DISA Microsoft Windows 11 STIG v2r3

Audit Details

Name: DISA Microsoft Windows 11 STIG v2r3

Updated: 6/23/2025

Authority: DISA STIG

Plugin: Windows

Revision: 1.1

Estimated Item Count: 259

File Details

Filename: DISA_STIG_Microsoft_Windows_11_v2r3.audit

Size: 553 kB

MD5: b8b5d4ba7268aeedd4d7aeceab33456c
SHA256: b2371a0d4602a1c8c1cd14e1087d9b3fd8fddc36fcd0d14a7d0de2df7623b57d

Audit Changelog

 
Revision 1.1

Jun 23, 2025

Functional Update
  • DISA_Microsoft_Windows_11_STIG_v2r3.audit from DISA Microsoft Windows 11 STIG v2r3
  • WN11-00-000025 - Windows 11 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).
  • WN11-00-000055 - Alternate operating systems must not be permitted on the same system.
  • WN11-00-000060 - Non-system-created file shares on a system must limit access to groups that require it.
  • WN11-00-000130 - Software certificate installation files must be removed from Windows 11.
  • WN11-00-000190 - Orphaned security identifiers (SIDs) must be removed from user rights on Windows 11.
  • WN11-00-000240 - Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.
  • WN11-00-000250 - Windows 11 nonpersistent VM sessions must not exceed 24 hours.
Miscellaneous
  • Platform check updated.