1.186 WN10-RG-000005

Information

Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.

GROUP ID: V-220907RULE ID: SV-220907r958726

The registry is integral to the function, security, and stability of the Windows system. Changing the system's registry permissions allows the possibility of unauthorized and anonymous modification to the operating system.

Solution

Maintain the default permissions for the HKEY_LOCAL_MACHINE registry hive.

The default permissions of the higher level keys are noted below.

HKEY_LOCAL_MACHINE\SECURITYType - 'Allow' for allInherited from - 'None' for allPrincipal - Access - Applies toSYSTEM - Full Control - This key and subkeysAdministrators - Special - This key and subkeys

HKEY_LOCAL_MACHINE\SOFTWAREType - 'Allow' for allInherited from - 'None' for allPrincipal - Access - Applies toUsers - Read - This key and subkeysAdministrators - Full Control - This key and subkeysSYSTEM - Full Control - This key and subkeysCREATOR OWNER - Full Control - This key and subkeysALL APPLICATION PACKAGES - Read - This key and subkeys

HKEY_LOCAL_MACHINE\SYSTEMType - 'Allow' for allInherited from - 'None' for allPrincipal - Access - Applies toUsers - Read - This key and subkeysAdministrators - Full Control - This key and subkeysSYSTEM - Full Control - This key and subkeysCREATOR OWNER - Full Control - This key and subkeysALL APPLICATION PACKAGES - Read - This key and subkeys

Microsoft has also given Read permission to the SOFTWARE and SYSTEM registry keys in later versions of Windows 10 to the following SID.

S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681

See Also

https://workbench.cisecurity.org/benchmarks/23869

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CCI|CCI-002235, Rule-ID|SV-220907r958726_rule, STIG-ID|WN10-RG-000005, Vuln-ID|V-220907

Plugin: Windows

Control ID: 22f6ab1a771e6daf384eb825b81ce380d0ca5b03cd91a31a302a300eb4af8e1e