1.14 WN16-00-000160

Information

Permissions for the system drive root directory (usually C:) must conform to minimum requirements.

GROUP ID:V-224832
RULE ID:SV-224832r958702

Changing the system's file and directory permissions allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.

The default permissions are adequate when the Security Option 'Network access: Let everyone permissions apply to anonymous users' is set to 'Disabled' (WN16-SO-000290).

Satisfies: SRG-OS-000312-GPOS-00122, SRG-OS-000312-GPOS-00123, SRG-OS-000312-GPOS-00124

Solution

Maintain the default permissions for the system drive's root directory and configure the Security Option 'Network access: Let everyone permissions apply to anonymous users' to 'Disabled' (WN16-SO-000290).

Default PermissionsC: <xhtml:br/> Type - 'Allow' for allInherited from - 'None' for all

Principal - Access - Applies to

- SYSTEM - Full control - This folder, subfolders, and files
- Administrators - Full control - This folder, subfolders, and files
- Users - Read & execute - This folder, subfolders, and files
- Users - Create folders/append data - This folder and subfolders
- Users - Create files/write data - Subfolders only
- CREATOR OWNER - Full Control - Subfolders and files only

See Also

https://workbench.cisecurity.org/benchmarks/23093