155
The following devices have been recommended to be Disabled for CC compliancy.
Protect Kernel Object Attributes
Key Path: HKLM\SYSTEM\CurrentControlSet\Control
Format
Value
Key:
Session Manager
Value
Name:
EnhancedSecurityLevel
REG_DWORD
1
Important:
The aforementioned key path, registry key, registry value name, and registry value all
need to be created.
This key ensures that the object manager may change attribute of a kernel object in the object table
for the current process if and only if the previous mode of the caller is kernel mode.
Restrict Null Session Access Over Named Pipes and Shares
Key Path: HKLM\SYSTEM\CurrentControlSet\Services\LanManServer
Format
Value
Key:
Parameters
Value
Name:
NullSessionPipes
NullSessionShares
REG_MULTI_SZ Delete
Values
Important:
Some NAS functionality may halt if the aforementioned pipes and shares are removed.
HP does not recommend Administrators remove any of the listed values.
This key prevents unauthorized access to the HP NAS server system by disabling all null session
access over named pipes and shares.
Prevent Applications From Interfering With the Session Lock
Key Path: HKCU\Software\Policies\Microsoft\Windows\Control Panel
Format
Value
Key:
Desktop
Value
Name:
BlockSendInputResets
REG_SZ
1
Important:
The aforementioned key path, registry key, registry value name, and registry value all
need to be created.
This key prevents application generated keyboard/mouse input messages from interfering with the
session lock.
Generate An Audit Event When The Audit Log Reaches a Percent Full Threshold
Key Path: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog
Format
Value
Key:
Security
Value
Name:
WarningLevel
REG_DWORD 90
Important:
The aforementioned registry key, registry value name, and registry value all need to be
created.
This key enables the generation of an audit event when the security log reaches a configurable
threshold.
Securing LDAP BIND Command Requests
Key Path: HKLM\SYSTEM\CurrentControlSet\Services\NTDS
Format
Value
Key:
Parameters
Value
Name:
LdapServerIntegrity
REG_DWORD 2
Important:
The aforementioned key path,registry key, registry value name, and registry value all need
to be created.