1.17 WN16-00-000190

Information

Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.

GROUP ID:V-224835
RULE ID:SV-224835r958726

The registry is integral to the function, security, and stability of the Windows system. Changing the system's registry permissions allows the possibility of unauthorized and anonymous modification to the operating system.

Solution

Maintain the default permissions for the HKEY_LOCAL_MACHINE registry hive.

The default permissions of the higher-level keys are noted below.

HKEY_LOCAL_MACHINE\SECURITY

- Type - 'Allow' for all
- Inherited from - 'None' for all
- Principal - Access - Applies to
- SYSTEM - Full Control - This key and subkeys
- Administrators - Special - This key and subkeys

HKEY_LOCAL_MACHINE\SOFTWARE

- Type - 'Allow' for all
- Inherited from - 'None' for all
- Principal - Access - Applies to
- Users - Read - This key and subkeys
- Administrators - Full Control - This key and subkeys
- SYSTEM - Full Control - This key and subkeys
- CREATOR OWNER - Full Control - This key and subkeys
- ALL APPLICATION PACKAGES - Read - This key and subkeys

HKEY_LOCAL_MACHINE\SYSTEM

- Type - 'Allow' for all
- Inherited from - 'None' for all
- Principal - Access - Applies to
- Users - Read - This key and subkeys
- Administrators - Full Control - This key and subkeys
- SYSTEM - Full Control - This key and subkeys
- CREATOR OWNER - Full Control - Subkeys only
- ALL APPLICATION PACKAGES - Read - This key and subkeys
- Server Operators - Read - This Key and subkeys (Domain controllers only)

See Also

https://workbench.cisecurity.org/benchmarks/23093

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6(7)(b), 800-53|CM-6b.

Plugin: Windows

Control ID: da1b6fbdcb9424a6203595d05c141cb120250c3f991836f47a2178597ef07ccf