<?xml version="1.0" encoding="UTF-8"?>
<Benchmark id="FDCC-XP-Firewall" resolved="0" xml:lang="en"
      xmlns="http://checklists.nist.gov/xccdf/1.1"
      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      xmlns:cdf="http://checklists.nist.gov/xccdf/1.1"
      xmlns:cpe="http://cpe.mitre.org/dictionary/2.0"
      xmlns:dc="http://purl.org/dc/elements/1.1/"
      xmlns:xhtml="http://www.w3.org/1999/xhtml"
      xmlns:dsig="http://www.w3.org/2000/09/xmldsig#"
      xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.1 http://nvd.nist.gov/schema/xccdf-1.1.4.xsd
      http://cpe.mitre.org/dictionary/2.0 http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
      <status date="2009-03-26">accepted</status>
      <title>FDCC: Guidance for Securing Microsoft Windows XP Firewall for IT Professional</title>
      <description>NIST Special Publication 800-68 has been created to assist IT professionals, in particular Windows XP system administrators and information security personnel, in effectively securing Windows XP Professional SP2 and SP3 systems with Windows Firewall.</description>
      <notice id="terms-of-use" xml:lang="en">Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment.  NIST assumes no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic. NIST would appreciate acknowledgement if the document and template are used.</notice>
      <front-matter xml:lang="en">todo - add text</front-matter>
      <rear-matter xml:lang="en"><xhtml:strong>Trademark Information</xhtml:strong><xhtml:br/><xhtml:br/>Microsoft, Windows, Windows XP, Windows Vista, Internet Explorer, and Windows Firewall are either registered trademarks or trademarks of Microsoft Corporation in the United States and other countries.<xhtml:br/><xhtml:br/>All other names are registered trademarks or trademarks of their respective companies.</rear-matter>
      <reference href="http://nvd.nist.gov/chklst_detail.cfm?config_id=76">
            <dc:publisher>National Institute of Standards and Technology</dc:publisher>
            <dc:identifier>SP 800-68</dc:identifier>
      </reference>
      <platform idref="cpe:/o:microsoft:windows_xp::sp2"/>
      <platform idref="cpe:/o:microsoft:windows_xp::sp3"/>
      <version>v1.2.1.0</version>
      <model system="urn:xccdf:scoring:default"/>
      <model system="urn:xccdf:scoring:flat"/>
      <!-- ==================================================================================================== -->
      <!-- ======================================  NIST 800-53 PROFILES  ====================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following profiles are used to turn on specific controls as definied in 800-53.  These controls  -->
      <!-- help determine the specific rules that will be evaluated as certain rules found in this document     -->
      <!-- require specific controls to be enabled.  This enable FISMA compliance to be achived by combining    -->
      <!-- guidance defined with high level recommendations made in 800-53.                                     -->
      <!--                                                                                                      -->
      <Profile id="low_800_53" abstract="true">
            <title>800-53 Low</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which all three security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of low. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="0"/>
            <select idref="AC-5" selected="0"/>
            <select idref="AC-6" selected="0"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="0"/>
            <select idref="AC-10" selected="0"/>
            <select idref="AC-11" selected="0"/>
            <select idref="AC-12" selected="0"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="0"/>
            <select idref="AC-16" selected="0"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="0"/>
            <select idref="AC-19" selected="0"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="0"/>
            <select idref="AU-7" selected="0"/>
            <select idref="AU-8" selected="0"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="0"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="0"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="0"/>
            <select idref="CM-4" selected="0"/>
            <select idref="CM-5" selected="0"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="0"/>
            <select idref="CP-4" selected="0"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="0"/>
            <select idref="CP-7" selected="0"/>
            <select idref="CP-8" selected="0"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="0"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="0"/>
            <select idref="IR-3" selected="0"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="0"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="0"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="0"/>
            <select idref="MP-4" selected="0"/>
            <select idref="MP-5" selected="0"/>
            <select idref="MP-6" selected="0"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="0"/>
            <select idref="PE-5" selected="0"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="0"/>
            <select idref="PE-10" selected="0"/>
            <select idref="PE-11" selected="0"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="0"/>
            <select idref="PE-18" selected="0"/>
            <select idref="PE-19" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="0"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="0"/>
            <select idref="SA-11" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="0"/>
            <select idref="SC-3" selected="0"/>
            <select idref="SC-4" selected="0"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="0"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="0"/>
            <select idref="SC-9" selected="0"/>
            <select idref="SC-10" selected="0"/>
            <select idref="SC-11" selected="0"/>
            <select idref="SC-12" selected="0"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="0"/>
            <select idref="SC-16" selected="0"/>
            <select idref="SC-17" selected="0"/>
            <select idref="SC-18" selected="0"/>
            <select idref="SC-19" selected="0"/>
            <select idref="SC-20" selected="0"/>
            <select idref="SC-21" selected="0"/>
            <select idref="SC-22" selected="0"/>
            <select idref="SC-23" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="0"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="0"/>
            <select idref="SI-7" selected="0"/>
            <select idref="SI-8" selected="0"/>
            <select idref="SI-9" selected="0"/>
            <select idref="SI-10" selected="0"/>
            <select idref="SI-11" selected="0"/>
            <select idref="SI-12" selected="0"/>
      </Profile>
      <Profile id="moderate_800_53" abstract="true">
            <title>800-53 Moderate</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="0"/>
            <select idref="AC-10" selected="0"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="0"/>
            <select idref="AC-16" selected="0"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="0"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="0"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="0"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="0"/>
            <select idref="SA-11" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="0"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="0"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="0"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="0"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="0"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="high_800_53" abstract="true">
            <title>800-53 High</title>
            <description>This profile selects specific controls that are recommended by Special Publication 800-53 for information systems in which at least one security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS 199 potential impact value of high. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="0"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="0"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="0"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="0"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="0"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="0"/>
            <select idref="SA-11" selected="0"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="0"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="0"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <Profile id="all_800_53" abstract="true">
            <title>800-53 All</title>
            <description>This profile selects all the security controls that are recommended by Special Publication 800-53 for information systems. Each control has an effect on other groups within this document as individual rule require certain controls to be selected.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AC-1" selected="true"/>
            <select idref="AC-2" selected="true"/>
            <select idref="AC-3" selected="true"/>
            <select idref="AC-4" selected="true"/>
            <select idref="AC-5" selected="true"/>
            <select idref="AC-6" selected="true"/>
            <select idref="AC-7" selected="true"/>
            <select idref="AC-8" selected="true"/>
            <select idref="AC-9" selected="true"/>
            <select idref="AC-10" selected="true"/>
            <select idref="AC-11" selected="true"/>
            <select idref="AC-12" selected="true"/>
            <select idref="AC-13" selected="true"/>
            <select idref="AC-14" selected="true"/>
            <select idref="AC-15" selected="true"/>
            <select idref="AC-16" selected="true"/>
            <select idref="AC-17" selected="true"/>
            <select idref="AC-18" selected="true"/>
            <select idref="AC-19" selected="true"/>
            <select idref="AC-20" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AT  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AT-1" selected="true"/>
            <select idref="AT-2" selected="true"/>
            <select idref="AT-3" selected="true"/>
            <select idref="AT-4" selected="true"/>
            <select idref="AT-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  AU  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="AU-1" selected="true"/>
            <select idref="AU-2" selected="true"/>
            <select idref="AU-3" selected="true"/>
            <select idref="AU-4" selected="true"/>
            <select idref="AU-5" selected="true"/>
            <select idref="AU-6" selected="true"/>
            <select idref="AU-7" selected="true"/>
            <select idref="AU-8" selected="true"/>
            <select idref="AU-9" selected="true"/>
            <select idref="AU-10" selected="true"/>
            <select idref="AU-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CA-1" selected="true"/>
            <select idref="CA-2" selected="true"/>
            <select idref="CA-3" selected="true"/>
            <select idref="CA-4" selected="true"/>
            <select idref="CA-5" selected="true"/>
            <select idref="CA-6" selected="true"/>
            <select idref="CA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CM  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CM-1" selected="true"/>
            <select idref="CM-2" selected="true"/>
            <select idref="CM-3" selected="true"/>
            <select idref="CM-4" selected="true"/>
            <select idref="CM-5" selected="true"/>
            <select idref="CM-6" selected="true"/>
            <select idref="CM-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  CP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="CP-1" selected="true"/>
            <select idref="CP-2" selected="true"/>
            <select idref="CP-3" selected="true"/>
            <select idref="CP-4" selected="true"/>
            <select idref="CP-5" selected="true"/>
            <select idref="CP-6" selected="true"/>
            <select idref="CP-7" selected="true"/>
            <select idref="CP-8" selected="true"/>
            <select idref="CP-9" selected="true"/>
            <select idref="CP-10" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IA-1" selected="true"/>
            <select idref="IA-2" selected="true"/>
            <select idref="IA-3" selected="true"/>
            <select idref="IA-4" selected="true"/>
            <select idref="IA-5" selected="true"/>
            <select idref="IA-6" selected="true"/>
            <select idref="IA-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  IR  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="IR-1" selected="true"/>
            <select idref="IR-2" selected="true"/>
            <select idref="IR-3" selected="true"/>
            <select idref="IR-4" selected="true"/>
            <select idref="IR-5" selected="true"/>
            <select idref="IR-6" selected="true"/>
            <select idref="IR-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MA-1" selected="true"/>
            <select idref="MA-2" selected="true"/>
            <select idref="MA-3" selected="true"/>
            <select idref="MA-4" selected="true"/>
            <select idref="MA-5" selected="true"/>
            <select idref="MA-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  MP  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="MP-1" selected="true"/>
            <select idref="MP-2" selected="true"/>
            <select idref="MP-3" selected="true"/>
            <select idref="MP-4" selected="true"/>
            <select idref="MP-5" selected="true"/>
            <select idref="MP-6" selected="true"/>
            <select idref="MP-7" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PE  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PE-1" selected="true"/>
            <select idref="PE-2" selected="true"/>
            <select idref="PE-3" selected="true"/>
            <select idref="PE-4" selected="true"/>
            <select idref="PE-5" selected="true"/>
            <select idref="PE-6" selected="true"/>
            <select idref="PE-7" selected="true"/>
            <select idref="PE-8" selected="true"/>
            <select idref="PE-9" selected="true"/>
            <select idref="PE-10" selected="true"/>
            <select idref="PE-11" selected="true"/>
            <select idref="PE-12" selected="true"/>
            <select idref="PE-13" selected="true"/>
            <select idref="PE-14" selected="true"/>
            <select idref="PE-15" selected="true"/>
            <select idref="PE-16" selected="true"/>
            <select idref="PE-17" selected="true"/>
            <select idref="PE-18" selected="true"/>
            <select idref="PE-19" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PL  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PL-1" selected="true"/>
            <select idref="PL-2" selected="true"/>
            <select idref="PL-3" selected="true"/>
            <select idref="PL-4" selected="true"/>
            <select idref="PL-5" selected="true"/>
            <select idref="PL-6" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  PS  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="PS-1" selected="true"/>
            <select idref="PS-2" selected="true"/>
            <select idref="PS-3" selected="true"/>
            <select idref="PS-4" selected="true"/>
            <select idref="PS-5" selected="true"/>
            <select idref="PS-6" selected="true"/>
            <select idref="PS-7" selected="true"/>
            <select idref="PS-8" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  RA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="RA-1" selected="true"/>
            <select idref="RA-2" selected="true"/>
            <select idref="RA-3" selected="true"/>
            <select idref="RA-4" selected="true"/>
            <select idref="RA-5" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SA  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SA-1" selected="true"/>
            <select idref="SA-2" selected="true"/>
            <select idref="SA-3" selected="true"/>
            <select idref="SA-4" selected="true"/>
            <select idref="SA-5" selected="true"/>
            <select idref="SA-6" selected="true"/>
            <select idref="SA-7" selected="true"/>
            <select idref="SA-8" selected="true"/>
            <select idref="SA-9" selected="true"/>
            <select idref="SA-10" selected="true"/>
            <select idref="SA-11" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SC  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SC-1" selected="true"/>
            <select idref="SC-2" selected="true"/>
            <select idref="SC-3" selected="true"/>
            <select idref="SC-4" selected="true"/>
            <select idref="SC-5" selected="true"/>
            <select idref="SC-6" selected="true"/>
            <select idref="SC-7" selected="true"/>
            <select idref="SC-8" selected="true"/>
            <select idref="SC-9" selected="true"/>
            <select idref="SC-10" selected="true"/>
            <select idref="SC-11" selected="true"/>
            <select idref="SC-12" selected="true"/>
            <select idref="SC-13" selected="true"/>
            <select idref="SC-14" selected="true"/>
            <select idref="SC-15" selected="true"/>
            <select idref="SC-16" selected="true"/>
            <select idref="SC-17" selected="true"/>
            <select idref="SC-18" selected="true"/>
            <select idref="SC-19" selected="true"/>
            <select idref="SC-20" selected="true"/>
            <select idref="SC-21" selected="true"/>
            <select idref="SC-22" selected="true"/>
            <select idref="SC-23" selected="true"/>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~  SI  ~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <select idref="SI-1" selected="true"/>
            <select idref="SI-2" selected="true"/>
            <select idref="SI-3" selected="true"/>
            <select idref="SI-4" selected="true"/>
            <select idref="SI-5" selected="true"/>
            <select idref="SI-6" selected="true"/>
            <select idref="SI-7" selected="true"/>
            <select idref="SI-8" selected="true"/>
            <select idref="SI-9" selected="true"/>
            <select idref="SI-10" selected="true"/>
            <select idref="SI-11" selected="true"/>
            <select idref="SI-12" selected="true"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- =========================================  FDCC PROFILES  ========================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- These profiles outline the specific guidance outlined by the Federal Desktop Core Configuration.     -->
      <!-- Each defines the set of XCCDF rules that are applicable for that guidance as well as specific values -->
      <!-- to be used when determining complinace.                                                              -->
      <!--                                                                                                      -->
      <Profile id="federal_desktop_core_configuration_version_1.2.1.0" extends="all_800_53">
            <title>Federal Desktop Core Configuration version 1.2.1.0</title>
            <description>This profile represents guidance outlined in Federal Core Configuration settings for Windows XP Firewall on desktop systems.</description>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''  3 - FDCC Other Settings                                                               ''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <select idref="allow_file_print_sharing_exceptions_domain_profile" selected="true"/>
            <select idref="allow_icm_exceptions_domain_profile" selected="true"/>
            <select idref="allow_local_port_exceptions_domain_profile" selected="true"/>
            <select idref="allow_local_program_exceptions_domain_profile" selected="true"/>
            <select idref="allow_logging_log_dropped_packets_domain_profile" selected="true"/>
            <select idref="allow_logging_log_successful_connections_domain_profile" selected="true"/>
            <select idref="allow_logging_log_size_domain_profile" selected="true"/>
            <select idref="allow_logging_log_path_domain_profile" selected="true"/>
            <select idref="allow_remote_administration_exceptions_domain_profile" selected="true"/>
            <select idref="allow_remote_desktop_exceptions_domain_profile" selected="true"/>
            <select idref="allow_upnp_framework_exceptions_domain_profile" selected="true"/>
            <select idref="prohibit_notifications_domain_profile" selected="true"/>
            <select idref="prohibit_unicast_response_to_multicast_or_broadcast_requests_domain_profile" selected="true"/>
            <select idref="protect_all_network_connections_domain_profile" selected="true"/>
            <select idref="AllowFilePrintSharingExceptionsStandardProfile" selected="true"/>
            <select idref="AllowICMPExceptionsStandardProfile" selected="true"/>
            <select idref="AllowLocalPortExceptionsStandardProfile" selected="true"/>
            <select idref="AllowLocalProgramExceptionsStandardProfile" selected="true"/>
            <select idref="AllowRemoteAdministrationExceptionsStandardProfile" selected="true"/>
            <select idref="AllowRemoteDesktopExceptionsStandardProfile" selected="true"/>
            <select idref="AllowUPnPframeworkExceptionsStandardProfile" selected="true"/>
            <select idref="DoNotAllowExceptionsStandardProfile" selected="true"/>
            <select idref="ProhibitNotificationsStandardProfile" selected="true"/>
            <select idref="ProhibitUnicastResponseToMulticastOrBroadcastRequestsStandardProfile" selected="true"/>
            <select idref="ProtectAllNetworkConnectionsStandardProfile" selected="true"/>
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <!-- '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' -->
            <refine-value idref="allow_file_print_sharing_exceptions_domain_profile_var" selector="disabled"/>
            <refine-value idref="allow_local_port_exceptions_domain_profile_var" selector="disabled"/>
            <refine-value idref="allow_local_program_exceptions_domain_profile_var" selector="disabled"/>
            <refine-value idref="allow_remote_administration_exceptions_domain_profile_var" selector="enabled"/>
            <refine-value idref="allow_remote_desktop_exceptions_domain_profile_var" selector="enabled"/>
            <refine-value idref="allow_logging_log_dropped_packets_domain_profile_var" selector="enabled"/>
            <refine-value idref="allow_logging_log_successful_connections_domain_profile_var" selector="enabled"/>
            <refine-value idref="allow_logging_log_size_domain_profile_var" selector="16384_kb"/>
            <refine-value idref="allow_logging_log_path_domain_profile_var" selector="systemroot_domainfwlog"/>
            <refine-value idref="allow_upnp_framework_exceptions_domain_profile_var" selector="disabled"/>
            <refine-value idref="prohibit_notifications_domain_profile_var" selector="enabled"/>
            <refine-value idref="prohibit_unicast_response_to_multicast_or_broadcast_requests_domain_profile_var" selector="enabled"/>
            <refine-value idref="protect_all_network_connections_domain_profile_var" selector="enabled"/>
            <refine-value idref="AllowFilePrintSharingExceptionsStandardProfile_var" selector="disabled"/>
            <refine-value idref="AllowLocalPortExceptionsStandardProfile_var" selector="disabled"/>
            <refine-value idref="AllowLocalProgramExceptionsStandardProfile_var" selector="disabled"/>
            <refine-value idref="AllowRemoteAdministrationExceptionsStandardProfile_var" selector="disabled"/>
            <refine-value idref="AllowRemoteDesktopExceptionsStandardProfile_var" selector="disabled"/>
            <refine-value idref="AllowUPnPframeworkExceptionsStandardProfile_var" selector="disabled"/>
            <refine-value idref="DoNotAllowExceptionsStandardProfile_var" selector="enabled"/>
            <refine-value idref="ProhibitNotificationsStandardProfile_var" selector="enabled"/>
            <refine-value idref="ProhibitUnicastResponseToMulticastOrBroadcastRequestsStandardProfile_var" selector="enabled"/>
            <refine-value idref="ProtectAllNetworkConnectionsStandardProfile_var" selector="enabled"/>
      </Profile>
      <!-- ==================================================================================================== -->
      <!-- ================================  NIST SP 800-53 (FISMA) Controls  ================================= -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following group contains all the different controls defined by NIST SP 800-53.  These controls   -->
      <!-- are hidden as they should not appear in any document generated from this file pertaining to specific -->
      <!-- security guidance.  These controls are used by the 800-53 profiles to enable high-level guidance     -->
      <!-- that is then passed down to the XP profiles and used to enable specific XCCDF Rules.                 -->
      <!--                                                                                                      -->
      <Group id="nist_sp80053_controls" hidden="true">
            <title>NIST SP 800-53 Controls</title>
            <Group id="access_control_checks" hidden="true">
                  <title>Applicable 800-53 Access Control Checks</title>
                  <Group id="AC-1" hidden="true">
                        <title>Access Control Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 11.1.1, 11.4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 15, 16</reference>
                        <reference>DOD 8500.2: ECAN-1, ECPA-1, PRAS-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.1.a(1)(b)</reference>
                  </Group>
                  <Group id="AC-2" hidden="true">
                        <title>Account Management</title>
                        <reference>ISO/IEC 17799: 6.2.2, 6.2.3, 8.3.3, 11.2.1, 11.2.2, 11.2.4, 11.7.2</reference>
                        <reference>NIST 800-26: 6.1.8, 15.1.1, 15.1.4, 15.1.15, 15.1.8, 15.2.2, 16.1.3, 16.1.5, 16.2.12</reference>
                        <reference>GAO FISCAM: AC-2.1 AC-2.2, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAAC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)</reference>
                  </Group>
                  <Group id="AC-3" hidden="true">
                        <title>Access Enforcement</title>
                        <reference>ISO/IEC 17799: 11.2.4, 11.4.5</reference>
                        <reference>NIST 800-26: 10.1.2, 15.1.1, 16.1.1, 16.1.2, 16.1.3, 16.1.7, 16.1.9, 16.2.1, 16.2.7, 16.2.10, 16.2.11, 16.2.15</reference>
                        <reference>GAO FISCAM: AC-2, AC-3.2</reference>
                        <reference>DOD 8500.2: DCFA-1, ECAN-1, EBRU-1, PRNK-1, ECCD-1, ECSD-2</reference>
                        <reference>DCID 6/3: Discretionary Access Control (DAC): 4.B.2.a(2), Mandatory Access Control (MAC): 4.B.4.a(3)</reference>
                  </Group>
                  <Group id="AC-4" hidden="true">
                        <title>Information Flow Enforcement</title>
                        <reference>ISO/IEC 17799: 10.6.2, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>DOD 8500.2: EBBD-1, EBBD-2</reference>
                        <reference>DCID 6/3: 4.B.3.a(3), 7.B.3.g</reference>
                  </Group>
                  <Group id="AC-5" hidden="true">
                        <title>Separation of Duties</title>
                        <reference>ISO/IEC 17799: 10.1.3, 10.6.1, 10.10.1</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2, 6.1.3, 15.2.1, 16.1.2, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2, SD-1.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 2.A.1, 4.B.3.a(18)</reference>
                  </Group>
                  <Group id="AC-6" hidden="true">
                        <title>Least Privilege</title>
                        <reference>ISO/IEC 17799: 11.2.2</reference>
                        <reference>NIST 800-26: 16.1.2, 16.1.3, 17.1.5</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="AC-7" hidden="true">
                        <title>Unsuccessful Login Attempts</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>NIST 800-26: 15.1.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(c)-(d)</reference>
                  </Group>
                  <Group id="AC-8" hidden="true">
                        <title>System Use Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1, 15.1.5</reference>
                        <reference>NIST 800-26: 16.2.13, 16.3.1, 17.1.9</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECWM-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(6)</reference>
                  </Group>
                  <Group id="AC-9" hidden="true">
                        <title>Previous Logon Notification</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECLO-2</reference>
                  </Group>
                  <Group id="AC-10" hidden="true">
                        <title>Concurrent Session Control</title>
                        <reference>DOD 8500.2: ECLO-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(a)</reference>
                  </Group>
                  <Group id="AC-11" hidden="true">
                        <title>Session Lock</title>
                        <reference>ISO/IEC 17799: 11.3.2</reference>
                        <reference>NIST 800-26: 16.1.4</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: PESL-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(5)</reference>
                  </Group>
                  <Group id="AC-12" hidden="true">
                        <title>Session Termination</title>
                        <reference>ISO/IEC 17799: 11.3.2, 11.5.5</reference>
                        <reference>NIST 800-26: 16.1.4, 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)(b)</reference>
                  </Group>
                  <Group id="AC-13" hidden="true">
                        <title>Supervision and Review—Access Control</title>
                        <reference>ISO/IEC 17799: 10.10.2, 11.2.4</reference>
                        <reference>NIST 800-26: 7.1.10, 11.2.2, 16.1.10, 16.2.5, 17.1.6, 17.1.7</reference>
                        <reference>GAO FISCAM: AC-4, AC-4.3, SS-2.2</reference>
                        <reference>DOD 8500.2: ECAT-1, ECAT-2, E3.3.9</reference>
                        <reference>DCID 6/3: 2.B.7.c, 4.B.3.a(8)(b)</reference>
                  </Group>
                  <Group id="AC-14" hidden="true">
                        <title>Permitted Actions without Identification or Authentication</title>
                        <reference>NIST 800-26: 16.2.12</reference>
                        <reference>DCID 6/3: 7.D.3.a</reference>
                  </Group>
                  <Group id="AC-15" hidden="true">
                        <title>Automated Marking</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 8.2.4, 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(11)</reference>
                  </Group>
                  <Group id="AC-16" hidden="true">
                        <title>Automated Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(3), 4.B.4.a(15), 4.B.4.a(16)</reference>
                  </Group>
                  <Group id="AC-17" hidden="true">
                        <title>Remote Access</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.4.4</reference>
                        <reference>NIST 800-26: 16.2.4, 16.2.8</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: EBRP-1, EBRU-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1)(b), 4.B.3.a(11), 7.D.2.e</reference>
                  </Group>
                  <Group id="AC-18" hidden="true">
                        <title>Wireless Access Restrictions</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.7.1, 11.7.2</reference>
                        <reference>DOD 8500.2: ECCT-1, ECWN-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8), 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="AC-19" hidden="true">
                        <title>Access Control for Portable and Mobile Systems</title>
                        <reference>ISO/IEC 17799: 11.7.1</reference>
                        <reference>NIST 800-26: 7.3.1, 7.3.2</reference>
                        <reference>DOD 8500.2: ECWN-1</reference>
                        <reference>DCID 6/3: 8.B.6.c, 9.G.4</reference>
                  </Group>
                  <Group id="AC-20" hidden="true">
                        <title>Use of External Information Systems</title>
                        <reference>ISO/IEC 17799: 6.1.4, 9.2.5, 11.7.1</reference>
                        <reference>NIST 800-26: 10.2.13</reference>
                        <reference>DCID 6/3: 8.B.6.c</reference>
                  </Group>
            </Group>
            <Group id="awareness_and_training" hidden="true">
                  <title>Applicable 800-53 Awareness and Training</title>
                  <Group id="AT-1" hidden="true">
                        <title>Security Awareness and Training Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 8.2.2, 15.1.1</reference>
                        <reference>NIST 800-26: 13</reference>
                        <reference>DOD 8500.2: PRTN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.c, Manual: 2.B.2.b(8); 2.B.4.e(6)</reference>
                  </Group>
                  <Group id="AT-2" hidden="true">
                        <title>Security Awareness</title>
                        <reference>ISO/IEC 17799: 6.2.3, 8.2.2, 10.4.1, 11.7.1, 13.1.1, 14.1.4, 15.1.4</reference>
                        <reference>NIST 800-26: 13.1.4, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-3" hidden="true">
                        <title>Security Training</title>
                        <reference>ISO/IEC 17799: 8.2.2, 10.3.2, 11.7.1, 13.1.1, 14.1.4</reference>
                        <reference>NIST 800-26: 13.1, 13.1.3, 13.1.5</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-4" hidden="true">
                        <title>Security Training Records</title>
                        <reference>NIST 800-26: 13.1.2</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="AT-5" hidden="true">
                        <title>Contacts with Security Groups and Associations</title>
                        <reference>ISO/IEC 17799: 6.1.7</reference>
                  </Group>
            </Group>
            <Group id="audit_and_accountablility" hidden="true">
                  <title>Applicable 800-53 Audit and Accountability</title>
                  <Group id="AU-1" hidden="true">
                        <title>Audit and Accountability Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1, 15.1.1</reference>
                        <reference>NIST 800-26: 17</reference>
                        <reference>DOD 8500.2: ECAT-1, ECTB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.d, Manual: 2.B.4.e(5); 4.B.2.a(4)</reference>
                  </Group>
                  <Group id="AU-2" hidden="true">
                        <title>Auditable Events</title>
                        <reference>ISO/IEC 17799: 10.10.1</reference>
                        <reference>NIST 800-26: 17.1.1, 17.1.2, 17.1.4</reference>
                        <reference>DOD 8500.2: ECAR-3</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(d)</reference>
                  </Group>
                  <Group id="AU-3" hidden="true">
                        <title>Content of Audit Records</title>
                        <reference>ISO/IEC 17799: 10.10.1, 10.10.4</reference>
                        <reference>NIST 800-26: 17.1.1</reference>
                        <reference>DOD 8500.2: ECAR-1, ECAR-2, ECAR-3, ECLC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a), 4.B.2.a(5)(a)</reference>
                  </Group>
                  <Group id="AU-4" hidden="true">
                        <title>Audit Storage Capacity</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="AU-5" hidden="true">
                        <title>Response to Audit Processing Failures</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>DCID 6/3: 4.B.4.a(9)(d)</reference>
                  </Group>
                  <Group id="AU-6" hidden="true">
                        <title>Audit Monitoring, Analysis, and Reporting</title>
                        <reference>ISO/IEC 17799: 10.10.2, 10.10.4, 13.2.1</reference>
                        <reference>NIST 800-26: 16.2.5, 17.1.7, 17.1.8</reference>
                        <reference>GAO FISCAM: AC-4.3</reference>
                        <reference>DOD 8500.2: ECAT-1, E3.3.9</reference>
                        <reference>DCID 6/3: 4.B.4.a(10)</reference>
                  </Group>
                  <Group id="AU-7" hidden="true">
                        <title>Audit Reduction and Report Generation</title>
                        <reference>ISO/IEC 17799: 10.10.3</reference>
                        <reference>NIST 800-26: 17.1.2, 17.1.7</reference>
                        <reference>DOD 8500.2: ECRG-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(6)</reference>
                  </Group>
                  <Group id="AU-8" hidden="true">
                        <title>Time Stamps</title>
                        <reference>ISO/IEC 17799: 10.10.6</reference>
                        <reference>DOD 8500.2: ECAR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(a)</reference>
                  </Group>
                  <Group id="AU-9" hidden="true">
                        <title>Protection of Audit Information</title>
                        <reference>ISO/IEC 17799: 10.10.3, 15.1.3, 15.3.2</reference>
                        <reference>NIST 800-26: 17.1.3, 17.1.4</reference>
                        <reference>DOD 8500.2: ECTP-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(b)</reference>
                  </Group>
                  <Group id="AU-10" hidden="true">
                        <title>Non-repudiation</title>
                        <reference>ISO/IEC 17799: 10.8.2, 10.9.1, 12.3.1</reference>
                        <reference>NIST 800-26: 15.1.2, 17.1.1</reference>
                        <reference>DOD 8500.2: DCNR-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(8)</reference>
                  </Group>
                  <Group id="AU-11" hidden="true">
                        <title>Audit Record Retention</title>
                        <reference>ISO/IEC 17799: 10.10.1, 15.1.3</reference>
                        <reference>NIST 800-26: 17.1.4</reference>
                        <reference>DOD 8500.2: ECRR-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(4)(c)</reference>
                  </Group>
            </Group>
            <Group id="certification_accreditation_and_security_assessment" hidden="true">
                  <title>Applicable 800-53 Certification, Accreditation, and Security Assessment</title>
                  <Group id="CA-1" hidden="true">
                        <title>Certification, Accreditation, and Security Assessment Policies and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1.4, 10.3.2, 15.1.1</reference>
                        <reference>NIST 800-26: 2, 4</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 2.B.2.b(1)</reference>
                  </Group>
                  <Group id="CA-2" hidden="true">
                        <title>Security Assessments</title>
                        <reference>ISO/IEC 17799: 6.1.8, 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 2.1.1, 2.1.3, 2.1.4</reference>
                        <reference>GAO FISCAM: SP-5.1</reference>
                        <reference>DOD 8500.2: DCII-1, ECMT-1, PEPS-1, E3.3.10</reference>
                        <reference>DCID 6/3: DCID: B.2.b; B.3.a, Manual: 4.B.2.b(6); 5.B.1.b(1); 9.B.1; 9.B.4</reference>
                  </Group>
                  <Group id="CA-3" hidden="true">
                        <title>Information System Connections</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.9.1, 11.4.5, 11.4.6, 11.4.7</reference>
                        <reference>NIST 800-26: 1.1.1, 3.2.9, 4.1.8, 12.2.3</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCID-1, EBCR-1 EBRU-1, EBPW-1, ECIC-1</reference>
                        <reference>DCID 6/3: 9.B.3, 9.D.3.c</reference>
                  </Group>
                  <Group id="CA-4" hidden="true">
                        <title>Security Certification</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 2.1.2, 3.2.3, 3.2.5, 3.2.6, 4.1.1, 4.1.6, 11.2.8. 12.2.5</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCAR-1, 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 4.B.3.b(8); 9.E.2.a(2); 9.E.2.a(3)</reference>
                  </Group>
                  <Group id="CA-5" hidden="true">
                        <title>Plan of Action and Milestones</title>
                        <reference>ISO/IEC 17799: 15.2.1</reference>
                        <reference>NIST 800-26: 1.1.5, 1.2.3, 2.2.1, 4.2.1</reference>
                        <reference>GAO FISCAM: SP-5.1 SP-5.2</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 9.E.2.a(3)(a)</reference>
                  </Group>
                  <Group id="CA-6" hidden="true">
                        <title>Security Accreditation</title>
                        <reference>ISO/IEC 17799: 10.3.2</reference>
                        <reference>NIST 800-26: 3.2.7, 12.2.5</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: DCID: B.3, Manual: 9.D.3; 9.D.4</reference>
                  </Group>
                  <Group id="CA-7" hidden="true">
                        <title>Continuous Monitoring</title>
                        <reference>ISO/IEC 17799: 15.2.1, 15.2.2</reference>
                        <reference>NIST 800-26: 10.2.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, E3.3.9</reference>
                        <reference>DCID 6/3: DCID: B.2.d; Manual: 2.B.4.e(7); 2.B.5.c(10); 5.B.2.b(2); 9.B.1; 9.D.7</reference>
                  </Group>
            </Group>
            <Group id="configuration_management" hidden="true">
                  <title>Applicable 800-53 Configuration Management</title>
                  <Group id="CM-1" hidden="true">
                        <title>Configuration Management Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.4.1, 12.5.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCCB-1, DCPR-1, DCAR-1, E3.3.8</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-2" hidden="true">
                        <title>Baseline Configuration and System Component Inventory</title>
                        <reference>ISO/IEC 17799: 7.1.1, 15.1.2</reference>
                        <reference>NIST 800-26: 1.1.1, 3.1.9, 10.2.7, 10.2.9, 12.1.4</reference>
                        <reference>GAO FISCAM: CC-2.3, CC-3.1, SS-1.2</reference>
                        <reference>DOD 8500.2: DCHW-1, DCSW-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 4.B.2.b(6)</reference>
                  </Group>
                  <Group id="CM-3" hidden="true">
                        <title>Configuration Change Control</title>
                        <reference>ISO/IEC 17799: 10.1.2, 10.2.3, 12.4.1, 12.5.1, 12.5.2, 12.5.3</reference>
                        <reference>NIST 800-26: 3.1.4, 10.2.2, 10.2.3, 10.2.8, 10.2.10, 10.2.11</reference>
                        <reference>GAO FISCAM: SS-3.2, CC-2.2</reference>
                        <reference>DOD 8500.2: DCPR-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(7) 4.B.1.c(3), 4.B.2.b(6), 5.B.2.a(5)</reference>
                  </Group>
                  <Group id="CM-4" hidden="true">
                        <title>Monitoring Configuration Changes</title>
                        <reference>ISO/IEC 17799: 10.1.2</reference>
                        <reference>NIST 800-26: 10.2.1, 10.2.4</reference>
                        <reference>GAO FISCAM: SS-3.1, SS-3.2, CC-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, E3.3.8</reference>
                        <reference>DCID 6/3: 2.B.7.c(7), 4.B.1.c(3), 5.B.2.b(2), 8.B.8.c(7)</reference>
                  </Group>
                  <Group id="CM-5" hidden="true">
                        <title>Access Restrictions for Change</title>
                        <reference>ISO/IEC 17799: 11.6.1</reference>
                        <reference>NIST 800-26: 6.1.3, 6.1.4, 10.1.1, 10.1.4, 10.1.5</reference>
                        <reference>GAO FISCAM: SD-1.1, SS-1.2, SS-2.1</reference>
                        <reference>DOD 8500.2: DCPR-1, ECSD-2</reference>
                        <reference>DCID 6/3: 5.B.3.a(2)(b)</reference>
                  </Group>
                  <Group id="CM-6" hidden="true">
                        <title>Configuration Settings</title>
                        <reference>NIST 800-26: 10.2.6, 10.3.1, 16.2.2, 16.2.3, 16.2.11</reference>
                        <reference>DOD 8500.2: DCSS-1, ECSC-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10)</reference>
                  </Group>
                  <Group id="CM-7" hidden="true">
                        <title>Least Functionality</title>
                        <reference>NIST 800-26: 10.3.1</reference>
                        <reference>DOD 8500.2: DCPP-1, ECIM-1, ECVI-1, E3.3.8</reference>
                        <reference>DCID 6/3: 4.B.2.a(10), 7.D.2.b</reference>
                  </Group>
            </Group>
            <Group id="contingency_planning" hidden="true">
                  <title>Applicable 800-53 Contingency Planning</title>
                  <Group id="CP-1" hidden="true">
                        <title>Contingency Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 5.1.1, 10.4.1, 14.1.1, 14.1.3, 15.1.1</reference>
                        <reference>NIST 800-26: 9</reference>
                        <reference>DOD 8500.2: COBR-1, DCAR-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 6.B.1.a(1)</reference>
                  </Group>
                  <Group id="CP-2" hidden="true">
                        <title>Contingency Plan</title>
                        <reference>ISO/IEC 17799: 10.3.2, 10.4.1, 10.8.5, 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 4.1.4, 9.1.1, 9.2, 9.2.1, 9.2.2, 9.2.3, 9.2.10, 12.1.8, 12.2.2</reference>
                        <reference>GAO FISCAM: SC-3.1, SC-1.1</reference>
                        <reference>DOD 8500.2: CODP-1, COEF-1</reference>
                        <reference>DCID 6/3: 6.B.2.b(1)</reference>
                  </Group>
                  <Group id="CP-3" hidden="true">
                        <title>Contingency Training</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.4</reference>
                        <reference>NIST 800-26: 9.3.2</reference>
                        <reference>GAO FISCAM: SC-2.3</reference>
                        <reference>DOD 8500.2: PRTN-1</reference>
                        <reference>DCID 6/3: 8.B.1</reference>
                  </Group>
                  <Group id="CP-4" hidden="true">
                        <title>Contingency Plan Testing</title>
                        <reference>ISO/IEC 17799: 10.5.1, 14.1.5</reference>
                        <reference>NIST 800-26: 4.1.4, 9.3.3</reference>
                        <reference>GAO FISCAM: SC-3.1</reference>
                        <reference>DOD 8500.2: COED-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)(b)</reference>
                  </Group>
                  <Group id="CP-5" hidden="true">
                        <title>Contingency Plan Update</title>
                        <reference>ISO/IEC 17799: 14.1.3, 14.1.5</reference>
                        <reference>NIST 800-26: 9.3.1, 9.3.3, 10.2.12</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: 6.B.3.b(2)</reference>
                  </Group>
                  <Group id="CP-6" hidden="true">
                        <title>Alternate Storage Sites</title>
                        <reference>ISO/IEC 17799: 10.5.1</reference>
                        <reference>NIST 800-26: 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: CODB-2</reference>
                        <reference>DCID 6/3: 6.B.2.a(2), 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-7" hidden="true">
                        <title>Alternate Processing Sites</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.1.3, 9.2.4, 9.2.5, 9.2.7, 9.2.9</reference>
                        <reference>GAO FISCAM: SC-2.1, SC-3.1</reference>
                        <reference>DOD 8500.2: COAS-1, COEB-1, COSP-1, COSP-2</reference>
                        <reference>DCID 6/3: 6.B.3.a(2)(d)</reference>
                  </Group>
                  <Group id="CP-8" hidden="true">
                        <title>Telecommunications Services</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>DCID 6/3: 6.B.2.a(4)</reference>
                  </Group>
                  <Group id="CP-9" hidden="true">
                        <title>Information System Backup</title>
                        <reference>ISO/IEC 17799: 10.5.1, 11.7.1</reference>
                        <reference>NIST 800-26: 9.1.1, 9.2.6, 9.2.9, 9.3.1, 12.1.9</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: CODB-1, CODB-2, COSW-1</reference>
                        <reference>DCID 6/3: 6.B.1.a(2)</reference>
                  </Group>
                  <Group id="CP-10" hidden="true">
                        <title>Information System Recovery and Reconstitution</title>
                        <reference>ISO/IEC 17799: 14.1.4</reference>
                        <reference>NIST 800-26: 9.2.8</reference>
                        <reference>GAO FISCAM: SC-2.1</reference>
                        <reference>DOD 8500.2: COTR-1, ECND-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(4), 6.B.1.a(1), 6.B.2.a(3)(d)</reference>
                  </Group>
            </Group>
            <Group id="identification_and_authentication" hidden="true">
                  <title>Applicable 800-53 Identification and Authentication</title>
                  <Group id="IA-1" hidden="true">
                        <title>Identification and Authentication Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11.2.3</reference>
                        <reference>DOD 8500.2: IAIA-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="IA-2" hidden="true">
                        <title>User Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.4.2, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1</reference>
                        <reference>DOD 8500.2: IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)</reference>
                  </Group>
                  <Group id="IA-3" hidden="true">
                        <title>Device Identification and Authentication</title>
                        <reference>ISO/IEC 17799: 11.4.2, 11.4.3, 11.7.1</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.5.a(14)</reference>
                  </Group>
                  <Group id="IA-4" hidden="true">
                        <title>Identifier Management</title>
                        <reference>ISO/IEC 17799: 11.2.3, 11.5.2</reference>
                        <reference>NIST 800-26: 15.1.1, 15.2.2, 15.1.8</reference>
                        <reference>GAO FISCAM: AC-2.1, AC-3.2, SP-4.1</reference>
                        <reference>DOD 8500.2: IAGA-1, IAIA-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(2)</reference>
                  </Group>
                  <Group id="IA-5" hidden="true">
                        <title>Authenticator Management</title>
                        <reference>ISO/IEC 17799: 11.5.2, 11.5.3</reference>
                        <reference>NIST 800-26: 15.1.6, 15.1.7, 15.1.9, 15.1.10, 15.1.11, 15.1.12, 15.1.13, 16.1.3, 16.2.3</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="IA-6" hidden="true">
                        <title>Authenticator Feedback</title>
                        <reference>ISO/IEC 17799: 11.5.1</reference>
                        <reference>DCID 6/3: 4.B.2.a(7)(g)</reference>
                  </Group>
                  <Group id="IA-7" hidden="true">
                        <title>Cryptographic Module Authentication</title>
                        <reference>NIST 800-26: 16.1.7</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
            </Group>
            <Group id="incident_response" hidden="true">
                  <title>Applicable 800-53 Incident Response</title>
                  <Group id="IR-1" hidden="true">
                        <title>Incident Response Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.4.1, 13.1, 13.2.1, 15.1.1</reference>
                        <reference>NIST 800-26: 14</reference>
                        <reference>DOD 8500.2: VIIR-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.c; C.4 Manual: 2.B.4.e(5); 2.B.2.b(6); 2.B.6.c(10); 8.B.7</reference>
                  </Group>
                  <Group id="IR-2" hidden="true">
                        <title>Incident Response Training</title>
                        <reference>ISO/IEC 17799: 13.1.1</reference>
                        <reference>NIST 800-26: 14.1.4</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.1.b(1)(f), 8.B.1.c(1)(e), 8.B.1.c(2)©</reference>
                  </Group>
                  <Group id="IR-3" hidden="true">
                        <title>Incident Response Testing</title>
                        <reference>ISO/IEC 17799: 14.1.5</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-4" hidden="true">
                        <title>Incident Handling</title>
                        <reference>ISO/IEC 17799: 6.1.6, 13.2.1, 13.2.2</reference>
                        <reference>NIST 800-26: 2.1.5, 14.1.1, 14.1.2, 14.1.6</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7, 9.B.2.e</reference>
                  </Group>
                  <Group id="IR-5" hidden="true">
                        <title>Incident Monitoring</title>
                        <reference>NIST 800-26: 14.1.3</reference>
                        <reference>DOD 8500.2: VIIR-1</reference>
                        <reference>DCID 6/3: 8.B.7.a</reference>
                  </Group>
                  <Group id="IR-6" hidden="true">
                        <title>Incident Reporting</title>
                        <reference>ISO/IEC 17799: 6.1.6, 6.2.2, 6.2.3, 13.1.1, 13.1.2</reference>
                        <reference>NIST 800-26: 14.1.2, 14.1.3, 14.2.1, 14.2.2, 14.2.3</reference>
                        <reference>DOD 8500.2: VIIR-1, E3.3.9</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="IR-7" hidden="true">
                        <title>Incident Response Assistance</title>
                        <reference>ISO/IEC 17799: 14.1.3</reference>
                        <reference>NIST 800-26: 8.1.1, 14.1.1</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DCID 6/3: 8.B.7.c</reference>
                  </Group>
            </Group>
            <Group id="maintenance" hidden="true">
                  <title>Applicable 800-53 Maintenance</title>
                  <Group id="MA-1" hidden="true">
                        <title>System Maintenance Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 10</reference>
                        <reference>DOD 8500.2: PRMP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.4.e(5); 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="MA-2" hidden="true">
                        <title>Periodic Maintenance</title>
                        <reference>ISO/IEC 17799: 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3, 10.2.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5), 8.B.8.c</reference>
                  </Group>
                  <Group id="MA-3" hidden="true">
                        <title>Maintenance Tools</title>
                        <reference>NIST 800-26: 10.1.3, 11.2.4</reference>
                        <reference>DCID 6/3: 6.B.3.a(5), 8.B.8.c(4), 8.B.8.c(5)</reference>
                  </Group>
                  <Group id="MA-4" hidden="true">
                        <title>Remote Maintenance</title>
                        <reference>ISO/IEC 17799: 11.4.4</reference>
                        <reference>NIST 800-26: 10.1.1, 17.1.1</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: EBRP-1</reference>
                        <reference>DCID 6/3: 8.B.8.d</reference>
                  </Group>
                  <Group id="MA-5" hidden="true">
                        <title>Maintenance Personnel</title>
                        <reference>ISO/IEC 17799: 6.2.3, 9.2.4</reference>
                        <reference>NIST 800-26: 10.1.1, 10.1.3</reference>
                        <reference>GAO FISCAM: SS-3.1</reference>
                        <reference>DOD 8500.2: PRMP-1</reference>
                        <reference>DCID 6/3: 8.B.8.a</reference>
                  </Group>
                  <Group id="MA-6" hidden="true">
                        <title>Timely Maintenance</title>
                        <reference>NIST 800-26: 9.1.2</reference>
                        <reference>GAO FISCAM: SC-1.2</reference>
                        <reference>DOD 8500.2: COMS-1, COSP-1</reference>
                        <reference>DCID 6/3: 6.B.2.a(5)</reference>
                  </Group>
            </Group>
            <Group id="media_protection" hidden="true">
                  <title>Applicable 800-53 Media Protection</title>
                  <Group id="MP-1" hidden="true">
                        <title>Media Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.1.1, 10.7, 15.1.1, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2</reference>
                        <reference>DOD 8500.2: PESP-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a Manual: 2.B.6.c(7); 8.B.2</reference>
                  </Group>
                  <Group id="MP-2" hidden="true">
                        <title>Media Access</title>
                        <reference>ISO/IEC 17799: 10.7.3</reference>
                        <reference>NIST 800-26: 8.2.1, 8.2.2, 8.2.3, 8.2.6, 8.2.7</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(1), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-3" hidden="true">
                        <title>Media Labeling</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.7.3, 10.8.2, 15.1.3</reference>
                        <reference>NIST 800-26: 8.2.5, 8.2.6, 10.2.9</reference>
                        <reference>DOD 8500.2: ECML-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 8.B.2.a, 8.B.2.c</reference>
                  </Group>
                  <Group id="MP-4" hidden="true">
                        <title>Media Storage</title>
                        <reference>ISO/IEC 17799: 10.7.1, 10.7.2, 10.7.3, 10.7.4, 15.1.3</reference>
                        <reference>NIST 800-26: 7.1.4, 8.2.1, 8.2.2, 8.2.9, 10.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PESS-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(4), 4.B.1.a(7)</reference>
                  </Group>
                  <Group id="MP-5" hidden="true">
                        <title>Media Transport</title>
                        <reference>ISO/IEC 17799: 10.8.3</reference>
                        <reference>NIST 800-26: 8.2.2, 8.2.4</reference>
                        <reference>DCID 6/3: 2.B.9.b(4)</reference>
                  </Group>
                  <Group id="MP-6" hidden="true">
                        <title>Media Sanitization</title>
                        <reference>ISO/IEC 17799: 9.2.6, 10.7.1, 10.7.2</reference>
                        <reference>NIST 800-26: 3.2.11, 3.2.12, 3.2.13, 8.2.8, 8.2.9, 8.2.10</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: PECS-1, PEDD-1</reference>
                        <reference>DCID 6/3: 8.B.5, 2.B.9.b(4), 8.B.5.a(4), 8.B.5.d, 8.B.5.e</reference>
                  </Group>
                  <Group id="MP-7" hidden="true">
                        <title>Media Destruction and Disposal</title>
                        <reference>ISO/IEC 17799: </reference>
                        <reference>NIST 800-26: </reference>
                        <reference>GAO FISCAM: </reference>
                        <reference>DOD 8500.2: </reference>
                        <reference>DCID 6/3: </reference>
                  </Group>
            </Group>
            <Group id="physical_and_environmental_protection" hidden="true">
                  <title>Applicable 800-53 Physical and Environmental Protection</title>
                  <Group id="PE-1" hidden="true">
                        <title>Physical and Environmental Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 7</reference>
                        <reference>DOD 8500.2: PETN-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.D</reference>
                  </Group>
                  <Group id="PE-2" hidden="true">
                        <title>Physical Access Authorizations</title>
                        <reference>ISO/IEC 17799: 9.1.2, 9.1.6</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PECF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.E</reference>
                  </Group>
                  <Group id="PE-3" hidden="true">
                        <title>Physical Access Control</title>
                        <reference>ISO/IEC 17799: 9.1.1, 9.1.2, 9.1.5, 9.1.6, 10.5.1</reference>
                        <reference>NIST 800-26: 7.1.1, 7.1.2, 7.1.5, 7.1.6, 7.1.8</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEPF-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-4" hidden="true">
                        <title>Access Control for Transmission Medium</title>
                        <reference>ISO/IEC 17799: 9.2.3</reference>
                        <reference>NIST 800-26: 7.2.2, 16.2.9</reference>
                        <reference>DCID 6/3: 8.D.2, 4.B.1.a(8)</reference>
                  </Group>
                  <Group id="PE-5" hidden="true">
                        <title>Access Control for Display Medium</title>
                        <reference>ISO/IEC 17799: 9.1.2, 11.3.3</reference>
                        <reference>NIST 800-26: 7.2.1</reference>
                        <reference>DOD 8500.2: PEDI-1, PEPF-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-6" hidden="true">
                        <title>Monitoring Physical Access</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(1), 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-7" hidden="true">
                        <title>Visitor Control</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.7, 7.1.11</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DOD 8500.2: PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-8" hidden="true">
                        <title>Access Records</title>
                        <reference>ISO/IEC 17799: 9.1.2</reference>
                        <reference>NIST 800-26: 7.1.9</reference>
                        <reference>GAO FISCAM: AC-4</reference>
                        <reference>DOD 8500.2: PEPF-2, PEVC-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2, 8.E</reference>
                  </Group>
                  <Group id="PE-9" hidden="true">
                        <title>Power Equipment and Power Cabling</title>
                        <reference>ISO/IEC 17799: 9.2.2, 9.2.3</reference>
                        <reference>NIST 800-26: 7.1.16</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-10" hidden="true">
                        <title>Emergency Shutoff</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEMS-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-11" hidden="true">
                        <title>Emergency Power</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>NIST 800-26: 7.1.18</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: COPS-1, COPS-2, COPS-3</reference>
                        <reference>DCID 6/3: 6.B.2.a(6), 6.B.2.a(7)</reference>
                  </Group>
                  <Group id="PE-12" hidden="true">
                        <title>Emergency Lighting</title>
                        <reference>ISO/IEC 17799: 9.2.2</reference>
                        <reference>DOD 8500.2: PEEL-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-13" hidden="true">
                        <title>Fire Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.12</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEFD-1, PEFS-1</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-14" hidden="true">
                        <title>Temperature and Humidity Controls</title>
                        <reference>ISO/IEC 17799: 9.2.1, 10.5.1, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.14, 7.1.15</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DOD 8500.2: PEHC-1, PETC-1</reference>
                        <reference>DCID 6/3: 8.D.2</reference>
                  </Group>
                  <Group id="PE-15" hidden="true">
                        <title>Water Damage Protection</title>
                        <reference>ISO/IEC 17799: 9.1.4, 9.2.1</reference>
                        <reference>NIST 800-26: 7.1.17</reference>
                        <reference>GAO FISCAM: SC-2.2</reference>
                        <reference>DCID 6/3: 8.C.2.a, 8.D.2</reference>
                  </Group>
                  <Group id="PE-16" hidden="true">
                        <title>Delivery and Removal</title>
                        <reference>ISO/IEC 17799: 9.1.6, 9.2.7, 10.7.1</reference>
                        <reference>NIST 800-26: 7.1.3</reference>
                        <reference>GAO FISCAM: AC-3.1</reference>
                        <reference>DCID 6/3: 8.B.5.e</reference>
                  </Group>
                  <Group id="PE-17" hidden="true">
                        <title>Alternate Work Site</title>
                        <reference>ISO/IEC 17799: 11.7.2</reference>
                        <reference>DOD 8500.2: EBRU-1</reference>
                  </Group>
                  <Group id="PE-18" hidden="true">
                        <title>Location of Information System Components</title>
                        <reference>ISO/IEC 17799: 9.2.1</reference>
                  </Group>
                  <Group id="PE-19" hidden="true">
                        <title>Information Leakage</title>
                  </Group>
            </Group>
            <Group id="planning" hidden="true">
                  <title>Applicable 800-53 Planning</title>
                  <Group id="PL-1" hidden="true">
                        <title>Security Planning Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 6.1, 15.1.1</reference>
                        <reference>NIST 800-26: 5</reference>
                        <reference>DOD 8500.2: DCAR-1, E3.4.6</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="PL-2" hidden="true">
                        <title>System Security Plan</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 4.1.5, 5.1.1, 5.1.2, 12.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: DCSD-1</reference>
                        <reference>DCID 6/3: 1.F.6, 2.B.6.c(3), 2.B.7.c(5), 9.E.2.a(1)(d), 9.F.2.a, Appendix C</reference>
                  </Group>
                  <Group id="PL-3" hidden="true">
                        <title>System Security Plan Update</title>
                        <reference>ISO/IEC 17799: 6.1</reference>
                        <reference>NIST 800-26: 3.2.10, 5.2.1</reference>
                        <reference>GAO FISCAM: SP-2.1</reference>
                        <reference>DOD 8500.2: 5.7.5</reference>
                        <reference>DCID 6/3: 2.B.7.c(5)</reference>
                  </Group>
                  <Group id="PL-4" hidden="true">
                        <title>Rules of Behavior</title>
                        <reference>ISO/IEC 17799: 7.1.3, 8.1.3, 15.1.5</reference>
                        <reference>NIST 800-26: 4.1.3, 13.1.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 2.B.9.b</reference>
                  </Group>
                  <Group id="PL-5" hidden="true">
                        <title>Privacy Impact Assessment</title>
                        <reference>ISO/IEC 17799: 15.1.4</reference>
                        <reference>DCID 6/3: DCID: B.3.a; Manual: 8.B.9</reference>
                  </Group>
                  <Group id="PL-6" hidden="true">
                        <title>Security-Related Activity Planning</title>
                        <reference>ISO/IEC 17799: 15.3.1</reference>
                  </Group>
            </Group>
            <Group id="personnel_security" hidden="true">
                  <title>Applicable 800-53 Personnel Security</title>
                  <Group id="PS-1" hidden="true">
                        <title>Personnel Security Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 8.1.1, 15.1.1</reference>
                        <reference>NIST 800-26: 6</reference>
                        <reference>DOD 8500.2: PRRB-1, DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5); 8.E</reference>
                  </Group>
                  <Group id="PS-2" hidden="true">
                        <title>Position Categorization</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.1.1, 6.1.2</reference>
                        <reference>GAO FISCAM: SD-1.2</reference>
                        <reference>DCID 6/3: 8.E</reference>
                  </Group>
                  <Group id="PS-3" hidden="true">
                        <title>Personnel Screening</title>
                        <reference>ISO/IEC 17799: 8.1.2</reference>
                        <reference>NIST 800-26: 6.2.1, 6.2.3</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRAS-1</reference>
                        <reference>DCID 6/3: 2.B.7.c(2), 2.B.8.b(5), 8.E</reference>
                  </Group>
                  <Group id="PS-4" hidden="true">
                        <title>Personnel Termination</title>
                        <reference>ISO/IEC 17799: 8.1.3, 8.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6), 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
                  <Group id="PS-5" hidden="true">
                        <title>Personnel Transfer</title>
                        <reference>ISO/IEC 17799: 8.3.1, 8.3.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.7</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.12.7</reference>
                        <reference>DCID 6/3: 2.B.9.b(6)</reference>
                  </Group>
                  <Group id="PS-6" hidden="true">
                        <title>Access Agreements</title>
                        <reference>ISO/IEC 17799: 6.1.5, 8.1.3</reference>
                        <reference>NIST 800-26: 6.1.5, 6.2.2</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 1.E.2, 8.E</reference>
                  </Group>
                  <Group id="PS-7" hidden="true">
                        <title>Third-Party Personnel Security</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 8.1.1, 8.1.2, 8.1.3, 8.2.1, 8.2.2, 11.2.1</reference>
                        <reference>GAO FISCAM: SP-4.1</reference>
                        <reference>DOD 8500.2: 5.7.10</reference>
                        <reference>DCID 6/3: 1.A.1, 8.D, 8.E</reference>
                  </Group>
                  <Group id="PS-8" hidden="true">
                        <title>Personnel Sanctions</title>
                        <reference>ISO/IEC 17799: 8.2.3, 11.2.1</reference>
                        <reference>NIST 800-26: 6.1.5</reference>
                        <reference>DOD 8500.2: PRRB-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(3)(e), 8.E</reference>
                  </Group>
            </Group>
            <Group id="risk_assessment" hidden="true">
                  <title>Applicable 800-53 Risk Assessment</title>
                  <Group id="RA-1" hidden="true">
                        <title>Risk Assessment Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 4.1, 15.1.1</reference>
                        <reference>NIST 800-26: 1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.3.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="RA-2" hidden="true">
                        <title>Security Categorization</title>
                        <reference>ISO/IEC 17799: 7.2.1</reference>
                        <reference>NIST 800-26: 1.1.3, 3.1.1</reference>
                        <reference>GAO FISCAM: SP-1, AC-1.1, AC-1.2</reference>
                        <reference>DOD 8500.2: E3.4.2</reference>
                        <reference>DCID 6/3: 3.C, 3.D, 9.E.2.a(1)(a), 9.E.2.a(1)(d)</reference>
                  </Group>
                  <Group id="RA-3" hidden="true">
                        <title>Risk Assessment</title>
                        <reference>ISO/IEC 17799: 4, 4.1, 4.2, 6.2.1, 10.10.2, 10.10.5, 12.5.1, 12.6.1, 14.1.1, 14.1.2</reference>
                        <reference>NIST 800-26: 1.1.2, 1.1.4, 1.1.5, 1.1.6, 1.2.1, 1.2.2, 1.2.3, 3.1.7, 3.1.8, 4.1.7, 7.1.13, 7.1.19, 12.2.4</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCDS-1, DCII-1, E3.3.10</reference>
                        <reference>DCID 6/3: 9.B</reference>
                  </Group>
                  <Group id="RA-4" hidden="true">
                        <title>Risk Assessment Update</title>
                        <reference>ISO/IEC 17799: 4.1</reference>
                        <reference>NIST 800-26: 1.1.2, 4.1.2</reference>
                        <reference>GAO FISCAM: SP-1</reference>
                        <reference>DOD 8500.2: DCAR-1, DCII-1</reference>
                        <reference>DCID 6/3: 9.B.4.f, 9.D.1.d</reference>
                  </Group>
                  <Group id="RA-5" hidden="true">
                        <title>Vulnerability Scanning</title>
                        <reference>ISO/IEC 17799: 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 14.2.1</reference>
                        <reference>DOD 8500.2: ECMT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 4.B.3.a(8)(b), 4.B.3.b(6)(b), 9.B.4.e</reference>
                  </Group>
            </Group>
            <Group id="system_and_services_acquisition" hidden="true">
                  <title>Applicable 800-53 System and Services Acquisition</title>
                  <Group id="SA-1" hidden="true">
                        <title>System and Services Acquisition Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 12.1, 15.1.1</reference>
                        <reference>NIST 800-26: 3</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SA-2" hidden="true">
                        <title>Allocation of Resources</title>
                        <reference>ISO/IEC 17799: 10.3.1</reference>
                        <reference>NIST 800-26: 3.1.2, 3.1.3, 3.1.5, 5.1.3</reference>
                        <reference>DOD 8500.2: DCPB-1, E3.3.4</reference>
                        <reference>DCID 6/3: DCID: C.2.a, Manual: 2.B.4.e(8)</reference>
                  </Group>
                  <Group id="SA-3" hidden="true">
                        <title>Life Cycle Support</title>
                        <reference>NIST 800-26: 3.1</reference>
                        <reference>DOD 8500.2: 5.8.1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 9.E.2</reference>
                  </Group>
                  <Group id="SA-4" hidden="true">
                        <title>Acquisitions</title>
                        <reference>ISO/IEC 17799: 12.1.1</reference>
                        <reference>NIST 800-26: 3.1.6, 3.1.7, 3.1.10, 3.1.11, 3.1.12</reference>
                        <reference>DOD 8500.2: DCAS-1, DCDS-1, DCIT-1, DCMC-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a; C.2.a, Manual: 9.B.4</reference>
                  </Group>
                  <Group id="SA-5" hidden="true">
                        <title>Information System Documentation</title>
                        <reference>ISO/IEC 17799: 10.7.4</reference>
                        <reference>NIST 800-26: 3.2.3, 3.2.4, 3.2.8, 12.1.1, 12.1.2, 12.1.3, 12.1.6, 12.1.7</reference>
                        <reference>GAO FISCAM: CC-2.1</reference>
                        <reference>DOD 8500.2: DCCS-1, DCHW-1, DCID-1, DCSD-1, DCSW-1, ECND-1, DCFA-1</reference>
                        <reference>DCID 6/3: 4.B.2.b(2), 4.B.2.b(3), 4.B.4.b(4), 9.C.3</reference>
                  </Group>
                  <Group id="SA-6" hidden="true">
                        <title>Software Usage Restrictions</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10, 10.2.13</reference>
                        <reference>GAO FISCAM: SS-3.2, SP-2.1</reference>
                        <reference>DOD 8500.2: DCPD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-7" hidden="true">
                        <title>User Installed Software</title>
                        <reference>ISO/IEC 17799: 15.1.2</reference>
                        <reference>NIST 800-26: 10.2.10</reference>
                        <reference>GAO FISCAM: SS-3.2</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SA-8" hidden="true">
                        <title>Security Engineering Principles</title>
                        <reference>ISO/IEC 17799: 12.1</reference>
                        <reference>NIST 800-26: 3.2.1</reference>
                        <reference>DOD 8500.2: DCBP-1, DCCS-1, E3.4.4</reference>
                        <reference>DCID 6/3: 1.H.1</reference>
                  </Group>
                  <Group id="SA-9" hidden="true">
                        <title>Outsourced Information System Services</title>
                        <reference>ISO/IEC 17799: 6.2.1, 6.2.3, 10.2.1, 10.2.2, 10.6.2</reference>
                        <reference>NIST 800-26: 12.2.3</reference>
                        <reference>DOD 8500.2: DCDS-1, DCID-1 DCIT-1, DCPP-1</reference>
                        <reference>DCID 6/3: 1.B.1, 8.C.2, 8.E</reference>
                  </Group>
                  <Group id="SA-10" hidden="true">
                        <title>Developer Configuration Management</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-3</reference>
                        <reference>DCID 6/3: 4.B.4.b(4), 8.C.2.a</reference>
                  </Group>
                  <Group id="SA-11" hidden="true">
                        <title>Developer Security Testing</title>
                        <reference>ISO/IEC 17799: 12.5.1, 12.5.2</reference>
                        <reference>NIST 800-26: 3.2.1, 3.2.2, 10.2.5, 12.1.5</reference>
                        <reference>GAO FISCAM: SS-3.1, CC-2.1</reference>
                        <reference>DOD 8500.2: E3.4.4</reference>
                        <reference>DCID 6/3: 4.B.4.b(4)</reference>
                  </Group>
            </Group>
            <Group id="system_and_communications_protection" hidden="true">
                  <title>Applicable 800-53 System and Communication Protection</title>
                  <Group id="SC-1" hidden="true">
                        <title>System and Communications Protection Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 10.8.1, 15.1.1</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5)</reference>
                  </Group>
                  <Group id="SC-2" hidden="true">
                        <title>Application Partitioning</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCPA-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-3" hidden="true">
                        <title>Security Function Isolation</title>
                        <reference>ISO/IEC 17799: 11.4.5</reference>
                        <reference>DOD 8500.2: DCSP-1</reference>
                        <reference>DCID 6/3: 4.B.3.b(6)(a), 4.B.4.b(8), 5.B.3.b(1), 5.B.3.b(2)</reference>
                  </Group>
                  <Group id="SC-4" hidden="true">
                        <title>Information Remnants</title>
                        <reference>ISO/IEC 17799: 10.8.1</reference>
                        <reference>GAO FISCAM: AC-3.4</reference>
                        <reference>DOD 8500.2: ECRC-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(14)</reference>
                  </Group>
                  <Group id="SC-5" hidden="true">
                        <title>Denial of Service Protection</title>
                        <reference>ISO/IEC 17799: 10.8.4, 13.2.1</reference>
                        <reference>DCID 6/3: 6.B.3.a(6)</reference>
                  </Group>
                  <Group id="SC-6" hidden="true">
                        <title>Resource Priority</title>
                        <reference>DCID 6/3: 6.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-7" hidden="true">
                        <title>Boundary Protection</title>
                        <reference>ISO/IEC 17799: 11.4.6</reference>
                        <reference>NIST 800-26: 16.2.2, 16.2.7, 16.2.9, 16.2.10, 16.2.11, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: COEB-1, EBBD-1, ECIM-1, ECVI-1</reference>
                        <reference>DCID 6/3: 4.B.4.a(27), 5.B.3.a(11)(b), 7.A.3, 7.B, 7.C, 7.D</reference>
                  </Group>
                  <Group id="SC-8" hidden="true">
                        <title>Transmission Integrity</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4, 11.2.9, 16.2.14</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-1</reference>
                        <reference>DCID 6/3: 5.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-9" hidden="true">
                        <title>Transmission Confidentiality</title>
                        <reference>ISO/IEC 17799: 10.6.1, 10.8.1, 10.9.1</reference>
                        <reference>DOD 8500.2: ECCT-1</reference>
                        <reference>DCID 6/3: 4.B.1.a(8)(a)</reference>
                  </Group>
                  <Group id="SC-10" hidden="true">
                        <title>Network Disconnect</title>
                        <reference>ISO/IEC 17799: 11.5.6</reference>
                        <reference>NIST 800-26: 16.2.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DCID 6/3: 4.B.2.a(17)</reference>
                  </Group>
                  <Group id="SC-11" hidden="true">
                        <title>Trusted Path</title>
                        <reference>ISO/IEC 17799: 10.9.2</reference>
                        <reference>NIST 800-26: 16.2.7</reference>
                        <reference>DCID 6/3: 4.B.4.a(14)</reference>
                  </Group>
                  <Group id="SC-12" hidden="true">
                        <title>Cryptographic Key Establishment and Mgmt.</title>
                        <reference>ISO/IEC 17799: 12.3.1, 12.3.2</reference>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 1.G</reference>
                  </Group>
                  <Group id="SC-13" hidden="true">
                        <title>Use of Validated Cryptography</title>
                        <reference>NIST 800-26: 16.1.7, 16.1.8</reference>
                        <reference>DOD 8500.2: IAKM-1, IATS-1</reference>
                        <reference>DCID 6/3: 1.G.1</reference>
                  </Group>
                  <Group id="SC-14" hidden="true">
                        <title>Public Access Protections</title>
                        <reference>ISO/IEC 17799: 10.7.4, 10.9.3</reference>
                        <reference>DOD 8500.2: EBPW-1</reference>
                  </Group>
                  <Group id="SC-15" hidden="true">
                        <title>Collaborative Computing</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: 7.G</reference>
                  </Group>
                  <Group id="SC-16" hidden="true">
                        <title>Transmission of Security Parameters</title>
                        <reference>ISO/IEC 17799: 7.2.2, 10.8.2, 10.9.2</reference>
                        <reference>NIST 800-26: 16.1.6</reference>
                        <reference>GAO FISCAM: AC-3.2</reference>
                        <reference>DOD 8500.2: ECTM-2</reference>
                        <reference>DCID 6/3: 4.B.1.a(3)</reference>
                  </Group>
                  <Group id="SC-17" hidden="true">
                        <title>Public Key Infrastructure Certificates</title>
                        <reference>ISO/IEC 17799: 12.3.2</reference>
                        <reference>DOD 8500.2: IAKM-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 4.B.3.a(11)</reference>
                  </Group>
                  <Group id="SC-18" hidden="true">
                        <title>Mobile Code</title>
                        <reference>ISO/IEC 17799: 10.4.1, 10.4.2</reference>
                        <reference>DOD 8500.2: DCMC-1</reference>
                        <reference>DCID 6/3: 2.B.4.e(5), 7.E</reference>
                  </Group>
                  <Group id="SC-19" hidden="true">
                        <title>Voice Over Internet Protocol</title>
                        <reference>DOD 8500.2: ECVI-1</reference>
                        <reference>DCID 6/3: DCID 6/3 2.B.4.d, 9.D.1.a</reference>
                  </Group>
                  <Group id="SC-20" hidden="true">
                        <title>Secure Name Address Resolution Service (Authoritative Source)</title>
                  </Group>
                  <Group id="SC-21" hidden="true">
                        <title>Secure Name Address Resolution Service (Resolution)</title>
                  </Group>
                  <Group id="SC-22" hidden="true">
                        <title>Architecture and Provisioning for Name/Address Resolution Service</title>
                  </Group>
                  <Group id="SC-23" hidden="true">
                        <title>Session Authenticity</title>
                  </Group>
            </Group>
            <Group id="system_and_information_integrity" hidden="true">
                  <title>Applicable 800-53 System and Information Integrity</title>
                  <Group id="SI-1" hidden="true">
                        <title>System and Information Integrity Policy and Procedures</title>
                        <reference>ISO/IEC 17799: 15.1.1</reference>
                        <reference>NIST 800-26: 11</reference>
                        <reference>DOD 8500.2: DCAR-1</reference>
                        <reference>DCID 6/3: DCID: B.2.a, Manual: 2.B.4.e(5), 5.B.1.b(1), 5.B.2.a(5)(a)(1)</reference>
                  </Group>
                  <Group id="SI-2" hidden="true">
                        <title>Flaw Remediation</title>
                        <reference>ISO/IEC 17799: 10.10.5, 12.4.1, 12.5.1, 12.5.2, 12.6.1</reference>
                        <reference>NIST 800-26: 10.3.2, 11.1.1, 11.1.2, 11.2.2, 11.2.7</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSQ-1, DCCT-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.2.a(5)(a)(3), 6.B.2.a(5)</reference>
                  </Group>
                  <Group id="SI-3" hidden="true">
                        <title>Malicious Code Protection</title>
                        <reference>ISO/IEC 17799: 10.4.1</reference>
                        <reference>NIST 800-26: 11.1.1, 11.1.2</reference>
                        <reference>DOD 8500.2: ECVP-1, VIVM-1</reference>
                        <reference>DCID 6/3: 5.B.1.a(4), 7.B.4.b(1)</reference>
                  </Group>
                  <Group id="SI-4" hidden="true">
                        <title>Information System Monitoring Tools and Techniques</title>
                        <reference>ISO/IEC 17799: 10.6.2, 10.10.1, 10.10.2, 10.10.4</reference>
                        <reference>NIST 800-26: 11.2.5, 11.2.6</reference>
                        <reference>DOD 8500.2: EBBD-1, EBVC-1, ECID-1</reference>
                        <reference>DCID 6/3: 4.B.2.a(5)(b), 4.B.3.a(8)(b), 6.B.3.a(8)</reference>
                  </Group>
                  <Group id="SI-5" hidden="true">
                        <title>Security Alerts and Advisories</title>
                        <reference>ISO/IEC 17799: 6.1.7, 10.4.1</reference>
                        <reference>NIST 800-26: 14.1.1, 14.1.2, 14.1.5</reference>
                        <reference>GAO FISCAM: SP-3.4</reference>
                        <reference>DOD 8500.2: VIVM-1</reference>
                        <reference>DCID 6/3: 8.B.7</reference>
                  </Group>
                  <Group id="SI-6" hidden="true">
                        <title>Security Functionality Verification</title>
                        <reference>NIST 800-26: 11.2.1, 11.2.2</reference>
                        <reference>GAO FISCAM: SS-2.2</reference>
                        <reference>DOD 8500.2: DCSS-1</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.2.b(2)</reference>
                  </Group>
                  <Group id="SI-7" hidden="true">
                        <title>Software and Information Integrity</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.4</reference>
                        <reference>NIST 800-26: 11.2.1, 11.2.4</reference>
                        <reference>DOD 8500.2: ECSD-2</reference>
                        <reference>DCID 6/3: 4.B.1.c(2), 5.B.1.a(3), 5.B.2.a(6)</reference>
                  </Group>
                  <Group id="SI-8" hidden="true">
                        <title>Spam Protection</title>
                        <reference>DCID 6/3: 5.B.1.a(4)</reference>
                  </Group>
                  <Group id="SI-9" hidden="true">
                        <title>Information Input Restrictions</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2</reference>
                        <reference>GAO FISCAM: SD-1</reference>
                        <reference>DCID 6/3: 2.B.9.b(11)</reference>
                  </Group>
                  <Group id="SI-10" hidden="true">
                        <title>Information Accuracy, Completeness, Validity, and Authenticity</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.1, 12.2.2</reference>
                        <reference>DCID 6/3: 7.B.2.h, 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-11" hidden="true">
                        <title>Error Handling</title>
                        <reference>ISO/IEC 17799: 12.2.1, 12.2.2, 12.2.3, 12.2.4</reference>
                        <reference>DCID 6/3: 2.B.4.d</reference>
                  </Group>
                  <Group id="SI-12" hidden="true">
                        <title>Information Output Handling and Retention</title>
                        <reference>ISO/IEC 17799: 10.7.3, 12.2.4</reference>
                        <reference>DOD 8500.2: PESP-1</reference>
                        <reference>DCID 6/3: 2.B.4.d, 8.B.9, 8.G</reference>
                  </Group>
            </Group>
      </Group>
      <!-- ==================================================================================================== -->
      <!-- =================================  XP FIREWALL SECURITY GUIDANCE  ================================== -->
      <!-- ==================================================================================================== -->
      <!--                                                                                                      -->
      <!-- The following groups represent different types of guidance for Microsoft Windows XP Firewall.  For   -->
      <!-- specific recommendations from individual agencies (NIST, NSA, DISA) please refer to the XCCDF        -->
      <!-- profiles above that enable certain rules and provided tailored values.                               -->
      <!--                                                                                                      -->
      <!-- **************************************************************************************************** -->
      <!-- ***  1 - Introduction                                                                            *** -->
      <!-- **************************************************************************************************** -->
      <Group id="introduction">
            <title>Introduction</title>
            <description>This guide has been created to assist federal agencies in effectively securing systems with Microsoft Windows XP Firewall based on OMB Federal Desktop Core Configuration recommendations.<xhtml:br/><xhtml:br/>Under the direction of OMB and in collaboration with DHS, DISA, NSA, USAF, and Microsoft, NIST has provided the following baseline to help agencies test, implement, and deploy the Microsoft Windows XP Firewall Federal Desktop Core Configuration (FDCC) baseline.  The Federal Desktop Core Configuration (FDCC) is an OMB-mandated security configuration.<xhtml:br/><xhtml:br/>Please refer to the FDCC home page for additional information.  http://fdcc.nist.gov</description>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  2 - FDCC Security Settings                                                                  *** -->
      <!-- **************************************************************************************************** -->
      <!--                                                                                                      -->
      <!-- none                                                                                                 -->
      <!--                                                                                                      -->
      <!-- **************************************************************************************************** -->
      <!-- ***  3 - FDCC Other Settings                                                                     *** -->
      <!-- **************************************************************************************************** -->
      <Group id="fdcc_other_settings">
            <title>FDCC Other Settings</title>
            <description>FDCC has identified the following additional controls that must be checked in order to verify compliance.</description>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Windows Firewall Domain Profile                                                           -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="windows_firewall_domain_profile">
                  <title>Windows Firewall - Domain Profile</title>
                  <description>The Domain Profile applies when a computer is connected to a network and authenticates to a domain controller in the domain to which the computer belongs.</description>
                  <Value id="allow_file_print_sharing_exceptions_domain_profile_var" operator="equals"
                        type="number">
                        <title>Allow file and print sharing exception</title>
                        <description>This setting allows file and printer sharing by configuring Windows Firewall to open UDP ports 137 and 138 and TCP ports 139 and 445. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive print jobs and requests for access to shared files. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from sharing files and printers. Because the computers in your environment running Windows XP will not normally be sharing files and printers, this appendix recommends you configure this setting as Disabled in all environments. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="allow_local_port_exceptions_domain_profile_var" operator="equals"
                        type="number">
                        <title>Allow local port exceptions</title>
                        <description>The Windows Firewall: Allow local port exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local port exceptions list. Windows Firewall can use two port exceptions lists; the other is defined by the Windows Firewall: Define port exceptions policy setting. If you enable this policy setting, the Windows Firewall component in Control Panel allows administrators to define a local port exceptions list. If you disable this policy setting, the Windows Firewall component in Control Panel does not allow administrators to define such a list. Typically, local administrators are not authorized to override organizational policy and establish their own port exceptions list in enterprise or high security environments. For that reason, this appendix recommends configuring this option as Disabled.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="allow_local_program_exceptions_domain_profile_var" operator="equals"
                        type="number">
                        <title>Allow local program exceptions</title>
                        <description>The Windows Firewall: Allow local program exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local program exceptions list. Disabling this policy setting does not allow administrators to define a local program exceptions list, and ensures that program exceptions only come from Group Policy. Setting this policy to Enabled allows local administrators to use Control Panel to define program exceptions locally. For enterprise client computers, there may be conditions that justify having the client define local program exceptions. These conditions may include applications that were not analyzed when creating the organization's firewall policy or new applications that require nonstandard port configuration. In those cases, you may choose to enable this setting, recognizing that the attack surface of the affected computers is increased.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="allow_logging_log_dropped_packets_domain_profile_var" operator="equals"
                        type="number">
                        <title>Allow Logging: Log Dropped Packets</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="allow_logging_log_successful_connections_domain_profile_var"
                        operator="equals"
                        type="number">
                        <title>Allow Logging: Log Successful Connections</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="allow_logging_log_size_domain_profile_var" operator="equals" type="number">
                        <title>Allow Logging: Log Size</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <value>1</value>
                        <value selector="4096_kb">4096</value>
                        <value selector="16384_kb">16384</value>
                  </Value>
                  <Value id="allow_logging_log_path_domain_profile_var" operator="equals" type="string">
                        <title>Allow Logging: Log Path</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <value>%systemroot%\DomainFW.log</value>
                        <value selector="systemroot_domainfwlog">%systemroot%\DomainFW.log</value>
                  </Value>
                  <Value id="allow_remote_administration_exceptions_domain_profile_var"
                        operator="equals"
                        type="number">
                        <title>Allow remote administration exceptions</title>
                        <description>Many organizations take advantage of remote computer administration in their daily operations. However, some attacks have exploited the ports typically used by remote administration programs; Windows Firewall can block these ports. To provide flexibility for remote administration, the Windows Firewall: Allow remote administration exception setting is available. Configuring this setting to Enabled allows the computer to receive the unsolicited incoming messages associated with remote administration on TCP ports 135 and 445. This policy setting also allows SVCHOST.EXE and LSASS.EXE to receive unsolicited incoming messages and allows hosted services to open additional dynamically-assigned ports, typically in the range of 1044 to 1044 but potentially anywhere from 1044 to 65535. Enabling this setting also requires you to specify the IP addresses or subnets from which these incoming messages are allowed. If you configure this policy setting as Disabled, Windows Firewall makes none of the described exceptions. This appendix recommends you enable this setting for enterprise computers if necessary, and to always disable the setting for high security computers. Computers in your environment should accept remote administration requests from as few computers as possible. To maximize the protection provided by the Windows Firewall, make sure to specify only the necessary IP addresses and subnets of computers used for remote administration. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="allow_remote_desktop_exceptions_domain_profile_var" operator="equals"
                        type="number">
                        <title>Allow Remote Desktop exception</title>
                        <description>Many organizations use Remote Desktop connections in their normal troubleshooting procedures or operations. However, some attacks have occurred that exploited the ports typically used by Remote Desktop. To provide flexibility for remote administration, the Windows Firewall: Allow Remote Desktop exception setting is available. Enabling this setting configures Windows Firewall to open TCP port 3389 for inbound connections. You must also specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks this port and prevents the computer from receiving Remote Desktop requests. If an administrator attempts to open this port by adding it to a local port exceptions list, Windows Firewall does not open the port. Some attacks can exploit an open port 3389. To maintain the enhanced management capabilities provided by Remote Desktop, you should configure this setting to Enabled and specify the IP addresses and subnets of the computers used for remote administration. Computers in your environment should accept Remote Desktop requests from as few computers as possible.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="allow_upnp_framework_exceptions_domain_profile_var" operator="equals"
                        type="number">
                        <title>Allow UPnP framework exception</title>
                        <description>The Windows Firewall: Allow UPnP framework exception setting allows a computer to receive unsolicited Plug and Play messages sent by network devices, such as routers with built-in firewalls. To receive these messages, Windows Firewall opens TCP port 2869 and UDP port 1900. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive Plug and Play messages. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from receiving Plug and Play messages.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <!-- Define Port Exceptions, not needed as just testing key existence -->
                  <Value id="prohibit_notifications_domain_profile_var" operator="equals" type="number">
                        <title>Prohibit notification</title>
                        <description>Windows Firewall can display notifications to users when a program requests that Windows Firewall add the program to the program exceptions list. This situation occurs when programs attempt to open a port and are not allowed to do so based on current Windows Firewall rules. The Windows Firewall: Prohibit notifications setting configures whether these settings are shown to the users. If you set this policy to Enabled, Windows Firewall prevents the display of these notifications. If you set it to Disabled, Windows Firewall allows the display of these notifications.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="prohibit_unicast_response_to_multicast_or_broadcast_requests_domain_profile_var"
                        operator="equals"
                        type="number">
                        <title>Prohibit unicast response to multicast or broadcast requests</title>
                        <description>The Windows Firewall: Prohibit unicast response to multicast or broadcast requests setting prevents a computer from receiving unicast responses to its outgoing multicast or broadcast messages. When this policy setting is enabled and the computer sends multicast or broadcast messages to other computers, Windows Firewall blocks the unicast responses sent by those other computers. When the setting is disabled and this computer sends a multicast or broadcast message to other computers, Windows Firewall waits up to three seconds for unicast responses from the other computers and then blocks all later responses. Typically, you would not want to receive unicast responses to multicast or broadcast messages. Such responses can indicate a denial of service (DoS) attack or an attacker attempting to probe a known live computer. This appendix recommends you configure this policy setting to Enabled to help prevent this type of attack. Note: This policy setting has no effect if the unicast message is a response to a Dynamic Host Configuration Protocol (DHCP) broadcast message sent by the computer. Windows Firewall always permits those DHCP unicast responses. However, this policy setting can interfere with the NetBIOS messages that detect name conflicts.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="protect_all_network_connections_domain_profile_var" operator="equals"
                        type="number">
                        <title>Protect all Network Connections</title>
                        <description>The Windows Firewall: Protect all network connections setting turns on Windows Firewall, which replaces Internet Connection Firewall on all computers that are running Windows XP SP2. This appendix recommends configuring this setting to Enabled to protect all network connections for computers in all environments. If this setting is configured as Disabled, Windows Firewall is turned off and all other settings for Windows Firewall are ignored. Note: If you enable this policy setting, Windows Firewall runs and ignores the Computer Configuration\Administrative Templates\Network\Network Connections\Prohibit use of Internet Connection Firewall on your DNS domain network policy setting.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Rule id="allow_file_print_sharing_exceptions_domain_profile" selected="false"
                        weight="10.0">
                        <title>Allow file and print sharing exception</title>
                        <description>This setting allows file and printer sharing by configuring Windows Firewall to open UDP ports 137 and 138 and TCP ports 139 and 445. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive print jobs and requests for access to shared files. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from sharing files and printers. Because the computers in your environment running Windows XP will not normally be sharing files and printers, this appendix recommends you configure this setting as Disabled in all environments. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3247-4</ident>
                        <ident system="cce.mitre.org/version/4">CCE-555</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50051"
                                    value-id="allow_file_print_sharing_exceptions_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5005"/>
                        </check>
                  </Rule>
                  <Rule id="allow_icm_exceptions_domain_profile" selected="false" weight="10.0">
                        <title>Allow ICMP exceptions (Allow inbound echo request and block everything else)</title>
                        <description>The Windows Firewall: Allow ICMP exceptions setting defines the set of Internet Control Message Protocol (ICMP) message types that Windows Firewall allows. Utilities can use ICMP messages to determine the status of other computers. For example, Ping uses the echo request message. If you set this policy setting to Enabled, you must specify which ICMP message types Windows Firewall allows the computer to send or receive. When you set this policy to Disabled, Windows Firewall blocks all unsolicited incoming ICMP message types and the listed outgoing ICMP message types. As a result, utilities that use the blocked ICMP messages will not be able to send those messages to or from the computer. Many attacker tools take advantage of computers that accept ICMP message types and use these messages to mount a variety of attacks. However, some applications require some ICMP messages in order to function properly. For that reason, this appendix recommends that you configure this setting to Disabled whenever possible. If your environment requires some ICMP messages to get through Windows Firewall, configure the setting with the appropriate message types. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3141-9</ident>
                        <ident system="cce.mitre.org/version/4">CCE-277</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5006"/>
                        </check>
                  </Rule>
                  <Rule id="allow_local_port_exceptions_domain_profile" selected="false" weight="10.0">
                        <title>Allow local port exceptions</title>
                        <description>The Windows Firewall: Allow local port exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local port exceptions list. Windows Firewall can use two port exceptions lists; the other is defined by the Windows Firewall: Define port exceptions policy setting. If you enable this policy setting, the Windows Firewall component in Control Panel allows administrators to define a local port exceptions list. If you disable this policy setting, the Windows Firewall component in Control Panel does not allow administrators to define such a list. Typically, local administrators are not authorized to override organizational policy and establish their own port exceptions list in enterprise or high security environments. For that reason, this appendix recommends configuring this option as Disabled.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3258-1</ident>
                        <ident system="cce.mitre.org/version/4">CCE-370</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50131"
                                    value-id="allow_local_port_exceptions_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5013"/>
                        </check>
                  </Rule>
                  <Rule id="allow_local_program_exceptions_domain_profile" selected="false"
                        weight="10.0">
                        <title>Allow local program exceptions</title>
                        <description>The Windows Firewall: Allow local program exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local program exceptions list. Disabling this policy setting does not allow administrators to define a local program exceptions list, and ensures that program exceptions only come from Group Policy. Setting this policy to Enabled allows local administrators to use Control Panel to define program exceptions locally. For enterprise client computers, there may be conditions that justify having the client define local program exceptions. These conditions may include applications that were not analyzed when creating the organization's firewall policy or new applications that require nonstandard port configuration. In those cases, you may choose to enable this setting, recognizing that the attack surface of the affected computers is increased.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-2828-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-502</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50031"
                                    value-id="allow_local_program_exceptions_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5003"/>
                        </check>
                  </Rule>
                  <Rule id="allow_logging_log_dropped_packets_domain_profile" selected="false"
                        weight="10.0">
                        <title>Allow Logging: Log Dropped Packets</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <requires idref="AU-2"/>
                        <requires idref="AU-3"/>
                        <requires idref="AU-4"/>
                        <requires idref="AU-8"/>
                        <ident system="http://cce.mitre.org">CCE-2965-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-251</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50141"
                                    value-id="allow_logging_log_dropped_packets_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5014"/>
                        </check>
                  </Rule>
                  <Rule id="allow_logging_log_successful_connections_domain_profile" selected="false"
                        weight="10.0">
                        <title>Allow Logging: Log Successful Connections</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <requires idref="AU-2"/>
                        <requires idref="AU-3"/>
                        <requires idref="AU-4"/>
                        <requires idref="AU-8"/>
                        <ident system="http://cce.mitre.org">CCE-3090-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-617</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50151"
                                    value-id="allow_logging_log_successful_connections_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5015"/>
                        </check>
                  </Rule>
                  <Rule id="allow_logging_log_size_domain_profile" selected="false" weight="10.0">
                        <title>Allow Logging: Log Size</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <requires idref="AU-2"/>
                        <requires idref="AU-3"/>
                        <requires idref="AU-4"/>
                        <requires idref="AU-8"/>
                        <ident system="http://cce.mitre.org">CCE-2958-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-57</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50161"
                                    value-id="allow_logging_log_size_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5016"/>
                        </check>
                  </Rule>
                  <Rule id="allow_logging_log_path_domain_profile" selected="false" weight="10.0">
                        <title>Allow Logging: Log Path</title>
                        <description>Allows Windows Firewall to record information about the unsolicited incoming messages that it receives. If you enable this policy setting, Windows Firewall writes the information to a log file. You must provide the name, location, and maximum size of the log file. The location can contain environment variables. You must also specify whether to record information about incoming messages that the firewall blocks (drops) and information about successful incoming and outgoing connections. Windows Firewall does not provide an option to log successful incoming messages. If you disable this policy setting, Windows Firewall does not record information in the log file. If you enable this policy setting, and Windows Firewall creates the log file and adds information, then upon disabling this policy setting, Windows Firewall leaves the log file intact. In the Windows Firewall component of Control Panel, the "Security Logging" settings are cleared and administrators cannot select them. If you do not configure this policy setting, Windows Firewall behaves as if the policy setting were disabled, except that administrators can choose whether to select the "Security Logging" settings.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <requires idref="AU-2"/>
                        <requires idref="AU-3"/>
                        <requires idref="AU-4"/>
                        <requires idref="AU-8"/>
                        <ident system="http://cce.mitre.org">CCE-2923-1</ident>
                        <ident system="cce.mitre.org/version/4">CCE-793</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50171"
                                    value-id="allow_logging_log_path_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5017"/>
                        </check>
                  </Rule>
                  <Rule id="allow_remote_administration_exceptions_domain_profile" selected="false"
                        weight="10.0">
                        <title>Allow remote administration exceptions</title>
                        <description>Many organizations take advantage of remote computer administration in their daily operations. However, some attacks have exploited the ports typically used by remote administration programs; Windows Firewall can block these ports. To provide flexibility for remote administration, the Windows Firewall: Allow remote administration exception setting is available. Configuring this setting to Enabled allows the computer to receive the unsolicited incoming messages associated with remote administration on TCP ports 135 and 445. This policy setting also allows SVCHOST.EXE and LSASS.EXE to receive unsolicited incoming messages and allows hosted services to open additional dynamically-assigned ports, typically in the range of 1044 to 1044 but potentially anywhere from 1044 to 65535. Enabling this setting also requires you to specify the IP addresses or subnets from which these incoming messages are allowed. If you configure this policy setting as Disabled, Windows Firewall makes none of the described exceptions. This appendix recommends you enable this setting for enterprise computers if necessary, and to always disable the setting for high security computers. Computers in your environment should accept remote administration requests from as few computers as possible. To maximize the protection provided by the Windows Firewall, make sure to specify only the necessary IP addresses and subnets of computers used for remote administration. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="AC-17"/>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-2476-0</ident>
                        <ident system="cce.mitre.org/version/4">CCE-771</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50041"
                                    value-id="allow_remote_administration_exceptions_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5004"/>
                        </check>
                  </Rule>
                  <Rule id="allow_remote_desktop_exceptions_domain_profile" selected="false"
                        weight="10.0">
                        <title>Allow Remote Desktop exception</title>
                        <description>Many organizations use Remote Desktop connections in their normal troubleshooting procedures or operations. However, some attacks have occurred that exploited the ports typically used by Remote Desktop. To provide flexibility for remote administration, the Windows Firewall: Allow Remote Desktop exception setting is available. Enabling this setting configures Windows Firewall to open TCP port 3389 for inbound connections. You must also specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks this port and prevents the computer from receiving Remote Desktop requests. If an administrator attempts to open this port by adding it to a local port exceptions list, Windows Firewall does not open the port. Some attacks can exploit an open port 3389. To maintain the enhanced management capabilities provided by Remote Desktop, you should configure this setting to Enabled and specify the IP addresses and subnets of the computers used for remote administration. Computers in your environment should accept Remote Desktop requests from as few computers as possible.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="AC-17"/>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3304-3</ident>
                        <ident system="cce.mitre.org/version/4">CCE-832</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50071"
                                    value-id="allow_remote_desktop_exceptions_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5007"/>
                        </check>
                  </Rule>
                  <Rule id="allow_upnp_framework_exceptions_domain_profile" selected="false"
                        weight="10.0">
                        <title>Allow UPnP framework exception</title>
                        <description>The Windows Firewall: Allow UPnP framework exception setting allows a computer to receive unsolicited Plug and Play messages sent by network devices, such as routers with built-in firewalls. To receive these messages, Windows Firewall opens TCP port 2869 and UDP port 1900. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive Plug and Play messages. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from receiving Plug and Play messages.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3176-5</ident>
                        <ident system="cce.mitre.org/version/4">CCE-590</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50081"
                                    value-id="allow_upnp_framework_exceptions_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5008"/>
                        </check>
                  </Rule>
                  <Rule id="define_port_exceptions_domain_profile" selected="false" weight="10.0">
                        <title>Define port exceptions</title>
                        <description>The Windows Firewall port exceptions list should be defined by Group Policy, which allows you to centrally manage and deploy your port exceptions and ensure that local administrators do not create less secure settings. The Windows Firewall: Define port exceptions policy setting allows you to centrally manage these settings. If you enable this policy setting, you can view and change the port exceptions list defined by Group Policy. To view and modify the port exceptions list, configure the policy setting to Enabled and then click the Show button. Note that if you type an invalid definition string, Windows Firewall adds it to the list without checking for errors, which means you can accidentally create multiple entries for the same port with conflicting Scope or Status values. If you disable this policy setting, the port exceptions list defined by Group Policy is deleted but other policy settings can continue to open or block ports. Also, if a local port exceptions list exists, it is ignored unless you enable the Windows Firewall: Allow local port exceptions policy setting. Environments with nonstandard applications that require specific ports to be open should consider deploying program exceptions. This appendix recommends enabling this setting and specifying a list of port exceptions only when program exceptions cannot be defined. Program exceptions allow the Windows Firewall to accept unsolicited network traffic only while the specified program is running, and port exceptions keep the specified ports open at all times. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions. </description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-2866-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-114</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:6008"/>
                        </check>
                  </Rule>
                  <Rule id="prohibit_notifications_domain_profile" selected="false" weight="10.0">
                        <title>Prohibit notification</title>
                        <description>Windows Firewall can display notifications to users when a program requests that Windows Firewall add the program to the program exceptions list. This situation occurs when programs attempt to open a port and are not allowed to do so based on current Windows Firewall rules. The Windows Firewall: Prohibit notifications setting configures whether these settings are shown to the users. If you set this policy to Enabled, Windows Firewall prevents the display of these notifications. If you set it to Disabled, Windows Firewall allows the display of these notifications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3198-9</ident>
                        <ident system="cce.mitre.org/version/4">CCE-762</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50091"
                                    value-id="prohibit_notifications_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5009"/>
                        </check>
                  </Rule>
                  <Rule id="prohibit_unicast_response_to_multicast_or_broadcast_requests_domain_profile"
                        selected="false"
                        weight="10.0">
                        <title>Prohibit unicast response to multicast or broadcast requests</title>
                        <description>The Windows Firewall: Prohibit unicast response to multicast or broadcast requests setting prevents a computer from receiving unicast responses to its outgoing multicast or broadcast messages. When this policy setting is enabled and the computer sends multicast or broadcast messages to other computers, Windows Firewall blocks the unicast responses sent by those other computers. When the setting is disabled and this computer sends a multicast or broadcast message to other computers, Windows Firewall waits up to three seconds for unicast responses from the other computers and then blocks all later responses. Typically, you would not want to receive unicast responses to multicast or broadcast messages. Such responses can indicate a denial of service (DoS) attack or an attacker attempting to probe a known live computer. This appendix recommends you configure this policy setting to Enabled to help prevent this type of attack. Note: This policy setting has no effect if the unicast message is a response to a Dynamic Host Configuration Protocol (DHCP) broadcast message sent by the computer. Windows Firewall always permits those DHCP unicast responses. However, this policy setting can interfere with the NetBIOS messages that detect name conflicts.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="SC-5"/>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-2972-8</ident>
                        <ident system="cce.mitre.org/version/4">CCE-696</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50111"
                                    value-id="prohibit_unicast_response_to_multicast_or_broadcast_requests_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5011"/>
                        </check>
                  </Rule>
                  <Rule id="protect_all_network_connections_domain_profile" selected="false"
                        weight="10.0">
                        <title>Protect all Network Connections</title>
                        <description>Many organizations use Remote Desktop connections in their normal troubleshooting procedures or operations. However, some attacks have occurred that exploited the ports typically used by Remote Desktop. To provide flexibility for remote administration, the Windows Firewall: Allow Remote Desktop exception setting is available. Enabling this setting configures Windows Firewall to open TCP port 3389 for inbound connections. You must also specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks this port and prevents the computer from receiving Remote Desktop requests. If an administrator attempts to open this port by adding it to a local port exceptions list, Windows Firewall does not open the port. Some attacks can exploit an open port 3389. To maintain the enhanced management capabilities provided by Remote Desktop, you should configure this setting to Enabled and specify the IP addresses and subnets of the computers used for remote administration. Computers in your environment should accept Remote Desktop requests from as few computers as possible.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile</dc:source>
                        </reference>
                        <requires idref="AC-17"/>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3154-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-806</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:50001"
                                    value-id="protect_all_network_connections_domain_profile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5000"/>
                        </check>
                  </Rule>
            </Group>
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <!-- ~~~  Windows Firewall Standard Profile                                                         -->
            <!-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -->
            <Group id="windows_firewall_standard_profile">
                  <title>Windows Firewall - Standard Profile</title>
                  <description>The Standard Profile is the default network location type when the computer is not connected to a domain. Standard profile settings should be the most restrictive because the computer is connected to a public network where security cannot be as tightly controlled as within an IT environment.</description>
                  <Value id="AllowFilePrintSharingExceptionsStandardProfile_var" operator="equals"
                        type="number">
                        <title>Allow file and print sharing exception</title>
                        <description>This setting allows file and printer sharing by configuring Windows Firewall to open UDP ports 137 and 138 and TCP ports 139 and 445. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive print jobs and requests for access to shared files. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from sharing files and printers. Because the computers in your environment running Windows XP will not normally be sharing files and printers, this appendix recommends you configure this setting as Disabled in all environments. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="AllowLocalPortExceptionsStandardProfile_var" operator="equals"
                        type="number">
                        <title>Allow local port exceptions</title>
                        <description>The Windows Firewall: Allow local port exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local port exceptions list. Windows Firewall can use two port exceptions lists; the other is defined by the Windows Firewall: Define port exceptions policy setting. If you enable this policy setting, the Windows Firewall component in Control Panel allows administrators to define a local port exceptions list. If you disable this policy setting, the Windows Firewall component in Control Panel does not allow administrators to define such a list. Typically, local administrators are not authorized to override organizational policy and establish their own port exceptions list in enterprise or high security environments. For that reason, this appendix recommends configuring this option as Disabled.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="AllowLocalProgramExceptionsStandardProfile_var" operator="equals"
                        type="number">
                        <title>Allow local program exceptions</title>
                        <description>The Windows Firewall: Allow local program exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local program exceptions list. Disabling this policy setting does not allow administrators to define a local program exceptions list, and ensures that program exceptions only come from Group Policy. Setting this policy to Enabled allows local administrators to use Control Panel to define program exceptions locally. For enterprise client computers, there may be conditions that justify having the client define local program exceptions. These conditions may include applications that were not analyzed when creating the organization's firewall policy or new applications that require nonstandard port configuration. In those cases, you may choose to enable this setting, recognizing that the attack surface of the affected computers is increased.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="AllowRemoteAdministrationExceptionsStandardProfile_var" operator="equals"
                        type="number">
                        <title>Allow remote administration exceptions</title>
                        <description>Many organizations take advantage of remote computer administration in their daily operations. However, some attacks have exploited the ports typically used by remote administration programs; Windows Firewall can block these ports. To provide flexibility for remote administration, the Windows Firewall: Allow remote administration exception setting is available. Configuring this setting to Enabled allows the computer to receive the unsolicited incoming messages associated with remote administration on TCP ports 135 and 445. This policy setting also allows SVCHOST.EXE and LSASS.EXE to receive unsolicited incoming messages and allows hosted services to open additional dynamically-assigned ports, typically in the range of 1044 to 1044 but potentially anywhere from 1044 to 65535. Enabling this setting also requires you to specify the IP addresses or subnets from which these incoming messages are allowed. If you configure this policy setting as Disabled, Windows Firewall makes none of the described exceptions. This appendix recommends you enable this setting for enterprise computers if necessary, and to always disable the setting for high security computers. Computers in your environment should accept remote administration requests from as few computers as possible. To maximize the protection provided by the Windows Firewall, make sure to specify only the necessary IP addresses and subnets of computers used for remote administration. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="AllowRemoteDesktopExceptionsStandardProfile_var" operator="equals"
                        type="number">
                        <title>Allow Remote Desktop exception</title>
                        <description>Many organizations use Remote Desktop connections in their normal troubleshooting procedures or operations. However, some attacks have occurred that exploited the ports typically used by Remote Desktop. To provide flexibility for remote administration, the Windows Firewall: Allow Remote Desktop exception setting is available. Enabling this setting configures Windows Firewall to open TCP port 3389 for inbound connections. You must also specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks this port and prevents the computer from receiving Remote Desktop requests. If an administrator attempts to open this port by adding it to a local port exceptions list, Windows Firewall does not open the port. Some attacks can exploit an open port 3389. To maintain the enhanced management capabilities provided by Remote Desktop, you should configure this setting to Enabled and specify the IP addresses and subnets of the computers used for remote administration. Computers in your environment should accept Remote Desktop requests from as few computers as possible.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="AllowUPnPframeworkExceptionsStandardProfile_var" operator="equals"
                        type="number">
                        <title>Allow UPnP framework exception</title>
                        <description>The Windows Firewall: Allow UPnP framework exception setting allows a computer to receive unsolicited Plug and Play messages sent by network devices, such as routers with built-in firewalls. To receive these messages, Windows Firewall opens TCP port 2869 and UDP port 1900. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive Plug and Play messages. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from receiving Plug and Play messages.</description>
                        <value>0</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="DoNotAllowExceptionsStandardProfile_var" operator="equals" type="number">
                        <title>Do not allow exceptions</title>
                        <description>The Windows Firewall: Do not allow exceptions setting specifies that Windows Firewall blocks all unsolicited incoming messages. This policy setting overrides all other Windows Firewall policy settings that allow such messages. If you enable this policy setting in the Windows Firewall component of Control Panel, the Don't allow exceptions check box is selected and administrators cannot clear it. Many environments contain applications and services that must be allowed to receive inbound unsolicited communications as part of their normal operation. In those cases, you may need to consider configuring this policy to Disabled to allow those applications and services to run properly. However, before making any change to this policy, you should test the environment to determine exactly what to allow and what to disallow. Note: This setting provides a strong defense against external attackers and should be set to Enabled in situations where you require complete protection from external attacks such as the outbreak of a new network worm. Setting this policy to Disabled allows Windows Firewall to apply other policy settings that allow unsolicited incoming messages.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="ProhibitNotificationsStandardProfile_var" operator="equals" type="number">
                        <title>Prohibit notification</title>
                        <description>Windows Firewall can display notifications to users when a program requests that Windows Firewall add the program to the program exceptions list. This situation occurs when programs attempt to open a port and are not allowed to do so based on current Windows Firewall rules. The Windows Firewall: Prohibit notifications setting configures whether these settings are shown to the users. If you set this policy to Enabled, Windows Firewall prevents the display of these notifications. If you set it to Disabled, Windows Firewall allows the display of these notifications.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="ProhibitUnicastResponseToMulticastOrBroadcastRequestsStandardProfile_var"
                        operator="equals"
                        type="number">
                        <title>Prohibit unicast response to multicast or broadcast requests</title>
                        <description>The Windows Firewall: Prohibit unicast response to multicast or broadcast requests setting prevents a computer from receiving unicast responses to its outgoing multicast or broadcast messages. When this policy setting is enabled and the computer sends multicast or broadcast messages to other computers, Windows Firewall blocks the unicast responses sent by those other computers. When the setting is disabled and this computer sends a multicast or broadcast message to other computers, Windows Firewall waits up to three seconds for unicast responses from the other computers and then blocks all later responses. Typically, you would not want to receive unicast responses to multicast or broadcast messages. Such responses can indicate a denial of service (DoS) attack or an attacker attempting to probe a known live computer. This appendix recommends you configure this policy setting to Enabled to help prevent this type of attack. Note: This policy setting has no effect if the unicast message is a response to a Dynamic Host Configuration Protocol (DHCP) broadcast message sent by the computer. Windows Firewall always permits those DHCP unicast responses. However, this policy setting can interfere with the NetBIOS messages that detect name conflicts.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Value id="ProtectAllNetworkConnectionsStandardProfile_var" operator="equals"
                        type="number">
                        <title>Protect all Network Connections</title>
                        <description>The Windows Firewall: Protect all network connections setting turns on Windows Firewall, which replaces Internet Connection Firewall on all computers that are running Windows XP SP2. This appendix recommends configuring this setting to Enabled to protect all network connections for computers in all environments. If this setting is configured as Disabled, Windows Firewall is turned off and all other settings for Windows Firewall are ignored. Note: If you enable this policy setting, Windows Firewall runs and ignores the Computer Configuration\Administrative Templates\Network\Network Connections\Prohibit use of Internet Connection Firewall on your DNS domain network policy setting.</description>
                        <value>1</value>
                        <value selector="enabled">1</value>
                        <value selector="disabled">0</value>
                  </Value>
                  <Rule id="AllowFilePrintSharingExceptionsStandardProfile" selected="false"
                        weight="10.0">
                        <title>Allow file and print sharing exception</title>
                        <description>This setting allows file and printer sharing by configuring Windows Firewall to open UDP ports 137 and 138 and TCP ports 139 and 445. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive print jobs and requests for access to shared files. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from sharing files and printers. Because the computers in your environment running Windows XP will not normally be sharing files and printers, this appendix recommends you configure this setting as Disabled in all environments. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3262-3</ident>
                        <ident system="cce.mitre.org/version/4">CCE-626</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51051"
                                    value-id="AllowFilePrintSharingExceptionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5105"/>
                        </check>
                  </Rule>
                  <Rule id="AllowICMPExceptionsStandardProfile" selected="false" weight="10.0">
                        <title>Allow ICMP exceptions (Block everything)</title>
                        <description>The Windows Firewall: Allow ICMP exceptions setting defines the set of Internet Control Message Protocol (ICMP) message types that Windows Firewall allows. Utilities can use ICMP messages to determine the status of other computers. For example, Ping uses the echo request message. If you set this policy setting to Enabled, you must specify which ICMP message types Windows Firewall allows the computer to send or receive. When you set this policy to Disabled, Windows Firewall blocks all unsolicited incoming ICMP message types and the listed outgoing ICMP message types. As a result, utilities that use the blocked ICMP messages will not be able to send those messages to or from the computer. Many attacker tools take advantage of computers that accept ICMP message types and use these messages to mount a variety of attacks. However, some applications require some ICMP messages in order to function properly. For that reason, this appendix recommends that you configure this setting to Disabled whenever possible. If your environment requires some ICMP messages to get through Windows Firewall, configure the setting with the appropriate message types. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3081-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-797</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5106"/>
                        </check>
                  </Rule>
                  <Rule id="AllowLocalPortExceptionsStandardProfile" selected="false" weight="10.0">
                        <title>Allow local port exceptions</title>
                        <description>The Windows Firewall: Allow local port exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local port exceptions list. Windows Firewall can use two port exceptions lists; the other is defined by the Windows Firewall: Define port exceptions policy setting. If you enable this policy setting, the Windows Firewall component in Control Panel allows administrators to define a local port exceptions list. If you disable this policy setting, the Windows Firewall component in Control Panel does not allow administrators to define such a list. Typically, local administrators are not authorized to override organizational policy and establish their own port exceptions list in enterprise or high security environments. For that reason, this appendix recommends configuring this option as Disabled.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-2989-2</ident>
                        <ident system="cce.mitre.org/version/4">CCE-77</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51131"
                                    value-id="AllowLocalPortExceptionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5113"/>
                        </check>
                  </Rule>
                  <Rule id="AllowLocalProgramExceptionsStandardProfile" selected="false" weight="10.0">
                        <title>Allow local program exceptions</title>
                        <description>The Windows Firewall: Allow local program exceptions setting allows administrators to use the Windows Firewall component in Control Panel to define a local program exceptions list. Disabling this policy setting does not allow administrators to define a local program exceptions list, and ensures that program exceptions only come from Group Policy. Setting this policy to Enabled allows local administrators to use Control Panel to define program exceptions locally. For enterprise client computers, there may be conditions that justify having the client define local program exceptions. These conditions may include applications that were not analyzed when creating the organization's firewall policy or new applications that require nonstandard port configuration. In those cases, you may choose to enable this setting, recognizing that the attack surface of the affected computers is increased.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3183-1</ident>
                        <ident system="cce.mitre.org/version/4">CCE-352</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51031"
                                    value-id="AllowLocalProgramExceptionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5103"/>
                        </check>
                  </Rule>
                  <Rule id="AllowRemoteAdministrationExceptionsStandardProfile" selected="false"
                        weight="10.0">
                        <title>Allow remote administration exceptions Disabled</title>
                        <description>Many organizations take advantage of remote computer administration in their daily operations. However, some attacks have exploited the ports typically used by remote administration programs; Windows Firewall can block these ports. To provide flexibility for remote administration, the Windows Firewall: Allow remote administration exception setting is available. Configuring this setting to Enabled allows the computer to receive the unsolicited incoming messages associated with remote administration on TCP ports 135 and 445. This policy setting also allows SVCHOST.EXE and LSASS.EXE to receive unsolicited incoming messages and allows hosted services to open additional dynamically-assigned ports, typically in the range of 1044 to 1044 but potentially anywhere from 1044 to 65535. Enabling this setting also requires you to specify the IP addresses or subnets from which these incoming messages are allowed. If you configure this policy setting as Disabled, Windows Firewall makes none of the described exceptions. This appendix recommends you enable this setting for enterprise computers if necessary, and to always disable the setting for high security computers. Computers in your environment should accept remote administration requests from as few computers as possible. To maximize the protection provided by the Windows Firewall, make sure to specify only the necessary IP addresses and subnets of computers used for remote administration. Note: If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall: Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall: Allow file and printer sharing exception, Windows Firewall: Allow remote administration exception, and Windows Firewall: Define port exceptions.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="AC-17"/>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-2954-6</ident>
                        <ident system="cce.mitre.org/version/4">CCE-467</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51041"
                                    value-id="AllowRemoteAdministrationExceptionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:51041"/>
                        </check>
                  </Rule>
                  <Rule id="AllowRemoteDesktopExceptionsStandardProfile" selected="false" weight="10.0">
                        <title>Allow Remote Desktop exception</title>
                        <description>Many organizations use Remote Desktop connections in their normal troubleshooting procedures or operations. However, some attacks have occurred that exploited the ports typically used by Remote Desktop. To provide flexibility for remote administration, the Windows Firewall: Allow Remote Desktop exception setting is available. Enabling this setting configures Windows Firewall to open TCP port 3389 for inbound connections. You must also specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks this port and prevents the computer from receiving Remote Desktop requests. If an administrator attempts to open this port by adding it to a local port exceptions list, Windows Firewall does not open the port. Some attacks can exploit an open port 3389. To maintain the enhanced management capabilities provided by Remote Desktop, you should configure this setting to Enabled and specify the IP addresses and subnets of the computers used for remote administration. Computers in your environment should accept Remote Desktop requests from as few computers as possible.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="AC-17"/>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3213-6</ident>
                        <ident system="cce.mitre.org/version/4">CCE-354</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51071"
                                    value-id="AllowRemoteDesktopExceptionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5107"/>
                        </check>
                  </Rule>
                  <Rule id="AllowUPnPframeworkExceptionsStandardProfile" selected="false" weight="10.0">
                        <title>Allow UPnP framework exception</title>
                        <description>The Windows Firewall: Allow UPnP framework exception setting allows a computer to receive unsolicited Plug and Play messages sent by network devices, such as routers with built-in firewalls. To receive these messages, Windows Firewall opens TCP port 2869 and UDP port 1900. If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive Plug and Play messages. You must specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from receiving Plug and Play messages.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3235-9</ident>
                        <ident system="cce.mitre.org/version/4">CCE-266</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51081"
                                    value-id="AllowUPnPframeworkExceptionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5108"/>
                        </check>
                  </Rule>
                  <Rule id="DoNotAllowExceptionsStandardProfile" selected="false" weight="10.0">
                        <title>Do not allow exceptions</title>
                        <description>The Windows Firewall: Do not allow exceptions setting specifies that Windows Firewall blocks all unsolicited incoming messages. This policy setting overrides all other Windows Firewall policy settings that allow such messages. If you enable this policy setting in the Windows Firewall component of Control Panel, the Don't allow exceptions check box is selected and administrators cannot clear it. Many environments contain applications and services that must be allowed to receive inbound unsolicited communications as part of their normal operation. In those cases, you may need to consider configuring this policy to Disabled to allow those applications and services to run properly. However, before making any change to this policy, you should test the environment to determine exactly what to allow and what to disallow. Note: This setting provides a strong defense against external attackers and should be set to Enabled in situations where you require complete protection from external attacks such as the outbreak of a new network worm. Setting this policy to Disabled allows Windows Firewall to apply other policy settings that allow unsolicited incoming messages.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3179-9</ident>
                        <ident system="cce.mitre.org/version/4">CCE-440</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51011"
                                    value-id="DoNotAllowExceptionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5101"/>
                        </check>
                  </Rule>
                  <Rule id="ProhibitNotificationsStandardProfile" selected="false" weight="10.0">
                        <title>Prohibit notification</title>
                        <description>Windows Firewall can display notifications to users when a program requests that Windows Firewall add the program to the program exceptions list. This situation occurs when programs attempt to open a port and are not allowed to do so based on current Windows Firewall rules. The Windows Firewall: Prohibit notifications setting configures whether these settings are shown to the users. If you set this policy to Enabled, Windows Firewall prevents the display of these notifications. If you set it to Disabled, Windows Firewall allows the display of these notifications.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3134-4</ident>
                        <ident system="cce.mitre.org/version/4">CCE-901</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51091"
                                    value-id="ProhibitNotificationsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5109"/>
                        </check>
                  </Rule>
                  <Rule id="ProhibitUnicastResponseToMulticastOrBroadcastRequestsStandardProfile"
                        selected="false"
                        weight="10.0">
                        <title>Prohibit unicast response to multicast or broadcast requests</title>
                        <description>The Windows Firewall: Prohibit unicast response to multicast or broadcast requests setting prevents a computer from receiving unicast responses to its outgoing multicast or broadcast messages. When this policy setting is enabled and the computer sends multicast or broadcast messages to other computers, Windows Firewall blocks the unicast responses sent by those other computers. When the setting is disabled and this computer sends a multicast or broadcast message to other computers, Windows Firewall waits up to three seconds for unicast responses from the other computers and then blocks all later responses. Typically, you would not want to receive unicast responses to multicast or broadcast messages. Such responses can indicate a denial of service (DoS) attack or an attacker attempting to probe a known live computer. This appendix recommends you configure this policy setting to Enabled to help prevent this type of attack. Note: This policy setting has no effect if the unicast message is a response to a Dynamic Host Configuration Protocol (DHCP) broadcast message sent by the computer. Windows Firewall always permits those DHCP unicast responses. However, this policy setting can interfere with the NetBIOS messages that detect name conflicts.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-5"/>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3103-9</ident>
                        <ident system="cce.mitre.org/version/4">CCE-632</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51111"
                                    value-id="ProhibitUnicastResponseToMulticastOrBroadcastRequestsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5111"/>
                        </check>
                  </Rule>
                  <Rule id="ProtectAllNetworkConnectionsStandardProfile" selected="false" weight="10.0">
                        <title>Protect all Network Connections</title>
                        <description>Many organizations use Remote Desktop connections in their normal troubleshooting procedures or operations. However, some attacks have occurred that exploited the ports typically used by Remote Desktop. To provide flexibility for remote administration, the Windows Firewall: Allow Remote Desktop exception setting is available. Enabling this setting configures Windows Firewall to open TCP port 3389 for inbound connections. You must also specify the IP addresses or subnets from which these incoming messages are allowed. If you disable this policy setting, Windows Firewall blocks this port and prevents the computer from receiving Remote Desktop requests. If an administrator attempts to open this port by adding it to a local port exceptions list, Windows Firewall does not open the port. Some attacks can exploit an open port 3389. To maintain the enhanced management capabilities provided by Remote Desktop, you should configure this setting to Enabled and specify the IP addresses and subnets of the computers used for remote administration. Computers in your environment should accept Remote Desktop requests from as few computers as possible.</description>
                        <reference>
                              <dc:type>GPO</dc:type>
                              <dc:source>Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile</dc:source>
                        </reference>
                        <requires idref="SC-7"/>
                        <ident system="http://cce.mitre.org">CCE-3284-7</ident>
                        <ident system="cce.mitre.org/version/4">CCE-273</ident>
                        <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                              <check-export export-name="oval:gov.nist.fdcc.xpfirewall:var:51001"
                                    value-id="ProtectAllNetworkConnectionsStandardProfile_var"/>
                              <check-content-ref href="fdcc-xpfirewall-oval.xml" name="oval:gov.nist.fdcc.xpfirewall:def:5100"/>
                        </check>
                  </Rule>
            </Group>
      </Group>
      <!-- **************************************************************************************************** -->
      <!-- ***  4 - Security Patches                                                                        *** -->
      <!-- **************************************************************************************************** -->
      <!--                                                                                                      -->
      <!-- see operating system benchmark                                                                       -->
      <!--                                                                                                      -->
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
      <!-- ==================================================================================================== -->
</Benchmark>
