Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CIS control ids #99

Merged
merged 5 commits into from
Apr 23, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -390,7 +390,6 @@ win19cis_rule_18_10_10_1: true
win19cis_rule_18_10_12_1: true
win19cis_rule_18_10_12_2: true
win19cis_rule_18_10_12_3: true
win19cis_rule_18_9_14_3: true
win19cis_rule_18_10_13_1: true
win19cis_rule_18_10_14_1: true
win19cis_rule_18_10_14_2: true
Expand Down
1 change: 1 addition & 0 deletions tasks/prelim.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@
ansible.builtin.set_fact:
win19cis_cloud_based_system: true
when:
- ansible_system_vendor == 'Microsoft Corporation'
- ansible_virtualization_type == 'Hyper-V' or
ansible_virtualization_type == 'hvm' or
ansible_virtualization_type == 'kvm'
Expand Down
49 changes: 31 additions & 18 deletions tasks/section18.yml
Original file line number Diff line number Diff line change
Expand Up @@ -559,15 +559,14 @@
- patch
- netbios

- name: "18.6.4.2 | PATCH | Ensure Turn off multicast name resolution is set to Enabled MS Only | Member Server"
- name: "18.6.4.2 | PATCH | Ensure Turn off multicast name resolution is set to Enabled"
ansible.windows.win_regedit:
path: HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient
name: EnableMulticast
data: 0
type: dword
when:
- win19cis_rule_18_6_4_2
- win2019cis_is_domain_member
tags:
- level1-domaincontroller
- level1-memberserver
Expand Down Expand Up @@ -2771,7 +2770,7 @@
ansible.windows.win_regedit:
path: HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
name: DisableRealtimeMonitoring
data: 1
data: 0
datatype: dword
when:
- win19cis_rule_18_10_43_10_2
Expand Down Expand Up @@ -3346,20 +3345,6 @@
- patch
- wik

- name: "18.10.81.1 | PATCH | Ensure Allow user control over installs is set to Disabled"
ansible.windows.win_regedit:
path: HKLM:\Software\Policies\Microsoft\Windows\Installer
name: EnableUserControl
data: 0
type: dword
when:
- win19cis_rule_18_10_81_1
tags:
- level1-domaincontroller
- level1-memberserver
- rule_18.10.81.1
- patch

- name: "18.10.80.2 | PATCH | Ensure 'Allow suggested apps in Windows Ink Workspace' is set to 'Disabled'"
block:
- name: "18.10.80.2 | AUDIT | Ensure 'Allow suggested apps in Windows Ink Workspace' is set to 'Disabled' | Warning Check For Variable Standards."
Expand Down Expand Up @@ -3396,6 +3381,34 @@
- automated
- patch

- name: "18.10.81.1 | PATCH | Ensure Allow user control over installs is set to Disabled"
ansible.windows.win_regedit:
path: HKLM:\Software\Policies\Microsoft\Windows\Installer
name: EnableUserControl
data: 0
type: dword
when:
- win19cis_rule_18_10_81_1
tags:
- level1-domaincontroller
- level1-memberserver
- rule_18.10.81.1
- patch

- name: "18.10.81.2 | PATCH | Ensure 'Always install with elevated privileges' is set to 'Disabled'"
ansible.windows.win_regedit:
path: HKLM:\Software\Policies\Microsoft\Windows\Installer
name: AlwaysInstallElevated
data: 0
type: dword
when:
- win19cis_rule_18_10_81_2
tags:
- level1-domaincontroller
- level1-memberserver
- rule_18.10.81.2
- patch

- name: "18.10.81.3 | PATCH | Ensure Prevent Internet Explorer security prompt for Windows Installer scripts is set to Disabled"
ansible.windows.win_regedit:
path: HKLM:\Software\Policies\Microsoft\Windows\Installer
Expand Down Expand Up @@ -3658,7 +3671,7 @@
ansible.windows.win_regedit:
path: HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate
name: ManagePreviewBuildsPolicyValue
data: 0
data: 1
type: dword
when:
- win19cis_rule_18_10_93_4_1
Expand Down
Loading