CIS Microsoft Windows 11 Enterprise v1.0.0 L1 + BL + NG

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Microsoft Windows 11 Enterprise v1.0.0 L1 + BL + NG

Updated: 7/11/2023

Authority: CIS

Plugin: Windows

Revision: 1.11

Estimated Item Count: 427

File Details

Filename: CIS_MS_Windows_11_Enterprise_Level_1_Bitlocker_Next_Generation_Windows_Security_v1.0.0.audit

Size: 966 kB

MD5: 4b15e14413a49412c127605d1c616a4e
SHA256: a80db7fe0b7e9c2502b92d3734ec1b904d3f32f28de8c8abf3021ef487f5f696

Audit Changelog

 
Revision 1.11

Jul 11, 2023

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.10

Apr 12, 2023

Functional Update
  • 1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'
  • 1.1.2 Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'
  • 1.1.3 Ensure 'Minimum password age' is set to '1 or more day(s)'
  • 1.1.4 Ensure 'Minimum password length' is set to '14 or more character(s)'
Miscellaneous
  • Metadata updated.
  • Variables updated.
Revision 1.9

Mar 8, 2023

Functional Update
  • 2.3.11.7 Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only. Refuse LM & NTLM'
Revision 1.8

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.7

Jan 4, 2023

Miscellaneous
  • Metadata updated.
Revision 1.6

Dec 21, 2022

Miscellaneous
  • Platform check updated.
  • Variables updated.
Revision 1.5

Dec 7, 2022

Miscellaneous
  • Metadata updated.
Revision 1.4

Sep 30, 2022

Functional Update
  • 19.7.8.5 Ensure 'Turn off Spotlight collection on Desktop' is set to 'Enabled'
Miscellaneous
  • References updated.
Revision 1.3

Jul 7, 2022

Functional Update
  • 18.5.4.1 Ensure 'Configure DNS over HTTPS (DoH) name resolution' is set to 'Enabled: Allow DoH' or higher
Revision 1.2

Jun 13, 2022

Functional Update
  • 18.4.13 Ensure 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' is set to 'Enabled: 90% or less'
  • 2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configured
  • 2.3.9.1 Ensure 'Microsoft network server: Amount of idle time required before suspending session' is set to '15 or fewer minute(s)'
  • 2.3.9.5 Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higher