1.10.3 Ensure 'Monitor file and program activity on your computer' is set to 'Enabled'

Information

This policy setting configures monitoring for file and program activity.

The recommended state for this setting is: Enabled.

Attackers routinely deploy new malware variants that can change faster than signature updates. Enabling this setting ensures that file and program activity are continually monitored.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Real-Time Protection\Monitor file and program activity on your computer

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 7777ef6b7c6740efcf6af13ce6b37be89eba3ce4ff06eed7ef741c7169245bd7