U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Windows 2008 STIG Version 6, Release 46 Checklist Details (Checklist Revisions)

SCAP 1.0 Content:

Supporting Resources:

Target:

Target CPE Name
Microsoft Internet Explorer cpe:/a:microsoft:ie (View CVEs)
Microsoft Windows Defender cpe:/a:microsoft:windows_defender (View CVEs)
Microsoft Windows Mail cpe:/a:microsoft:windows_mail (View CVEs)
Microsoft Windows Media Player cpe:/a:microsoft:windows_media_player (View CVEs)
Microsoft Windows Server 2008 cpe:/o:microsoft:windows_server_2008:- (View CVEs)

Checklist Highlights

Checklist Name:
Windows 2008 STIG
Checklist ID:
228
Version:
Version 6, Release 46
Type:
Compliance
Review Status:
Final
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
04/29/2011

Checklist Summary:

The Windows Server 2008 Security Checklist is composed of three major sections and several appendices. The organizational breakdown proceeds as follows: Section 1 - Introduction This section contains summary information about the sections and appendices that comprise the Windows Server 2008 Security Checklist, and defines its scope. Supporting documents consulted are listed in this section. Section 2 - Automated System Check Procedures The Gold Disk does not support Windows 2008 at this time. Section 3 - Manual System Check Procedures This section documents the procedures that instruct the reviewer on how to perform an SRR manually, and to interpret the program output for vulnerabilities. Appendix A - Object Permissions This appendix documents the any additional Access Control Lists (ACLs) for file and registry objects. The tables contained in this section are referenced in Section 3. Appendix B - Joint Task Force Global Network Operations (JTF-GNO) Information Assurance Vulnerability Management (IAVM) Compliance This appendix contains checks for IAVM compliance to be done against a Windows Server 2008 machine. Appendix C - MS Group Policy Analysis Tools This appendix provides information for the use of Microsoft tools for analyzing group policy. Appendix D - Windows VMS Asset Creation and Findings Import Procedures for Reviewers and Self Assessments This appendix documents the procedures for creating assets and importing findings into VMS 6.0 Appendix E - Joint Task Force - Global Network Operations (JTF-GNO) Communications Tasking Orders (CTO) Compliance This appendix identifies Windows specific requirements from JTF-GNO CTOs. Appendix F - SRR Result Report This section is the matrix that allows the reviewer to document vulnerabilities discovered during the SRR process. The entries in this table are mapped to procedures, referenced by Vulnerability and STIG IDs in Sections 3 and Appendix B.

Checklist Role:

  • Server
  • Server Operating System

Known Issues:

Not provided.

Target Audience:

This document is designed to instruct the reviewer on how to assess Windows Server 2008 configurations in Windows domains. In addition, the security settings recommended can also be used to configure Group Policy in a Windows Active Directory environment.

Target Operational Environment:

  • Managed

Testing Information:

Not provided.

Regulatory Compliance:

Not provided.

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

Not provided.

Product Support:

Not provided.

Point of Contact:

Not provided.

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

Version 6, Release 1.27 - 25 April 2014
Version 6, Release 1.26 - 13 March 2014
Version 6, Release 1.25 - 24 January 2014
Version 6, Release 1.24 - 23 December 2013
Version 6, Release 1.23 - 25 October 2013
Version 6, Release 1.22 - 24 July 2013
Version 6, Release 1.21 - 29 March 2013
Version 6, Release 1.20 - 26 October 2012
Version 6, Release 1.19 - 27 July 2012
Version 6, Release 1.18 - 27 April 2012
Version 6, Release 1.17 - 24 January 2012
Version 6, Release 1.16 - 28 October 2011
Version 6, Release 1.15 - 29 July 2011

Dependency/Requirements:

URL Description
http://iase.disa.mil/stigs/Documents/Windows_Server_2008_Security_Guide.docx Windows Server 2008 Security Guide (DOCX)
http://iase.disa.mil/stigs/Documents/windows_server_2008_security_guide.pdf Windows Server 2008 Security Guide (PDF)
http://www.microsoft.com/downloads/details.aspx?FamilyID=1b6acf93-147a-4481-9346-f93a4081eea8&DisplayLang=en The Threats and Countermeasures Guide
http://www.microsoft.com/downloads/details.aspx?familyid=a3d1bbed-7f35-4e72-bfb5-b84a526c1565&displaylang=en Windows Vista Security Guide

References:

Reference URL Description

NIST checklist record last modified on 06/17/2014