CIS: Windows Server 2022


This document provides information about the hotfix containing Windows Server 2022  Security Configuration Benchmark Version 1.0.0. This template contains implementation for 419 rules that that can be installed on TrueSight Server Automation 22.2.


Important

  • On the file server, check the value of the featureCisWin22Template key in the content.version file, located in the %FILESERVER%\BladeLogic\storage\Content directory. Depending on the value, do one of the following:
    • If the value is 22.2.00.000, you don’t need to perform the steps mentioned in this topic, as these templates are deployed as part of the 22.2 installation process.
    • If the value is lower than 22.2.00.000, perform the steps mentioned in this topic to deploy these templates.
  • Ensure to review the default values of the templates' local and global properties to match with the organization standards.

Before you begin

Before you install this hotfix, ensure that you perform the following:

  • Some policy settings require the installation of the SecGuide custom templates included with the STIG package. SecGuide.admx and SecGuide.adml (These files can be downloaded from Microsoft site) must be copied to the Target Machine at \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
  • Some policy settings require the installation of the MSS-Legacy custom templates included with the STIG package. MSS-Legacy.admx and MSS-Legacy.adml (These files can be downloaded from Microsoft site) must be copied to the Target Machine at \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
  • Save a backup of the extended_objects folder, which is at the following location on the file server:
    <File_Server_Root>/extended_objects/

Step 1: Downloading and installing the files

Download the CIS_Template_and_EO package from the EPD location and extract its contents to a temporary location on the file server.

You must log in or register to view this page


Click here to expand checksum related infromation

Verify the downloaded content by using the following check sums.

S.No

File Name

MD5SUM

1

CIS - Windows Server 2022.zip

a0f748801d7aee11fe8c60795066e032

Verify the extended objects are present on the application. If the md5sums match, go ahead and replace them. If these md5sums do not match, you must manually merge the fixes.

Step 2: Replacing the extended object scripts on the file server


    1. Navigate to the extended objects script files on your file server:
      <File_Server_Root>/extended_objects/
    2. Replace the Extended Object script files on your file server, with the extracted Extended Object script files stored in the temporary location:
      <temporary_location_on_file_server>/extended_objects/

Step 3: Importing the Compliance Content

  1. Log on the Console.
  2. Right-click on Component Templates and click Import
  3. Select the Import (Version-neutral) option.
  4. Select the updated CIS - Windows Server 2022.zip package from the temporary location.
    image2022-5-19_19-17-19.png
  5. The CIS template for Windows server 2022 is available in the CIS - Windows Server 2022 zip package. To import the templates, select the CIS - Windows Server 2022 and click Next.
  6. Ensure that you select the Update objects according to the imported package and Preserve template group path options and click Next.

    cis-win2k22.png

  7. Navigate to the last screen of the wizard and click Finish.
    The templates are imported successfully.

    image2022-5-19_19-49-5.png

Rules within the template

The template contains 419 rules.

The following are the details of the 272 rules provided in the zip package. It contains the following types of rules:

  • Rules that check for compliance (audit) and provides remediation - 394
  • Rules that check for compliance(audit) but do not provide remediation - 24
  • Rules that do not check for compliance and do not provide remediation - 1

The following are the details of the rules that are divided into parts:

  • Rules not divided into parts = 393
  • Rules divided into two parts = (5 Rule  (5 * 2) = 10
  • Rules divided into 3 parts = (1 Rule (1*3))=3
  • Rules divided into 5 parts (1 Rule (1*5))=5

So, the current rule count according to CIS Windows 2022 template after running the compliance job is 419.

Important

Ensure that you have gone through the following points before you run the compliance checks or perform remediation:

  • While running compliance jobs on domain controller targets, set the target server's DOMAIN property to DC.
  • Leave DOMAIN property blank for member servers and standalone systems.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*