6707"/>
                              </check>
                        </Rule>
                        <Rule id="Screen-Saver-timeout" selected="false" weight="10.0">
                              <title>Screen Saver timeout</title>
                              <description>Specifies how much user idle time must elapse before the screen saver is launched. When configured, this idle time can be set from a minimum of 1 second to a maximum of 86,400 seconds, or 24 hours. If set to zero, the screen saver will not be started.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Control Panel\Display</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <requires idref="AC-3"/>
                              <requires idref="CM-7"/>
                              <requires idref="SC-5"/>
                              <ident system="http://cce.mitre.org">CCE-2980-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-830</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6708" value-id="Screen-Saver-timeout_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6708"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--             Power Management Settings              -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="power_management_settings">
                        <title>Power Management settings</title>
                        <description>todo - description needed</description>
                        <Value id="prompt_for_password_on_resume_from_hibernate_suspend_var" operator="equals" type="string">
                              <title>Prompt for password on resume from hibernate / suspend</title>
                              <description>Prompt for password on resume from hibernate / suspend</description>
                              <value>Enabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="disabled">Disabled</value>
                        </Value>
                        <Rule id="prompt_for_password_on_resume_from_hibernate_suspend" selected="false" weight="10.0">
                              <title>Prompt for password on resume from hibernate / suspend</title>
                              <description>This settings allows you to configure client computers to always lock when resuming from a hibernate or suspend. If you enable this setting, the client computer is locked when it is resumed from a suspend or hibernate state.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\System\Power Management</dc:source>
                              </reference>
                              <requires idref="AC-11"/>
                              <ident system="http://cce.mitre.org">CCE-4390-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-509</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6714" value-id="prompt_for_password_on_resume_from_hibernate_suspend_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6714"/>
                              </check>
                        </Rule>
                  </Group>
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <!--            Attachment Manager Settings             -->
                  <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
                  <Group id="attachment_manager_settings">
                        <title>Attachment Manager Settings</title>
                        <description>todo - description needed</description>
                        <Value id="do_not_preserve_zone_information_in_file_attachments_var" operator="equals" type="string">
                              <title>Do not preserve zone information in file attachments</title>
                              <description>Do not preserve zone information in file attachments</description>
                              <value>Disabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="disabled">Disabled</value>
                        </Value>
                        <Value id="hide_mechanisms_to_remove_zone_information_var" operator="equals" type="string">
                              <title>Hide mechanisms to remove zone information</title>
                              <description>Hide mechanisms to remove zone information</description>
                              <value>Enabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="disabled">Enabled</value>
                        </Value>
                        <Value id="notify_antivirus_programs_when_opening_attachments_var" operator="equals" type="string">
                              <title>Notify antivirus programs when opening attachments</title>
                              <description>Notify antivirus programs when opening attachments</description>
                              <value>Enabled</value>
                              <value selector="enabled">Enabled</value>
                              <value selector="disabled">Enabled</value>
                        </Value>
                        <Rule id="do_not_preserve_zone_information_in_file_attachments" selected="false" weight="10.0">
                              <title>Do not preserve zone information in file attachments</title>
                              <description>This policy setting allows you to manage whether Windows marks file attachments with information about their zone of origin (i.e. restricted, Internet, intranet, local).</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Windows Components\Attachment Manager</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-4412-3</ident>
                              <ident system="cce.mitre.org/version/4">CCE-12</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6502" value-id="do_not_preserve_zone_information_in_file_attachments_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6502"/>
                              </check>
                        </Rule>
                        <Rule id="hide_mechanisms_to_remove_zone_information" selected="false" weight="10.0">
                              <title>Hide mechanisms to remove zone information</title>
                              <description>This policy setting allows you to manage whether users can manually remove the zone information from saved file attachments by clicking the Unblock button in the file’s property sheet or by using a check box in the security warning dialog.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Windows Components\Attachment Manager</dc:source>
                              </reference>
                              <requires idref="CM-6"/>
                              <ident system="http://cce.mitre.org">CCE-5042-7</ident>
                              <ident system="cce.mitre.org/version/4">CCE-58</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6503" value-id="hide_mechanisms_to_remove_zone_information_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6503"/>
                              </check>
                        </Rule>
                        <Rule id="notify_antivirus_programs_when_opening_attachments" selected="false" weight="10.0">
                              <title>Notify antivirus programs when opening attachments</title>
                              <description>This policy setting allows you to manage the behavior for notifying registered antivirus programs. If multiple programs are registered, they will all be notified.</description>
                              <reference>
                                    <dc:type>GPO</dc:type>
                                    <dc:source>User Configuration\Administrative Templates\Windows Components\Attachment Manager</dc:source>
                              </reference>
                              <requires idref="SI-3"/>
                              <ident system="http://cce.mitre.org">CCE-5059-1</ident>
                              <ident system="cce.mitre.org/version/4">CCE-372</ident>
                              <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                                    <check-export export-name="oval:gov.nist.fdcc.xp:var:6504" value-id="notify_antivirus_programs_when_opening_attachments_var"/>
                                    <check-content-ref href="fdcc-winxp-oval.xml" name="oval:gov.nist.fdcc.xp:def:6504"/>
                              </check>
                        </Rule>
                  </Group>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  7 - Security Patches                                                                        *** -->
      <!-- **************************************************************************************************** -->
      <Group id="security_patches">
            <title>Security Patches</title>
            <description>Securing a given computer has become increasingly important. As such, it is essential to keep a host up to current patch levels to eliminate known vulnerabilities and weaknesses. In conjunction with antivirus software and a personal firewall, patching goes a long way to securing a host against outside attacks and exploitation. Microsoft provides two mechanisms for distributing security updates: Automatic Updates and Microsoft Update. In smaller environments, either method may be sufficient for keeping systems current with patches. Other environments typically have a software change management control process or a patch management program that tests patches before deploying them; distribution may then occur through local Windows Update Services (WUS) or Windows Server Update Services (WSUS) servers, which provide approved security patches for use by the Automatic Updates feature.</description>
            <Rule id="security_patches_up_to_date" selected="false" weight="10.0">
                  <title>Security Patches Up-To-Date</title>
                  <description>Keep systems up to current patch levels to eliminate known vulnerabilities and weaknesses.</description>
                  <requires idref="CM-6"/>
                  <requires idref="SI-2"/>
                  <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                        <check-content-ref href="http://nvd.nist.gov/scap/content/fdcc-winxp-patches.xml"/>
                        <check-content-ref href="fdcc-winxp-patches.xml"/>
                  </check>
            </Rule>
      </Group>
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
</Benchmark>
