3.1 Set cmdlets 'Turn on Administrator Audit Logging' to 'True'

Information

Administrator audit logging is used to provide a log of the settings that are changed by administrators anywhere in the system. By default this setting is turned on to ensure discovery of configuration related security breaches.

Rationale:

Administrators may be able to reconfigure the system to expose a vulnerability with no record of the changes made.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-AdminAuditLogConfig -AdminAuditLogCmdlets *

See Also

https://workbench.cisecurity.org/files/1512

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Windows

Control ID: c8f8dc4cdb8e0d5ccc7bbb82b4a98c84aa9ae811510758ae23e277009b2736df