Score: <%BASecPanelCisScore> of 10    (scoring rules...)  = Pass
 = Fail
Benchmark: CIS Win2003 Domain Controller Legacy, Version 1.1
             
Service Packs and Hotfixes
Current Service Pack Section Score: <%BA(.sa.pass(0)?'1.25':'0.00')> of 1.25 
1. Latest Service Pack
 
Critical and Security Hotfixes Section Score: <%BA(.sa.pass(1)?'1.25':'0.00')> of 1.25 
1. Latest Critical and Security Hotfixes
 
Account and Audit Policies
Password Policies Section Score: <%BA(.sa.pass(2)?'0.83':'0.00')> of 0.83 
1. Current Password Ages
2. Minimum Password Length
 
Audit and Account Policies Section Score: <%BA(.sa.pass(3)?'0.83':'0.00')> of 0.83 
1. Audit Account Logon Events
2. Audit Account Management
3. Audit Logon Events
4. Audit Object Access
5. Audit Policy Change
6. Audit System Events
7. Minimum Password Age
8. Maximum Password Age
9. Password Complexity
10. Store Passwords using Reversible Encryption
11. Password History Size
12. Account Lockout Duration
13. Account Lockout Threshold
14. Reset Account Lockout Count Time
 
Event Log Policies Section Score: <%BA(.sa.pass(4)?'0.83':'0.00')> of 0.83 
1. Application Event Log: Maximum Size
2. Application Event Log: Restrict Guest Access
3. Security Event Log: Maximum Size
4. Security Event Log: Restrict Guest Access
5. System Event Log: Maximum Size
6. System Event Log: Restrict Guest Access
 
Security Settings
Security Options Section Score: <%BA(.sa.pass(5)?'2.50':'0.00')> of 2.50 
1. Accounts: Guest Account Status
2. Accounts: Limit Local Account Use of Blank Passwords to Console Logon Only
3. Accounts: Rename Administrator Account
4. Accounts: Rename Guest Account
5. Devices: Allowed to Format and Eject Removable Media
6. Devices: Prevent users from Installing Device Drivers
7. Devices: Unsigned Driver Installation Behavior
8. Domain Controller: Allow Server Operators to Schedule Tasks
9. Domain Controller: Refuse Machine Account Password Changes
10. Domain Member: Digitally Encrypt Secure Channel Data (When Possible)
11. Domain Member: Digitally Sign Secure Channel Data (When Possible)
12. Domain Member: Disable Machine Account Password Changes
13. Domain Member: Maximum Machine Account Password Age
14. Interactive Logon: Do Not Display Last User Name
15. Interactive Logon: Do Not Require CTRL+ALT+DEL
16. Interactive Logon: Message Text for Users Attempting to Log On
17. Interactive Logon: Message Title for Users Attempting to Log On
18. Interactive Logon: Prompt User to Change Password Before Expiration
19. Interactive Logon: Smart Card Removal Behavior
20. Microsoft Network Client: Digitally Sign Communication (if server agrees)
21. Microsoft Network Client: Send Unencrypted Password to Connect to Third-Party SMB Server
22. Microsoft Network Server: Amount of Idle Time Required Before Disconnecting Session
23. Microsoft Network Server: Digitally Sign Communication (if client agrees)
24. Microsoft Network Server: Disconnect Clients When Logon Hours Expire
25. Network Access: Let Everyone Permissions Apply to Anonymous Users
26. Network Access: Named Pipes That Can Be Accessed Anonymously
27. Network Access: Remotely Accessible Registry Paths
28. Network Access: Remotely Accessible Registry Paths and sub-Paths
29. Network Access: Restrict Anonymous Access to Named Pipes and Shares
30. Network Access: Shares That Can Be Accessed Anonymously
31. Network Access: Sharing and Security Model for Local Accounts
32. Network Security: LAN Manager Authentication Level
33. Network Security: LDAP Client Signing Requirements
34. Recovery Console: Allow Automatic Administrative Log On
35. Shutdown: Allow System to be Shut Down Without Having to Log On
36. System Cryptography: Force Strong Key Protection for User Keys Stored on the Computer
37. System Objects: Default Owner for Objects Created by Members of the Administrators Group
38. System Objects: Strengthen Default Permissions of Internal System Objects
39. System Settings: Optional Subsystems
40. MSS: (AFD DynamicBacklogGrowthDelta) Number of Connections to Create When Additional Connections are Necessary for Winsock Applications (10 recommended)
41. MSS: (AFD EnableDynamicBacklog) Enable Dynamic Backlog for Winsock Applications (recommended)
42. MSS: (AFD MaximumDynamicBacklog) Maximum Number of 'quasi-free' Connections for Winsock Applications
43. MSS: (AFD MinimumDynamicBacklog) Minimum Number of Free Connections for Winsock Applications (20 recommended for systems under attack, 10 otherwise)
44. MSS: (DisableIPSOurceRouting) IP Source Routing Protection Level
45. MSS: (EnableDeadGWDetect) Allow Automatic Detection of Dead Network Gateways
46. MSS: (EnableICMPRedirect) Allow ICMP Redirects to Override OSPF Generated Routes
47. MSS: (NoNameReleaseOnDemand) Allow the Computer to Ignore NetBIOS Name Release Requests Except From WINS Servers
48. MSS: (Perform Router Discovery) Allow IRDP to Detect and Configure Default Gateway Addresses
49. MSS: (SynAttackProtect) Syn Attack Protection Level
50. MSS: (TCPMaxConnectResponseRetransmissions) SYN - ACK Retransmissions When a Connection Request is not Acknowledged
51. MSS: (TCPMaxDataRetransmissions) How Many Times Unacknowledged Data is Retransmitted (3 recommended, 5 is default)
52. MSS: (TCPMaxPortsExhausted) How Many Dropped Connect Requests to Initiate SYN Attack Protection (5 is recommended)
53. MSS: Disable Autorun for All Drives
54. MSS: Enable Safe DLL Search Mode
55. MSS: How Often Keep-alive Packets are Sent in Milliseconds
56. MSS: The time in seconds before the screen saver grace period expires
 
Available Services and Other Requirements
Available Services Section Score: <%BA(.sa.pass(6)?'0.63':'0.00')> of 0.63 
1. Alerter Service Permissions
2. Client Service for Netware Permissions
3. Clipbook Service Permissions
4. FAX Service Permissions
5. File Replication Service Permissions
6. File Server for Macintosh Permissions
7. FTP Publishing Service Permissions
8. Help and Support Service Permissions
9. HTTP SSL Service Permissions
10. IIS Admin Service Permissions
11. Indexing Service Permissions
12. License Logging Service Permissions
13. Messenger Service Permissions
14. Microsoft POP3 Service Permissions
15. NetMeeting Remote Desktop Sharing Service Permissions
16. Network Connections Service Permissions
17. Network News Transport Protocol Service Permissions
18. Print Server for Macintosh Permissions
19. Remote Access Auto Connection Manager Service Permissions
20. Remote Access Connection Manager Service Permissions
21. Remote Administration Service Permissions
22. Remote Desktop Help Session Manager Permissions
23. Remote Installation Service Permissions
24. Remote Procedure Call (RPC) Locator Service Permissions
25. Remote Server Manager Service Permissions
26. Remote Server Monitor Service Permissions
27. Remote Storage Notification Service Permissions
28. Remote Storage Server Permissions
29. SMTP Service Permissions
30. SNMP Service Permissions
31. SNMP Trap Permissions
32. Telephony Service Permissions
33. Telnet Service Permissions
34. Trivial FTP Daemon Permissions
35. Wireless Configuration Service Permissions
36. World Wide Web Publishing Services Permissions
 
User Rights Section Score: <%BA(.sa.pass(7)?'0.63':'0.00')> of 0.63 
1. Act as Part of the Operating System
2. Allow Logon Locally
3. Allow Logon through Terminal Services
4. Change the System Time
5. Create a Token Object
6. Create Permanent Shared Objects
7. Debug Programs
8. Enable Computer and User Accounts to be Trusted for Delegation
9. Impersonate a Client after Authentication
10. Load and Unload Device Drivers
11. Log on as a Batch Job
12. Replace a Process Level Token
13. Synchronize Directory Service Data
14. Take Ownership of File or Other Objects
 
Other System Requirements Section Score: <%BA(.sa.pass(8)?'0.63':'0.00')> of 0.63 
1. All Local Volumes NTFS
2. Restricted Group: Remote Desktop Users
 
File and Registry Permissions Section Score: <%BA(.sa.pass(9)?'0.63':'0.00')> of 0.63 
1. Permissions for HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer
2. Permissions for HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies
3. Permissions for HKLM\System\CurrentControlSet\Enum
4. Permissions for HKLM\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\PermittedManagers
5. Permissions for HKLM\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities
6. Permissions for USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
7. Permissions for HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit
8. Permissions for %SystemRoot%\system32\tftp.exe
9. Permissions for %SystemRoot%\system32\telnet.exe
10. Permissions for %SystemRoot%\system32\tlntsvr.exe
11. Permissions for %SystemRoot%\system32\subst.exe
12. Permissions for %SystemRoot%\system32\sc.exe
13. Permissions for %SystemRoot%\system32\runas.exe
14. Permissions for %SystemRoot%\system32\rsh.exe
15. Permissions for %SystemRoot%\system32\rexec.exe
16. Permissions for %SystemRoot%\system32\regsvr32.exe
17. Permissions for %SystemRoot%\system32\regedt32.exe
18. Permissions for %SystemRoot%\regedit.exe
19. Permissions for %SystemRoot%\system32\reg.exe
20. Permissions for %SystemRoot%\system32\rcp.exe
21. Permissions for %SystemRoot%\system32\netsh.exe
22. Permissions for %SystemRoot%\system32\net1.exe
23. Permissions for %SystemRoot%\system32\net.exe
24. Permissions for %SystemRoot%\system32\ftp.exe
25. Permissions for %SystemRoot%\system32\eventtriggers.exe
26. Permissions for %SystemRoot%\system32\eventcreate.exe
27. Permissions for %SystemRoot%\system32\edlin.exe
28. Permissions for %SystemRoot%\system32\drwtsn32.exe
29. Permissions for %SystemRoot%\system32\drwatson.exe
30. Permissions for %SystemRoot%\system32\debug.exe
31. Permissions for %SystemRoot%\system32\cacls.exe
32. Permissions for %SystemRoot%\system32\attrib.exe
33. Permissions for %SystemRoot%\system32\at.exe