Quantcast
Channel: Security and Compliance Management forum
Viewing all 481 articles
Browse latest View live

SCAP Export

$
0
0
I need to configure some additional setting in the Windows 7 template then export it out to the SCAP format.  The file will only export as a ".cab" file, so I extrated the files and then zipped them (zip is the only format that will import into the McAfee Policy Auditor software) but the file will not import, the software says that it is not a vaild file.  When I exported the Windows 7 template without making any changes it worked.  Do anyone know what the issue could be with the export after making changes to the base template?

MSS Settings - Registry key alternatives

$
0
0

I have quite a serious issue (it feels like it to me anyway!)

I am securing a baseline for a client - we are using 2012 R2. The existing policy and baseline (for 2k8) has the MSS settings in it. However from what I can see there is no way to apply these to 2012 R2 because SCM is not compatible with 2012 R2.

I thought I would sort this by simply finding registry key entries for the associated MSS configs (rationale for this attempted approach is that some of the MSS settings are showing up in the registry) but the keys dont match up (I am using the Win 2012 R2 baseline from Centre for Internet Security).

What I need is a way to get the configuration of the MSS items into the R2 build, and my problem is that 2012 r2 is not supported by SCM 3.0?

I am guessing now that I will have to roll another box which supprts SCM and then get the MSS settings built into the local policy there and then use that policy as the baseline. Before I embark on that step i just want to make sure that will work, and that I wont have any issues with the MSS settings when I try and apply them to an R2 box?

Finally, have I got this wrong or have MS released 2012 R2 without providing any means to apply some key security settings?

Finally finally :-). I am really really just shocked at how - well - crummy this whole MSS config thing is. MS Should have been baking these settings into every OS since 2008 surely. Why on earth would they make people install tooling - or wait for tooling which is completely unnecessary.


SCM v3.0 Import DISA STIGs?

$
0
0
From the content available from iase.disa.mil, is there a way to directly import DISA STIGs into SCM?  I'm looking to use this product to quickly generate and spit out DISA STIG Baselines to then export the data as GPOs for implementation in our environement.  Any help would be greatly appreciated.

Total physical memory

$
0
0

Security_Compliance_Manager_Setup.exe

Fails on Installation Requirements:

Total physical memory

You are installing on MIcrosoft Windows NT 6.1.7601 SP1 woth Only 67 MB memory. MS SCM requires at least 512MB of total physical memory.

This happend after I uninstalled the provious working setup deleting the DB.

VMWare Windows 7 Prof SP1 64bit 4GB RA

SmartScreen Filter in Internet Zone - Use it or not?

$
0
0

The SCM 3.0 recommends that SmartScreen filter be enabled for:

  • Locked-Down Trusted Sites Zone
  • Locked-Down Intranet Zone
  • Locked-Down Internet Zone
  • Locked-Down Restricted Sites Zone
  • Locked-Down Local Machine Zone
  • Local Machine Zone

I do not find a recommendation to enable SmartScreen filter for the Internet zone. Is this an oversight or is there something I am missing?


Charlie Newman

Process Pack for IT GRC - No Knowledge Libraries for Service Manager 2012

$
0
0

Hi Folks, so I'm installing the Process Pack for IT GRC.  I'm noticing the Knowledge Importer isn't finding any libraries to populate the service.  Can I manually import these libraries into the system?  This was working before the release of Microsoft Security Compliance Manager v3.0.  Thanks!

-Norman

IT GRC Process Pack and Sevice Manager 2012 R2

$
0
0

Hi Folks, does anyone know if the current IT GRC Process Pack (SP1) will work with Service Manager 2012 R2? In the past we've found that they are locked to the same release (i.e. RTM only works with RTM, SP1 only works with SP1, etc.) If someone can point us in the right direction that would be ideal. Thanks.

-Norman

GPO creation from exported baseline fails. - ""The Data is invalid"

$
0
0

I am working in a multi-domain environment.  I have backed up GPOs from multiple domains and imported them into SCM for analysis.  BTW - Tool works great for comparing a large number of GPOs. 

Scenario
======

1. I export a GPO baseline that was originally imported from domain1 as a GPO Backup folder.

2. In GPMC I create a new blank GPO with desired name.

3. Right-click new GPO and select import settings and navigate to backp created folder in step 1.  I get the warning "the BAckup contains references to security principals...".  At Migrating References screen I select "Copying them Identically from Source".  The import status goes to about 90% then fails with "The Data is invalid" message.

I have tried creating a migration table (from GPO backup) and I get the same results.

I have tried to create the GPO by restoring a backup and pointing to the folder in step 1 and I get a message "No GPO backups found"

So far I have this problem with three GPOs that contain a couple of hundred settings.   For each of these GPOs and export error was generated stating "the following settings were not included in export because they are not configured"

I have successfully exported backups from other GPO baselines and created new GPOs using this method.

Questions
========

1. What is the best method to troubleshoot this issue?

2. I have noticed the SCM backups do not have gpreport.xml file in the folder when exported.

3. How can I determine which "data is invalid"






"I need more cowbell!"


Unable to import settings to new GPO using gpmc import settings

$
0
0

Hello and thanks for the peek. faced with untangling a GPO jungle, wanted to use SCM 3.0 to :

1. export related GPO's using GPMC to backup folder

2. import related GPO's using SCM custom baselines/gpo import from backup folder

3. Select imported GPO baseline 1 as Baseline A and imported GPO baseline 2 as Baseline B and compare/merge using SCM

4. execute compare and then "merge baselines"

5. sleect new merged baseline name and proceed

6. Select "merged baseline" baseline and export tp GPO bakup folder

7 open GPMC> create new GPO> import settings > select back(ed)up folder path

8. select merged baseline within the path

9. continue with the wizard and unable to complete....getting "data is invalid" message and the wizard ends.

Simply said...Should I expect this process to work?

Thanks,

Serpaburger

IT GRC Process Pack _ Create Risks from Library

$
0
0

Hi Folks, so I'm trying to figure out if MSFT provides the a Risk Library - since when we create a Program and then attempt to "Create Risks from Library" the content is empty. I've gone through the process to import the MPs to provide various Control Libraries - but I don't see where we can include anything for the Risks. If someone can point me in the right direction that would be ideal.  Thanks!

-Norman

None of my servers are working for any of my games.

$
0
0
A few days ago me & my friend were playing on one of my servers and now none of them are working. I'm running on windows 7 and I've tried deactivating my firewalls but that didn't work.

Can you help me deploying a GPO ?

$
0
0

Hi , I try to deploy a GPO using MDT 2K13 , WDS and SCM 3.0 .

I install my custom SEVEN by PxE .

I'd like to deploy a GPO with these options changed :

- Specific Wallpaper and theme 

- Pevent changing Wallpaper and theme 

So when i'm on SCM , I expand the Windows 7 node to have : Win7SP1 Bitlocker Security 1.0 , Win7SP1 Computer Security 1.0 , Win7SP1 Domain Security 1.0 , Win7SP1 Extanded DCM Checks 1.0 , Win7SP1 User Security 1.0

So , which one should I duplicate to add these settings I told above ?

Then can you explain me the way to export it and put it on my customized windows 7 ?

Thanks a lot for your incoming answers ! 

Regards .


Error attempting to install SCM 3.0

$
0
0

I am attempting to install SCM 3.0 on Windows 7 workstation (64bit).  It has to install SQL Server 2008 Experss.  The SQL install is failing.  Getting window "The Microsoft Compliance Manager Setup Wizard failed while installing SQL Server Express Edition . Unknown Error (0x84b30001).  I look at the summary.txt file for the install and see Exit code : -2068643839  Error facility code 1203  exit error code 1

I am running with admin account and launched the SCM 3.0 executable with admin perms.  Anyone help with this ??

Baseline for Windows 7 and Internet Explorer 11

$
0
0

I am trying to great the GPOs for Windows 7 Pro with Internet Explorer 11.

I do not see a Baseline for IE 11.

Can I use the IE 10 Baseline?

Import Multiple GPO's at once

$
0
0

Is it possible to import multiple GPO backups at once into the Security Compliance Manager 3.0 Console as custom baselines?


BRL


down load problem

$
0
0

at the moment I have windows 8

try to down load Nero 12

everytime when nearly finish it says" The instalatiuon of Microsoft XML 4.0 Failed

setup will now exit.

so still with this problem for days.. try everything allready.. such as clean all former Nero in this PC

what now then?????????

Importing GPO

$
0
0
I am trying to import 2 (or more) GPO's from a domain so I can compare the baselines. I did Import "GPO Backup Folder" selected the backup and it is good. Then I do the same thing with the second and I get a message "An item with the same key has already been added". Selecting OK bring the screen "Object reference not set to an instance of an object". I can rename the GPO in the GPMC and back it up again and the same thing. Where is this key stored so I can rename it or bypass it? How can I get around this error?

Can not install Win7SP1_IT_GRC_MCA_MP.cab

$
0
0

Hello,

the actual SCM 3.0 package (Version: 3.0.60, Setting Library Version:2.0.82001) includes the Win7SP1_IT_GRC_MCA_MP.cab as part of the Windows 7 SP1 baseline attachment \ guides.

Unfortunately includes the .CAB file MPpackage.xml. The import SCM (.cab) process searches for package.xml in the .cab file. The Import Baseline Wizard therefore always displays an error (The package appears to be missing the required component 'package.xml'. Double-click the file to view more details about this error.) and as the result no import is possible.

Can Microsoft provide an updated .cab file which could be installed? A workaround would be fine as well.

Cheers

Thomas

Error when trying to export GPO Backup Folder

$
0
0

 Setting Default file format has following errors:
Rule Save Word files as has error: The string is missing with ID: '
              ' in setting 'Default file format'.

I am trying to export a Group Policy using Microsoft Security Compliance Manager and I get this error

Any ideas as to what is wrong??

thanks


many thanks

SCCM 2012 with SCM - support for non-Windows?

$
0
0

Hello all,

As part of compliance configuration, i came across the Microsoft's Security Compliance Manager 3.0 (latest version) mainly for compliance and remediation. But after going through their docs, I feel SCM is used only on Windows OS (clients or servers). 

a] Does SCM support contact with non-Microsoft vendors to import security baselines?

b] Does SCM support audit, compliance and remediation on non-windows OS devices? (clients/servers)

Any help is greatly appreciated.

thanks 

Viewing all 481 articles
Browse latest View live




Latest Images