WindowsBaselineAssistant

<items>
  <item>
    <name>检查密码最长使用期限</name>
    <description>长期不修改密码会提高密码暴露风险,所以为了提高系统的保密性.需要检查密码最长使用期限.</description>
    <type>secedit</type>
    <mark>MaximumPasswordAge</mark>
    <standard>90</standard>
    <assessment>greaternumber</assessment>
  </item>
  <item>
    <name>检查密码长度最小值</name>
    <description>长度小的口令存在被爆破出的风险,所以为了保证密码的安全,提高保密性需要检查口令最小长度</description>
    <type>secedit</type>
    <mark>MinimumPasswordLength</mark>
    <standard>8</standard>
    <assessment>greaternumber</assessment>
  </item>
  <item>
    <name>检查是否启用密码复杂度要求</name>
    <description>仅包含字母数字字符的密码可通过多种公开可用的工具轻松发现.</description>
    <type>secedit</type>
    <mark>PasswordComplexity</mark>
    <standard>1</standard>
    <assessment>enum</assessment>
  </item>
  <item>
    <name>密码使用最长期限天</name>
    <description>密码使用最长期限天</description>
    <type>secedit</type>
    <mark>MaximumPasswordAge</mark>
    <standard>90</standard>
    <assessment>equals</assessment>
  </item>
  <item>
    <name>强制密码历史</name>
    <description>强制密码历史</description>
    <type>secedit</type>
    <mark>PasswordHistorySize</mark>
    <standard>3</standard>
    <assessment>equals</assessment>
  </item>
  <item>
    <name>账号锁定30分钟</name>
    <description>账号锁定30分钟</description>
    <type>secedit</type>
    <mark>LockoutDuration</mark>
    <standard>30</standard>
    <assessment>equals</assessment>
  </item>
  <item>
    <name>密码锁定次数</name>
    <description>账号密码锁定次数</description>
    <type>secedit</type>
    <mark>LockoutBadCount</mark>
    <standard>3</standard>
    <assessment>equals</assessment>
  </item>
  <item>
    <name>重置账号锁定计时30分钟后</name>
    <description>重置账号锁定计时30分钟后</description>
    <type>secedit</type>
    <mark>ResetLockoutCount</mark>
    <standard>30</standard>
    <assessment>equals</assessment>
  </item>
  <item>
    <name>关闭个性化菜单</name>
    <description>开始选项中,关闭个性化菜单</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
    <regitem>Intellimenus</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>关闭Edge浏览器打印</name>
    <description>关闭Edge浏览器打印</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main</registry>
    <regitem>AllowPrinting</regitem>
    <standard>0</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>关闭浏览器密码管理器</name>
    <description>关闭浏览器密码管理器</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main</registry>
    <regitem>FormSuggest Passwords</regitem>
    <standard>no</standard>
    <assessment>enum</assessment>
    <valuetype>string</valuetype>
  </item>
  <item>
    <name>阻止从可移动媒体进行任何安装</name>
    <description>阻止从可移动媒体进行任何安装</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installer</registry>
    <regitem>DisableMedia</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>不允许发布共享文件夹</name>
    <description>不允许发布共享文件夹</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\SharedFolders</registry>
    <regitem>PublishSharedFolders</regitem>
    <standard>0</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>禁止用户添加网络打印机</name>
    <description>禁止用户添加网络打印机</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\Wizard</registry>
    <regitem>Downlevel Browse</regitem>
    <standard>0</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>阻止添加打印机</name>
    <description>阻止添加打印机</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
    <regitem>NoAddPrinter</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>阻止更改主题</name>
    <description>阻止更改主题</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
    <regitem>NoThemesTab</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>启用屏幕保护程序</name>
    <description>启用屏幕保护程序</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
    <regitem>ScreenSaveActive</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>string</valuetype>
  </item>
  <item>
    <name>屏幕保护程序主题</name>
    <description>屏幕保护程序主题彩带</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
    <regitem>SCRNSAVE.EXE</regitem>
    <standard>Ribbons.scr</standard>
    <assessment>equals</assessment>
    <valuetype>string</valuetype>
  </item>
  <item>
    <name>带有密码的屏幕保护</name>
    <description>带有密码的屏幕保护</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
    <regitem>ScreenSaverIsSecure</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>string</valuetype>
  </item>
  <item>
    <name>屏幕保护超时时间60秒</name>
    <description>屏幕保护超时时间60秒</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop</registry>
    <regitem>ScreenSaveTimeOut</regitem>
    <standard>60</standard>
    <assessment>equals</assessment>
    <valuetype>string</valuetype>
  </item>
  <item>
    <name>阻止用户更改壁纸</name>
    <description>阻止用户更改壁纸</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop</registry>
    <regitem>NoChangingWallPaper</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>禁止读取可移动存储设备</name>
    <description>禁止读取可移动存储设备</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\RemovableStorageDevices\</registry>
    <regitem>Deny_All</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>不允许开启热点共享</name>
    <description>不允许开启热点共享,移动热点</description>
    <type>registry</type>
    <registry>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Network Connections</registry>
    <regitem>NC_ShowSharedAccessUI</regitem>
    <standard>0</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>仅运行允许的windows程序</name>
    <description>仅运行允许的windows程序,必须指定程序名</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</registry>
    <regitem>RestrictRun</regitem>
    <standard>1</standard>
    <assessment>equals</assessment>
    <valuetype>dword</valuetype>
  </item>
  <item>
    <name>允许运行的软件</name>
    <description>允许运行的软件,cmd,msedge,regedit</description>
    <type>registry</type>
    <registry>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun</registry>
    <regitem>cmd.exe</regitem>
    <standard>cmd.exe</standard>
    <assessment>array</assessment>
    <valuetype>string</valuetype>
  </item>
</items>
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值