Win 10: BSI provides security settings

B2B Cyber ​​Security ShortNews

Share post

The Federal Office for Information Security (BSI) has published recommendations for action to secure Windows systems in German and English as part of the “Study on system structure, logging, hardening and security functions in Windows 10” (SiSyPHuS Win10).

Most of the successful attacks on IT systems with Microsoft Windows 10 can already be detected or prevented with the on-board tools in the operating system. In order to facilitate the necessary configuration of the operating system, the Federal Office for Information Security (BSI) has issued recommendations for action to secure Windows systems in German as part of the "Study on system structure, logging, hardening and security functions in Windows 10" (SiSyPHuS Win10) and published in English. A focus during the creation was on simple implementation and practical application. The BSI therefore provides the recommended configuration settings as group policy objects (GPO) that can be imported directly into Windows - a service that is fast and secure.

Recommendations as importable GPOs

“As the federal cyber security authority, it is the task of the BSI to always think about digitization and information security together. We support users in government, business and society in using IT products and software safely. More than a third of computer users worldwide use Windows 10, and the trend is rising. That is why we put the operating system through its paces and derive specific recommendations from it that we can use to make digitization more secure, ”explains Arne Schönbohm, President of the BSI.

This publication is part of a comprehensive security analysis in which the BSI examines the security-critical functions of the operating system. The aim is to be able to evaluate the security and residual risks for the use of Windows 10, to identify framework conditions for a safe use of the operating system and to create practical recommendations for hardening and safe use of Windows 10.

Recommendations are aimed at authorities and companies

The recommendations from SiSyPHuS Win10 are primarily aimed at federal and state authorities as well as at companies. But also tech-savvy citizens can implement the recommendations, depending on the Windows 10 version used.

The subject of investigation is Windows 10 Enterprise LTSC 2019 64bit in German. The analyzes that have already been completed and carried out on the basis of LTSC version 1607 are compared with the current LTSC version and updated to the new operating system version.

The recommendations for the security functions, GPO and other published partial results of the study are available on the BSI website. The BSI will successively publish further results from other sub-areas of the study. The analyzes include components such as the Powershell, the “Application Compatibility Infrastructure”, the driver management and the PatchGuard.

More at BSI.bund.de

 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more