Talk With an Expert

Criticality of Advanced Audit Policy in Early Detection of Cyber-Attack

Criticality of Advanced Audit Policy in Early Detection of Cyber-Attack (PDF, 4.89MB)Published: 16 Dec, 2021
Created by:
Rebecca Harness

Windows 11, and its predecessors, install with most security and audit policies set to a disabled state. System administrators may find the implementation of popular security configuration frameworks, such as Microsoft’s Secure Configuration Framework, difficult to justify unless specific benefits are identified. Audit policies, in particular, have the potential to provide valuable information for operational troubleshooting and early detection of security incidents. The recent release of Windows 11 provided the opportunity to identify if these challenges remain and, if so, demonstrate specific value to implementing Microsoft Security Configuration Framework – Level 1 – Advanced Audit Policy Configuration.