What are the recommended Audit Policy settings for Windows when implementing logging for the PCI DSS or other security standard?

Recommended Windows Audit Policy settings for PCI DSS and other compliance standards – Advanced Audit Policy templates for 2008R2, 2012R2, Server 2016 and Windows 10

Use of the audit policy to generate audit logs is an essential best practice for compliance and security. Its vital to get expert advice, not just to make sure you are getting all the audit events needed, but also to know where to stop to avoid an event log tsunami. Simply enabling all audit policy subcategories for all categories in the Advanced Audit Policy Configuration will burn up disk space and normalization resources on your SIEM system quicker than you can say 'How many Terabytes?!'

NNT have put together the following audit policies, based on expert guidance from Microsoft, Center for Internet Security and our experienced PCI QSA/Security Auditor partners.

To enable logging of all relevant Windows security events to underpin your security policy, it is necessary to configure the Local Security Policy for the Server/Workstation. This can be done either directly using the Local Security Policy console or applied globally using Group Policy.

The Easy Route: Audit Policy GPO Downloads for Compliance

Download the GPO template file for direct import and deployment via Active Directory

group policy icon

For a full overview on using any of these Audit Policy GPO files or the other NNT Remediation Kit content available, take a look at the notes and recorded demo HERE»

IMPORTANT! Make sure that the Advanced Audit Policy Subcategory Settings are not over-written by the application of Standard Audit Policy settings by configuring the 'Audit: Force Audit Policy Subcategory Settings (Windows Vista or later) to Override Audit Policy Category Settings' to 'Enable'

Security Options

Server 2012R2 – Audit Policy for PCI Compliance

Account Logon

Audit Policy: Account Logon: Audit Credential Validation to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Account Management

Audit Policy: Account Management: Audit Application Group Management to 'Success, Failure'
Audit Policy: Account Management: Audit Computer Account Management to 'Success, Failure'
Audit Policy: Account Management: Audit Other Account Management Events to 'Success, Failure'
Audit Policy: Account Management: Audit Security Group Management to 'Success, Failure'
Audit Policy: Account Management: Audit User Account Management to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Detailed Tracking

Audit Policy: Detailed Tracking: Audit Process Creation to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Logon/Logoff

Audit Policy: Logon/Logoff: Audit Account Lockout to 'Success'
Audit Policy: Logon/Logoff: Audit Logoff to 'Success'
Audit Policy: Logon/Logoff: Audit Logon to 'Success, Failure'
Audit Policy: Logon/Logoff: Audit Other Logon/Logoff Events to 'Success, Failure'
Audit Policy: Logon/Logoff: Audit Special Logon to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Object Access

Audit Policy: Object Access: Audit Removable Storage to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Policy Change

Audit Policy: Policy Change: Audit Policy Change' to 'Success and Failure'
Audit Policy: Policy Change: Authentication Policy Change' to 'Success'
Audit Policy: Policy Change: Authorization Policy Change' to 'No Auditing'
Audit Policy: Policy Change: Filtering Platform Policy Change' to 'No Auditing'
Audit Policy: Policy Change: MPSSVC Rule-Level Policy Change' to 'No Auditing'
Audit Policy: Policy Change: Other Policy Change Events' to 'No Auditing'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Privilege Use

Audit Policy: Privilege Use: Audit Sensitive Privilege Use to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

System

Audit Policy: System: Audit IPsec Driver to 'Success, Failure'
Audit Policy: System: Audit Other System Events to 'Success, Failure'
Audit Policy: System: Audit Security State Change to 'Success'
Audit Policy: System: Audit Security System Extension to 'Success, Failure'
Audit Policy: System: Audit System Integrity to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Server 2016 – Audit Policy for PCI Compliance

Account Logon

Audit Policy: Account Logon: Audit Credential Validation to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Account Management

Audit Policy: Account Management: Audit Application Group Management to 'Success, Failure'
Audit Policy: Account Management: Audit Computer Account Management to 'Success, Failure'
Audit Policy: Account Management: Audit Other Account Management Events to 'Success, Failure'
Audit Policy: Account Management: Audit Security Group Management to 'Success, Failure'
Audit Policy: Account Management: Audit User Account Management to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Detailed Tracking

Audit Policy: Detailed Tracking: Audit PNP Activity to 'Success'
Audit Policy: Detailed Tracking: Audit Process Creation to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Logon/Logoff

Audit Policy: Logon/Logoff: Audit Account Lockout to 'Success, Failure'
Audit Policy: Logon/Logoff: Audit Group Membership to 'Success'
Audit Policy: Logon/Logoff: Audit Logoff to 'Success'
Audit Policy: Logon/Logoff: Audit Logon to 'Success, Failure'
Audit Policy: Logon/Logoff: Audit Other Logon/Logoff Events to 'Success, Failure'
Audit Policy: Logon/Logoff: Audit Special Logon to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Object Access

Audit Policy: Object Access: Audit Removable Storage to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Policy Change

Audit Policy: Policy Change: Audit Audit Policy Change to 'Success, Failure'
Audit Policy: Policy Change: Audit Authentication Policy Change to 'Success'
Audit Policy: Policy Change: Audit Authorization Policy Change to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Privilege Use

Audit Policy: Privilege Use: Audit Sensitive Privilege Use to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

System

Audit Policy: System: Audit IPsec Driver to 'Success, Failure'
Audit Policy: System: Audit Other System Events to 'Success, Failure'
Audit Policy: System: Audit Security State Change to 'Success'
Audit Policy: System: Audit Security System Extension to 'Success, Failure'
Audit Policy: System: Audit System Integrity to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Windows 10 – Audit Policy for PCI Compliance

Account Logon

Audit Policy: Account Logon: Audit Credential Validation to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Account Management

Audit Policy: Account Management: Audit Application Group Management to 'Success, Failure'
Audit Policy: Account Management: Audit Computer Account Management to 'Success, Failure'
Audit Policy: Account Management: Audit Other Account Management Events to 'Success, Failure'
Audit Policy: Account Management: Audit Security Group Management to 'Success, Failure'
Audit Policy: Account Management: Audit User Account Management to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Detailed Tracking

Audit Policy: Detailed Tracking: Audit PNP Activity to 'Success'
Audit Policy: Detailed Tracking: Audit Process Creation to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Logon/Logoff

Audit Policy: Logon/Logoff: Audit Account Lockout to 'Success'
Audit Policy: Logon/Logoff: Audit Group Membership to 'Success'
Audit Policy: Logon/Logoff: Audit Logoff to 'Success'
Audit Policy: Logon/Logoff: Audit Logon to 'Success, Failure'
Audit Policy: Logon/Logoff: Audit Other Logon/Logoff Events to 'Success, Failure'
Audit Policy: Logon/Logoff: Audit Special Logon to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Object Access

Audit Policy: Object Access: Audit Removable Storage to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Policy Change

Audit Policy: Policy Change: Audit Audit Policy Change to 'Success, Failure'
Audit Policy: Policy Change: Audit Authentication Policy Change to 'Success'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Privilege Use

Audit Policy: Privilege Use: Audit Sensitive Privilege Use to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

System

Audit Policy: System: Audit IPsec Driver to 'Success, Failure'
Audit Policy: System: Audit Other System Events to 'Success, Failure'
Audit Policy: System: Audit Security State Change to 'Success'
Audit Policy: System: Audit Security System Extension to 'Success, Failure'
Audit Policy: System: Audit System Integrity to 'Success, Failure'

For a free automated system compliance audit:

Request a free trial of NNT Change Tracker

Windows 2008,2003,XP – Audit Policy for PCI Compliance

  • Account Logon Events – Success and Failure
  • Account Management Events – Success and Failure
  • Directory Service Access Events – Failure *
  • Logon Events – Success and Failure
  • Object Access Events – Success and Failure **
  • Policy Change Events – Success and Failure
  • Privilege Use Events - Failure
  • Process Tracking – No Auditing ***
  • System Events – Success and Failure ****

* Directory Service Access Events available on a Domain Controller only

** Object Access – Used in conjunction with Folder and File Auditing. Auditing Failures reveals attempted access to forbidden secure objects which may be an attempted security breach. Auditing Success is used to provide an Audit Trail of all access to secured date, for example, card data in a settlement/transaction file/folder.

Note: when using Server 2008/Win7 or later, there is an 'Advanced Audit Policy Configuration' option available which allows more precise application of auditing of Object Access events and is useful in eliminating unwanted events. If available, enable the 'Audit File System' option only for Success, and optionally Failure, but leave other settings as 'Not Configured'.

*** Process Tracking – not recommended as this will generate a large number of events. Better to use a specialized whitelisting/blacklisting technology such as NNT Remote Angel.

**** System Events – Not required for PCI DSS compliance but often used to provided additional 'added value' from a PCI DSS initiative, providing early warning signs of problems with hardware and so pre-empt system failures.

Note: This article serves as a Quick Start Guide. For a more comprehensive guide that makes full use of the Windows Advanced Audit Policy see this article HERE »

NNT Products
USA Offices
New Net Technologies LLC
Naples
Suite #10115, 9128 Strada Place
Naples, Florida, 34108
Atlanta
201 17th Street, Suite 300
Atlanta, Georgia, 30363.

Tel: 1-888-898-0674
email [email protected]
UK Office
New Net Technologies LLC
Rivers Lodge
West Common
Harpenden
Hertfordshire
AL5 2JN

Tel: 01582 287310
email [email protected]
Connect
Google+ Linkedin Twitter - Change Tracker Facebook rss feed YouTube
CIS benchmarking SEWP Cybersecurity 500 Sans Institute
Copyright 2017, New Net Technologies LLC. All rights reserved. 
NNT and Change Tracker are registered trademarks of New Net Technologies LLC.
All other product, company names and trademarks are the property of their respective owners.