STIGQter STIGQter: STIG Summary: Windows PAW Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 15 May 2020:

A Windows update service must be available to provide software updates for the PAW platform.

DISA Rule

SV-92859r1_rule

Vulnerability Number

V-78153

Group Title

PAW-00-000800

Rule Version

WPAW-00-000800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install a Windows update service (for example, Microsoft WSUS or System Center Configuration Manager [SCCM]) to provide software updates to all Windows-based PAWs in the organization.

Configure the Windows update service to download available operating system updates and install them when approved.

Based on site policy, configure the Windows update service to either automatically approve new updates for installation or to not install updates until installation is initiated by an authorized PAW maintenance administrator.

If WSUS is being used, configure Windows Update for WSUS on each PAW (use appropriate configuration procedures if an alternate Windows update service is used).

Go to Computer Configuration\Administrative Templates\Windows Components\Windows Updates and follow the steps below:

1. Enable the Configure Automatic Updates policy.
2. Select option 4 - Auto download and schedule the install.
3. Change the option "Scheduled install day" to "0 - Every Day" and the option "Scheduled install time" to your organizational preference.
4. Enable option "Specify intranet Microsoft update service location" policy, and specify in both options the URL of the WSUS server.

Check Contents

Verify an automated software update service is being used at the site to update the operating system of site PAWs.

If an automated software update service is not set up and configured to provide updates to site PAWs, this is a finding.

Vulnerability Number

V-78153

Documentable

False

Rule Version

WPAW-00-000800

Severity Override Guidance

Verify an automated software update service is being used at the site to update the operating system of site PAWs.

If an automated software update service is not set up and configured to provide updates to site PAWs, this is a finding.

Check Content Reference

M

Target Key

3283

Comments