<items>
<item>
<name>检查密码最长使用期限</name>
<description>长期不修改密码会提高密码暴露风险,所以为了提高系统的保密性.需要检查密码最长使用期限.</description>
<type>secedit</type>
<mark>MaximumPasswordAge</mark>
<standard>90</standard>
<assessment>greaternumber</assessment>
</item>
<item>
<name>检查密码长度最小值</name>
<description>长度小的口令存在被爆破出的风险,所以为了保证密码的安全,提高保密性需要检查口令最小长度</description>
<type>secedit</type>
<mark>MinimumPasswordLength</mark>
<standard>8</standard>
<assessment>greaternumber</assessment>
</item>
<item>
<name>检查是否启用密码复杂度要求</name>
<description>仅包含字母数字字符的密码可通过多种公开可用的工具轻松发现.</description>
<type>secedit</type>
<mark>PasswordComplexity</mark>
<standard>1</standard>
<assessment>enum</assessment>
</item>
<item>
<name>密码使用最长期限天</name>
<description>密码使用最长期限天</description>
<type>secedit</type>
<mark>MaximumPasswordAge</mark>
<standard>90</standard>
<assessment>equals</assessment>
</item>
<item>
<name>强制密码历史</name>
<description>强制密码历史</description>
<type>secedit</type>
<mark>PasswordHistorySize</mark>
<standard>3</standard>
<assessment>equals</assessment>
</item>
<item>
<name>账号锁定30分钟</name>
<description>账号锁定30分钟</description>
<type>secedit</type>
<mark>LockoutDuration</mark>
<standard>30</standard>
<assessment>equals</assessment>
</item>
<item>
<name>密码锁定次数</name>
<description>账号密码锁定次数</description>
<type>secedit</type>
<mark>LockoutBadCount</mark>
<standard>3</standard>
<assessment>equals</assessment>
</item>
<item>
<name>重置账号锁定计时30分钟后</name>
<description>重置账号锁定计时30分钟后</description>
<type>secedit</type>
<mark>ResetLockoutCount</mark>
<standard>30</standard>
<assessment>equals</assessment>
</item>
<item>
<name>关闭个性化菜单</name>
<description>开始选项中,关闭个性化菜单</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
<regitem>Intellimenus</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>关闭Edge浏览器打印</name>
<description>关闭Edge浏览器打印</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main</registry>
<regitem>AllowPrinting</regitem>
<standard>0</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>关闭浏览器密码管理器</name>
<description>关闭浏览器密码管理器</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main</registry>
<regitem>FormSuggest Passwords</regitem>
<standard>no</standard>
<assessment>enum</assessment>
<valuetype>string</valuetype>
</item>
<item>
<name>阻止从可移动媒体进行任何安装</name>
<description>阻止从可移动媒体进行任何安装</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installer</registry>
<regitem>DisableMedia</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>不允许发布共享文件夹</name>
<description>不允许发布共享文件夹</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\SharedFolders</registry>
<regitem>PublishSharedFolders</regitem>
<standard>0</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>禁止用户添加网络打印机</name>
<description>禁止用户添加网络打印机</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\Wizard</registry>
<regitem>Downlevel Browse</regitem>
<standard>0</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>阻止添加打印机</name>
<description>阻止添加打印机</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
<regitem>NoAddPrinter</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>阻止更改主题</name>
<description>阻止更改主题</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
<regitem>NoThemesTab</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>启用屏幕保护程序</name>
<description>启用屏幕保护程序</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
<regitem>ScreenSaveActive</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>string</valuetype>
</item>
<item>
<name>屏幕保护程序主题</name>
<description>屏幕保护程序主题彩带</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
<regitem>SCRNSAVE.EXE</regitem>
<standard>Ribbons.scr</standard>
<assessment>equals</assessment>
<valuetype>string</valuetype>
</item>
<item>
<name>带有密码的屏幕保护</name>
<description>带有密码的屏幕保护</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
<regitem>ScreenSaverIsSecure</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>string</valuetype>
</item>
<item>
<name>屏幕保护超时时间60秒</name>
<description>屏幕保护超时时间60秒</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
<regitem>ScreenSaveTimeOut</regitem>
<standard>60</standard>
<assessment>equals</assessment>
<valuetype>string</valuetype>
</item>
<item>
<name>阻止用户更改壁纸</name>
<description>阻止用户更改壁纸</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop</registry>
<regitem>NoChangingWallPaper</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>禁止读取可移动存储设备</name>
<description>禁止读取可移动存储设备</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\RemovableStorageDevices\</registry>
<regitem>Deny_All</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>不允许开启热点共享</name>
<description>不允许开启热点共享,移动热点</description>
<type>registry</type>
<registry>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Network Connections</registry>
<regitem>NC_ShowSharedAccessUI</regitem>
<standard>0</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>仅运行允许的windows程序</name>
<description>仅运行允许的windows程序,必须指定程序名</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
<regitem>RestrictRun</regitem>
<standard>1</standard>
<assessment>equals</assessment>
<valuetype>dword</valuetype>
</item>
<item>
<name>允许运行的软件</name>
<description>允许运行的软件,cmd,msedge,regedit</description>
<type>registry</type>
<registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun</registry>
<regitem>cmd.exe</regitem>
<standard>cmd.exe</standard>
<assessment>array</assessment>
<valuetype>string</valuetype>
</item>
</items>
WindowsBaselineAssistant
最新推荐文章于 2024-09-26 17:00:06 发布