Policy change auditing not enabled |
Risk Level: | Low | Check or Attack Name: Policy Audit |
Platforms: | Windows NT | |
Description: | Policy Change Auditing is not enabled. Policy auditing records when security policy changes are made. Since these events have a significant impact on the host and the network, ISS recommends always auditing these events. These events appear in the Event Viewer Security Log. |
Remedy: | Enable Security Policy Changes auditing. To enable auditing, follow these steps:
References: | Microsoft Knowledge Base Article Q174074, Security Event Descriptions, http://support.microsoft.com/support/kb/articles/q174/0/74.asp |
