IncidentResponsev2

Task Enable Account Usage Auditing

Conditions

Given a user account with necessary rights to modify audit policies and a target computer

Standards

End State

System is configured to log account usage events in support of operational and forensic auditing that are compliant with the system owner’s needs and meet regulatory compliance requirements for the enclave.

Notes

Mission Element lead ought to request this capability of the business owner in order to secure accounts and organizational units

Manual Steps

References

Windows Commands AuditPol

Revision History