Gold University of Minnesota M. Skip to main content.University of Minnesota.
Driven to Discover.

What's Inside OIT



links related to OIT

University of Minnesota

STANDARDS & GUIDELINES



     

GUIDELINE—Windows Vista Desktop Computer Security (Appendix S)


Responsible Office: Office of Information Technology
Responsible Officer: Chief Information Officer

EFFECTIVE DATE:
November 2006
VIEW HISTORY
RELATED POLICY/PROCEDURE:
Securing Private Data Standard

GUIDELINE
A guideline is highly recommended.


Introduction

This document was prepared as a guideline for securing Windows Vista desktops. "Basic" and "Level-2" Security settings are required for all workstations that work with private data.  "Basic" is required and "Level-2" is recommended for all other workstations on the University network.  Consult with your local technical support staff.

For a comparison of the various editions of Windows Vista and recommended editions for the University environment, see Security Recommendations on the Initial Release of Windows Vista.

“Basic” Security Settings for Windows Vista Computers

 

This is required for all workstations on the University network, including those that work with private data.
 

Windows FeatureMinimum Required Setting
Windows FirewallEnabled
Automatic Windows UpdatesEnabled
  
Symantec AntiVirus SettingsMinimum Required Setting
Symantec AV InstalledInstalled or Managed
Live Update EnabledEnabled
Virus Definition File Age8 days or less
Live Update Schedule FrequencyDaily
Auto Protect FilesystemEnabled

Use the QuickStart Basic Tool to verify and set some of the basic security settings recommended for Windows Vista computers.

“Level-2” Security Settings for Windows Vista Computers

These additional settings are required for workstations that work with private data and are recommended for all other workstations on the University network.

Account Lockout PolicyVista Default SettingMinimum Required Setting
Account Lockout DurationNot Analyzed15 Minute Minimum
Accounts Lockout Threshold0 invalid logon attempts7 wrong passwords Maximum
Reset Account Lockout Counter AfterNot Analyzed15 Minute Minimum
    
Audit PolicyVista Default SettingMinimum Required Setting
Audit Account Logon EventsNo auditingAudit Success and Failure attempts
Audit Account ManagementNo auditingAudit Success and Failure attempts
Audit Logon EventsNo auditingAudit Success and Failure attempts
Audit Object AccessNo auditingAudit Failure on attempts
Audit Policy ChangeNo auditingSuccess, Failure
Audit Privilege UseNo auditingAudit Failure on attempts
Audit System EventsNo auditingAudit Success and Failure on attempts
    
Event Log PolicyVista Default SettingMinimum Required Setting
Maximum Application Log Size20480 kilobytes9984 kilobytes Minimum
Maximum Security Log Size20480 kilobytes99968 kilobytes Minimum
Maximum System Log Size20480 kilobytes9984 kilobytes Minimum
Retention Method for Application LogAs neededAs needed
Retention Method for Security LogAs neededAs needed
Retention Method for System LogAs neededAs needed
    
Password PolicyVista Default SettingMinimum Required Setting
Enforce Password History0 passwords remembered5 passwords Minimum
Maximum Password Age42 days360 days
Minimum password age0 days1 days
Minimum Password Length0 characters8 characters Minimum
Password must meet complexity requirementsDisabledEnabled
Store Passwords using Reversible Encryption for all users in the domainDisabledDisabled
    
Security Options PolicyVista Default SettingMinimum Required Setting
Accounts: Guest account statusDisabledDisabled
Accounts: Limit local account use of blank passwords to console logon onlyEnabledEnabled
Network access: Allow anonymous SID/Name translationDisabledDisabled
Network access: Do not allow anonymous enumeration of SAM accountsEnabledEnabled
Network access: Do not allow anonymous enumeration of SAM accounts and sharesDisabledEnabled
Network security: Do not store LAN Manager hash value on next password changeEnabledEnabled
Network security: LAN Manager authentication levelSend NTLMv2 response onlySend NTLMv2 response only. Refuse LM & NTLM
Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsNo minimumRequire NTLMv2 session security, Require 128-bit encryption
Network security: Minimum session security for NTLM SSP based (including secure RPC) serversNo minimumRequire NTLMv2 session security, Require 128-bit encryption
Network access: Let Everyone permissions apply to anonymous users   Disabled
Recovery console: Allow automatic Administrative logon Disabled
   
User Rights PolicyVista Default SettingMinimum Required Setting
Deny Access to this computer from the network[hostname]\GuestAdministrator
Deny log on through Terminal Services (Remote Desktop) Administrator
   
File System SettingsVista Default SettingMinimum Required Setting
Enable updating of the Last Accessed timestamp on Files in Vista Enabled
   
Device AutoRunVista Default SettingMinimum Required Setting
CD Drive media autorun restrictions Autorun restricted on ALL media forms
Running commands in portable media AUTORUN.INF files Disabled
   
Screen SaverVista Default SettingMinimum Required Setting
Password required when returning from Screen Saver Enabled
Screen Saver Time out Setting 30 minutes Maximum
Screen Saver Enabled
Screen Saver selected Do not use bubbles.scr
   
Network ComponentsVista Default SettingMinimum Required Setting
IPv6 Disabled Protocols All IPv6 protocols disabled
   
Power SettingsVista Default SettingMinimum Required Setting
Prompt for Password on Resume Enabled

Use the QuickStart Level-2 Verify tool to verify the additional recommended security settings for Windows Vista computers.  Use the QuickStart Level-2 Wizard to apply the recommended security setting to a Windows Vista computer.

Similar “Basic” and “Level-2” settings are recommended for Windows Vista servers.

Together the "Basic" and "Level-2" Security Settings help meet 6 steps in the Securing Private Data Standard http://www.umn.edu/oit/security/privatedata.html

Resources and Links