ࡱ>  f2\p Sain, Joe Ba==xN%58X@"1Calibri1Calibri1Calibri1Calibri1Calibri1h8Cambria1,8Calibri18Calibri18Calibri1Calibri1Calibri1<Calibri1>Calibri1?Calibri14Calibri14Calibri1 Calibri1 Calibri1Calibri1Calibri1 Calibri1Arial1Arial1Arial1Arial1Verdana1 Arial1Arial1Calibri1 Arial1Arial1<Arial1Arial1Calibri1Arial"$"#,##0_);\("$"#,##0\)!"$"#,##0_);[Red]\("$"#,##0\)""$"#,##0.00_);\("$"#,##0.00\)'""$"#,##0.00_);[Red]\("$"#,##0.00\)7*2_("$"* #,##0_);_("$"* \(#,##0\);_("$"* "-"_);_(@_).))_(* #,##0_);_(* \(#,##0\);_(* "-"_);_(@_)?,:_("$"* #,##0.00_);_("$"* \(#,##0.00\);_("$"* "-"??_);_(@_)6+1_(* #,##0.00_);_(* \(#,##0.00\);_(* "-"??_);_(@_)[$-409]General                                                                       ( (     ff + ) , *      P  P         ` (d (d (d (d (d (d (d (d (d (d (d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d 1(d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (d (                                                                                                                                                                  !                                                                                       ! ! ! ! ! ! ! ! ! ! !                                                                                                                                  !  ! ! ! ! ! ! ! ! ! !  ! ! ! ! ! ! ! ! ! !  ! ! ! ! ! ! ! ! ! !  ! ! ! ! ! ! ! ! ! !  ! ! ! ! ! ! ! ! ! !  ! ! !                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    !                                                                                                                                              ! ! ! ! ! ! ! ! ! !                                                ! ! ! ! ! ! ! ! !  ! !           ! ! ! ! ! ! ! ! ! !  ! ! ! ! ! ! ! ! ! !  ! ! ! ! ! ! ! ! ! !  !  ! ! ! !       (   (                   "            !       #   a>   (x  (<  (x (8  x/  (x(  x  8  x x/  x(  8  )x  )<  )x !8  )x/  )x(  (0  )|/  )x  (p  )x  !x/  )x/  (x/  (8  (x (x  )x@ @  )x  )|  !x )x  )<  !8  )<  )x  !8  )8  (x  (4  (p (8  x/  p/  (p( ||iR[}-} 00\);_(*}-} 00\);_(*}-} 00\);_(*}-} 00\);_(*}-} 00\);_(*}-} 00\);_(*}-} 00\);_(*}-} 00\);_(*}-} 00\);_(*}-}  00\);_(*}-}  00\);_(*}-}  00\);_(*}-}  00\);_(*}-}  00\);_(*}-} 00\);_(*}-} 00\);_(*}-}/ 00\);_(*}-}0 00\);_(*}-}1 00\);_(*}-}2 00\);_(*}-}5 00\);_(*}-}7 00\);_(*}A}6 00\);_(*;_(@_) }A}7 00\);_(*?;_(@_) }A}8 00\);_(*23;_(@_) }-}9 00\);_(*}A}5 a00\);_(*;_(@_) }A}) 00\);_(*;_(@_) }A} e00\);_(*;_(@_) }}; ??v00\);_(*̙;_(@_)    }}4 ???00\);_(*;_(@_) ??? ??? ??? ???}}- }00\);_(*;_(@_)    }A}< }00\);_(*;_(@_) }}. 00\);_(*;_(@_) ??? ??? ??? ???}-}9 00\);_(*}}2 00\);_(*;_(@_)    }-}4 00\);_(*}U}8 00\);_(*;_(@_)  }A}" 00\);_(*;_(@_) }A} 00\);_(*ef;_(@_) }A} 00\);_(*L;_(@_) }A} 00\);_(*23;_(@_) }A}# 00\);_(*;_(@_) }A} 00\);_(*ef;_(@_) }A} 00\);_(*L;_(@_) }A} 00\);_(*23;_(@_) }A}$ 00\);_(*;_(@_) }A} 00\);_(*ef;_(@_) }A} 00\);_(*L;_(@_) }A} 00\);_(*23;_(@_) }A}% 00\);_(*;_(@_) }A} 00\);_(*ef;_(@_) }A} 00\);_(*L;_(@_) }A} 00\);_(*23;_(@_) }A}& 00\);_(*;_(@_) }A} 00\);_(*ef;_(@_) }A} 00\);_(*L;_(@_) }A}  00\);_(*23;_(@_) }A}' 00\);_(* ;_(@_) }A} 00\);_(*ef ;_(@_) }A} 00\);_(*L ;_(@_) }A}! 00\);_(*23 ;_(@_) }d};00\);_(*3 ;_(   }(}?00\);_(*}(}D00\);_(*}d}I00\);_(*3 ;_(   }(}K00\);_(*}d}Z00\);_(*3 ;_(   }-}[ 00\);_(*}-}^ 00\);_(*}-}` 00\);_(*}(}h00\);_(*}<}( 00\);_(* 3 ;_(}<}* 00\);_(*3 ;_(}(}+00\);_(*}(}3 00\);_(*}<} e00\);_(*3 ;_(}(}H 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(}+ 00\);_(*}(}- 00\);_(*}(}. 00\);_(*}(}/ 00\);_(*}(}0 00\);_(*}(}1 00\);_(*}(}2 00\);_(*}(}3 00\);_(*}(}4 00\);_(*}(}5 00\);_(*}(}6 00\);_(*}(}8 00\);_(*}(}9 00\);_(*}(}: 00\);_(*}(}; 00\);_(*}(}< 00\);_(*}(}= 00\);_(*}(}> 00\);_(*}(}? 00\);_(*}(}@ 00\);_(*}(}A 00\);_(*}(}C 00\);_(*}(}D 00\);_(*}(}E 00\);_(*}(}F 00\);_(*}(}G 00\);_(*}(}H 00\);_(*}(}I 00\);_(*}(}J 00\);_(*}(}K 00\);_(*}(}L 00\);_(*}(}N 00\);_(*}(}O 00\);_(*}(}P 00\);_(*}(}Q 00\);_(*}(}R 00\);_(*}(}S 00\);_(*}(}T 00\);_(*}(}U 00\);_(*}(}V 00\);_(*}(}W 00\);_(*}(}Y 00\);_(*}(}Z 00\);_(*}(}[ 00\);_(*}(}\ 00\);_(*}(}] 00\);_(*}(}^ 00\);_(*}(}_ 00\);_(*}(}` 00\);_(*}(}a 00\);_(*}(}b 00\);_(*}(}d 00\);_(*}(}e 00\);_(*}(}f 00\);_(*}(}  00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}(} 00\);_(*}-} 00\);_(*}(} 00\);_(*}(}  00\);_(*}(}  00\);_(*}(}  00\);_(*}(}  00\);_(*}}*}}3 00\);_(*3 ;_(    20% - Accent1M 20% - Accent1 ef % 20% - Accent2M" 20% - Accent2 ef % 20% - Accent3M& 20% - Accent3 ef % 20% - Accent4M* 20% - Accent4 ef % 20% - Accent5M. 20% - Accent5 ef % 20% - Accent6M2 20% - Accent6  ef % 40% - Accent1M 40% - Accent1 L % 40% - Accent2M# 40% - Accent2 L渷 % 40% - Accent3M' 40% - Accent3 L % 40% - Accent4M+ 40% - Accent4 L % 40% - Accent5M/ 40% - Accent5 L % 40% - Accent6M3 40% - Accent6  Lմ % 60% - Accent1M 60% - Accent1 23 % 60% - Accent2M$ 60% - Accent2 23ږ % 60% - Accent3M( 60% - Accent3 23כ % 60% - Accent4M, 60% - Accent4 23 % 60% - Accent5M0 60% - Accent5 23 %! 60% - Accent6M4 60% - Accent6  23 % "Accent1AAccent1 O % #Accent2A!Accent2 PM % $Accent3A%Accent3 Y % %Accent4A)Accent4 d % &Accent5A-Accent5 K % 'Accent6A1Accent6  F %( Accent6 2@ Accent6 2  F )Bad9Bad  % *Bad 28Bad 2  +Blue Background@Blue Background  ,Bold- Calculation Calculation  }% . Check Cell Check Cell  %????????? ???/ Comma0( Comma [0]1&Currency2. Currency [0]3Excel Built-in Normal 1PExcel Built-in Normal 1 4Explanatory TextG5Explanatory Text % 5Good;Good  a%6 Heading 1G Heading 1 I}%O7 Heading 2G Heading 2 I}%?8 Heading 3G Heading 3 I}%239 Heading 49 Heading 4 I}%: Hyperlink 2 ;InputuInput ̙ ??v% < Linked CellK Linked Cell }% =Mine >Mine 10 ?Mine 11 @Mine 12 AMine 13 BMine 14 CMine 15 DMine 16 EMine 17 FMine 18 GMine 19 HMine 2I Mine 2 10J Mine 2 11K Mine 2 12L Mine 2 13M Mine 2 14N Mine 2 15O Mine 2 16P Mine 2 17Q Mine 2 18R Mine 2 19 SMine 2 2T Mine 2 20U Mine 2 21V Mine 2 22W Mine 2 23X Mine 2 24Y Mine 2 25Z Mine 2 26[ Mine 2 27\ Mine 2 28] Mine 2 29 ^Mine 2 3_ Mine 2 30` Mine 2 31a Mine 2 32b Mine 2 33c Mine 2 34d Mine 2 35e Mine 2 36f Mine 2 37g Mine 2 38h Mine 2 39 iMine 2 4j Mine 2 40k Mine 2 41l Mine 2 42m Mine 2 43n Mine 2 44o Mine 2 45p Mine 2 46q Mine 2 47r Mine 2 48s Mine 2 49 tMine 2 5u Mine 2 50v Mine 2 51w Mine 2 52x Mine 2 53y Mine 2 54 zMine 2 6 {Mine 2 7 |Mine 2 8 }Mine 2 9 ~Mine 20 Mine 21 Mine 22 Mine 23 Mine 24 Mine 25 Mine 26 Mine 27 Mine 28 Mine 29 Mine 3 Mine 30 Mine 31 Mine 32 Mine 33 Mine 34 Mine 35 Mine 36 Mine 37 Mine 38 Mine 39 Mine 4 Mine 40 Mine 41 Mine 42 Mine 43 Mine 44 Mine 45 Mine 46 Mine 47 Mine 48 Mine 49 Mine 5 Mine 50 Mine 51 Mine 52 Mine 53 Mine 54 Mine 6 Mine 7 Mine 8 Mine 9 My Normal NeutralANeutral  e% Neutral 2@ Neutral 2  e3Normal % Normal 10 Normal 10 2 Normal 109 Normal 109 2 Normal 109 3 Normal 11 Normal 110 Normal 110 2 Normal 110 3 Normal 12 Normal 127 Normal 127 2 Normal 13 Normal 135 Normal 135 2 Normal 136 Normal 136 2 Normal 137 Normal 137 2 Normal 138 Normal 138 2 Normal 139 Normal 139 2 Normal 14 Normal 140 Normal 140 2 Normal 143 Normal 143 2 Normal 144 Normal 144 2 Normal 15 Normal 16 Normal 17 Normal 18 Normal 19 Normal 2 Normal 2 10 Normal 2 10 2 Normal 2 11 Normal 2 12 Normal 2 13 Normal 2 14 Normal 2 15 Normal 2 16 Normal 2 17 Normal 2 18Normal 2 18 10Normal 2 18 10 2Normal 2 18 10 3Normal 2 18 11Normal 2 18 11 2Normal 2 18 12Normal 2 18 12 2Normal 2 18 13Normal 2 18 13 2Normal 2 18 14Normal 2 18 14 2Normal 2 18 15Normal 2 18 15 2Normal 2 18 16Normal 2 18 16 2Normal 2 18 17Normal 2 18 17 2Normal 2 18 18Normal 2 18 18 2Normal 2 18 19Normal 2 18 19 2 Normal 2 18 2Normal 2 18 20Normal 2 18 20 2Normal 2 18 21Normal 2 18 21 2Normal 2 18 22Normal 2 18 22 2Normal 2 18 23Normal 2 18 23 2Normal 2 18 24Normal 2 18 25Normal 2 18 26Normal 2 18 27 Normal 2 18 3Normal 2 18 3 2Normal 2 18 3 3 Normal 2 18 4Normal 2 18 4 2Normal 2 18 4 3 Normal 2 18 5Normal 2 18 5 2Normal 2 18 5 3 Normal 2 18 6Normal 2 18 6 2Normal 2 18 6 3 Normal 2 18 7Normal 2 18 7 2 Normal 2 18 7 3  Normal 2 18 8 Normal 2 18 8 2 Normal 2 18 8 3  Normal 2 18 9Normal 2 18 9 2Normal 2 18 9 3 Normal 2 19Normal 2 19 10Normal 2 19 10 2Normal 2 19 10 3Normal 2 19 11Normal 2 19 11 2Normal 2 19 12Normal 2 19 12 2Normal 2 19 13Normal 2 19 13 2Normal 2 19 14Normal 2 19 14 2Normal 2 19 15Normal 2 19 15 2Normal 2 19 16Normal 2 19 16 2 Normal 2 19 17!Normal 2 19 17 2"Normal 2 19 18#Normal 2 19 18 2$Normal 2 19 19%Normal 2 19 19 2& Normal 2 19 2'Normal 2 19 20(Normal 2 19 20 2)Normal 2 19 21*Normal 2 19 21 2+Normal 2 19 22,Normal 2 19 22 2-Normal 2 19 23.Normal 2 19 23 2/Normal 2 19 240Normal 2 19 251Normal 2 19 262Normal 2 19 273 Normal 2 19 34Normal 2 19 3 25Normal 2 19 3 36 Normal 2 19 47Normal 2 19 4 28Normal 2 19 4 39 Normal 2 19 5:Normal 2 19 5 2;Normal 2 19 5 3< Normal 2 19 6=Normal 2 19 6 2>Normal 2 19 6 3? Normal 2 19 7@Normal 2 19 7 2ANormal 2 19 7 3B Normal 2 19 8CNormal 2 19 8 2DNormal 2 19 8 3E Normal 2 19 9FNormal 2 19 9 2GNormal 2 19 9 3H Normal 2 26 Normal 2 2 I Normal 2 2 10J Normal 2 2 11K Normal 2 2 12L Normal 2 2 13M Normal 2 2 14N Normal 2 2 15O Normal 2 2 16P Normal 2 2 17Q Normal 2 2 18R Normal 2 2 19S Normal 2 2 2TNormal 2 2 2 10UNormal 2 2 2 10 2VNormal 2 2 2 10 3WNormal 2 2 2 11XNormal 2 2 2 11 2YNormal 2 2 2 11 3ZNormal 2 2 2 12[Normal 2 2 2 12 2\Normal 2 2 2 12 3]Normal 2 2 2 13^Normal 2 2 2 13 2_Normal 2 2 2 13 3`Normal 2 2 2 14aNormal 2 2 2 14 2bNormal 2 2 2 14 3cNormal 2 2 2 15dNormal 2 2 2 15 2eNormal 2 2 2 16fNormal 2 2 2 16 2gNormal 2 2 2 17hNormal 2 2 2 17 2iNormal 2 2 2 18jNormal 2 2 2 18 2kNormal 2 2 2 19lNormal 2 2 2 2mNormal 2 2 2 20nNormal 2 2 2 21oNormal 2 2 2 22pNormal 2 2 2 23qNormal 2 2 2 24rNormal 2 2 2 25sNormal 2 2 2 26tNormal 2 2 2 27uNormal 2 2 2 28vNormal 2 2 2 29wNormal 2 2 2 3xNormal 2 2 2 3 2yNormal 2 2 2 3 3zNormal 2 2 2 3 4{Normal 2 2 2 3 5|Normal 2 2 2 3 6}Normal 2 2 2 30~Normal 2 2 2 30 2Normal 2 2 2 31Normal 2 2 2 31 2Normal 2 2 2 32Normal 2 2 2 32 2Normal 2 2 2 33Normal 2 2 2 33 2Normal 2 2 2 34Normal 2 2 2 34 2Normal 2 2 2 35Normal 2 2 2 35 2Normal 2 2 2 36Normal 2 2 2 36 2Normal 2 2 2 37Normal 2 2 2 37 2Normal 2 2 2 38Normal 2 2 2 39Normal 2 2 2 4Normal 2 2 2 40Normal 2 2 2 41Normal 2 2 2 42Normal 2 2 2 43Normal 2 2 2 44Normal 2 2 2 45Normal 2 2 2 46Normal 2 2 2 47Normal 2 2 2 48Normal 2 2 2 48 2Normal 2 2 2 49Normal 2 2 2 5Normal 2 2 2 5 2Normal 2 2 2 5 3Normal 2 2 2 5 4Normal 2 2 2 50@Normal 2 2 2 50 Normal 2 2 2 50 2DNormal 2 2 2 50 2 Normal 2 2 2 50 3DNormal 2 2 2 50 3 Normal 2 2 2 50 4DNormal 2 2 2 50 4 Normal 2 2 2 50 5DNormal 2 2 2 50 5 Normal 2 2 2 50 6DNormal 2 2 2 50 6 Normal 2 2 2 50 7DNormal 2 2 2 50 7 Normal 2 2 2 50 8DNormal 2 2 2 50 8 Normal 2 2 2 51@Normal 2 2 2 51 Normal 2 2 2 52@Normal 2 2 2 52 Normal 2 2 2 53@Normal 2 2 2 53 Normal 2 2 2 54Normal 2 2 2 55Normal 2 2 2 56Normal 2 2 2 57Normal 2 2 2 58Normal 2 2 2 59Normal 2 2 2 6Normal 2 2 2 60Normal 2 2 2 7Normal 2 2 2 7 2Normal 2 2 2 7 3Normal 2 2 2 8Normal 2 2 2 8 2Normal 2 2 2 8 3Normal 2 2 2 9Normal 2 2 2 9 2Normal 2 2 2 9 3 Normal 2 2 20 Normal 2 2 21 Normal 2 2 22 Normal 2 2 23 Normal 2 2 24 Normal 2 2 25Normal 2 2 25 10Normal 2 2 25 10 2Normal 2 2 25 10 3Normal 2 2 25 11Normal 2 2 25 11 2Normal 2 2 25 12Normal 2 2 25 12 2Normal 2 2 25 13Normal 2 2 25 13 2Normal 2 2 25 14Normal 2 2 25 14 2Normal 2 2 25 15Normal 2 2 25 15 2Normal 2 2 25 16Normal 2 2 25 16 2Normal 2 2 25 17Normal 2 2 25 17 2Normal 2 2 25 18Normal 2 2 25 18 2Normal 2 2 25 19Normal 2 2 25 19 2Normal 2 2 25 2Normal 2 2 25 20Normal 2 2 25 20 2Normal 2 2 25 21Normal 2 2 25 21 2Normal 2 2 25 22Normal 2 2 25 22 2Normal 2 2 25 23Normal 2 2 25 23 2Normal 2 2 25 24Normal 2 2 25 25Normal 2 2 25 3Normal 2 2 25 3 2Normal 2 2 25 3 3Normal 2 2 25 4Normal 2 2 25 4 2Normal 2 2 25 4 3Normal 2 2 25 5Normal 2 2 25 5 2Normal 2 2 25 5 3Normal 2 2 25 6Normal 2 2 25 6 2Normal 2 2 25 6 3Normal 2 2 25 7Normal 2 2 25 7 2Normal 2 2 25 7 3Normal 2 2 25 8Normal 2 2 25 8 2Normal 2 2 25 8 3Normal 2 2 25 9Normal 2 2 25 9 2Normal 2 2 25 9 3 Normal 2 2 26 Normal 2 2 27 Normal 2 2 28Normal 2 2 28 10Normal 2 2 28 10 2Normal 2 2 28 11Normal 2 2 28 11 2Normal 2 2 28 12Normal 2 2 28 12 2Normal 2 2 28 13Normal 2 2 28 13 2Normal 2 2 28 14Normal 2 2 28 14 2Normal 2 2 28 15Normal 2 2 28 15 2Normal 2 2 28 16Normal 2 2 28 16 2Normal 2 2 28 17Normal 2 2 28 17 2 Normal 2 2 28 18 Normal 2 2 28 18 2 Normal 2 2 28 19 Normal 2 2 28 19 2 Normal 2 2 28 2Normal 2 2 28 2 2Normal 2 2 28 2 3Normal 2 2 28 20Normal 2 2 28 20 2Normal 2 2 28 21Normal 2 2 28 21 2Normal 2 2 28 22Normal 2 2 28 22 2Normal 2 2 28 3Normal 2 2 28 3 2Normal 2 2 28 3 3Normal 2 2 28 4Normal 2 2 28 4 2Normal 2 2 28 4 3Normal 2 2 28 5Normal 2 2 28 5 2Normal 2 2 28 5 3Normal 2 2 28 6 Normal 2 2 28 6 2!Normal 2 2 28 6 3"Normal 2 2 28 7#Normal 2 2 28 7 2$Normal 2 2 28 7 3%Normal 2 2 28 8&Normal 2 2 28 8 2'Normal 2 2 28 8 3(Normal 2 2 28 9)Normal 2 2 28 9 2*Normal 2 2 28 9 3+ Normal 2 2 29< Normal 2 2 29 , Normal 2 2 3- Normal 2 2 30< Normal 2 2 30 . Normal 2 2 31< Normal 2 2 31 / Normal 2 2 32< Normal 2 2 32 0 Normal 2 2 33< Normal 2 2 33 1 Normal 2 2 34< Normal 2 2 34 2 Normal 2 2 35< Normal 2 2 35 3 Normal 2 2 36< Normal 2 2 36 4 Normal 2 2 37< Normal 2 2 37 5 Normal 2 2 38< Normal 2 2 38 6 Normal 2 2 39< Normal 2 2 39 7 Normal 2 2 48 Normal 2 2 40< Normal 2 2 40 9 Normal 2 2 41< Normal 2 2 41 : Normal 2 2 42< Normal 2 2 42 ; Normal 2 2 43< Normal 2 2 43 < Normal 2 2 44< Normal 2 2 44 = Normal 2 2 45< Normal 2 2 45 > Normal 2 2 46< Normal 2 2 46 ? Normal 2 2 47< Normal 2 2 47 @ Normal 2 2 48< Normal 2 2 48 A Normal 2 2 49< Normal 2 2 49 B Normal 2 2 5C Normal 2 2 50< Normal 2 2 50 D Normal 2 2 51< Normal 2 2 51 E Normal 2 2 52< Normal 2 2 52 F Normal 2 2 53< Normal 2 2 53 G Normal 2 2 54< Normal 2 2 54 H Normal 2 2 55< Normal 2 2 55 I Normal 2 2 56< Normal 2 2 56 J Normal 2 2 57< Normal 2 2 57 K Normal 2 2 58< Normal 2 2 58 L Normal 2 2 59< Normal 2 2 59 M Normal 2 2 6N Normal 2 2 60< Normal 2 2 60 O Normal 2 2 61< Normal 2 2 61 P Normal 2 2 62< Normal 2 2 62 Q Normal 2 2 63< Normal 2 2 63 R Normal 2 2 64< Normal 2 2 64 S Normal 2 2 65< Normal 2 2 65 T Normal 2 2 66< Normal 2 2 66 U Normal 2 2 67< Normal 2 2 67 V Normal 2 2 68< Normal 2 2 68 W Normal 2 2 69< Normal 2 2 69 X Normal 2 2 7Y Normal 2 2 70< Normal 2 2 70 Z Normal 2 2 71< Normal 2 2 71 [ Normal 2 2 72< Normal 2 2 72 \ Normal 2 2 73< Normal 2 2 73 ] Normal 2 2 74< Normal 2 2 74 ^ Normal 2 2 75< Normal 2 2 75 _ Normal 2 2 76< Normal 2 2 76 ` Normal 2 2 77< Normal 2 2 77 a Normal 2 2 78< Normal 2 2 78 b Normal 2 2 79< Normal 2 2 79 c Normal 2 2 8d Normal 2 2 80< Normal 2 2 80 e Normal 2 2 85< Normal 2 2 85 f Normal 2 2 86< Normal 2 2 86 g Normal 2 2 9h Normal 2 20iNormal 2 20 10jNormal 2 20 10 2kNormal 2 20 10 3lNormal 2 20 11mNormal 2 20 11 2nNormal 2 20 12oNormal 2 20 12 2pNormal 2 20 13qNormal 2 20 13 2rNormal 2 20 14sNormal 2 20 14 2tNormal 2 20 15uNormal 2 20 15 2vNormal 2 20 16wNormal 2 20 16 2xNormal 2 20 17yNormal 2 20 17 2zNormal 2 20 18{Normal 2 20 18 2|Normal 2 20 19}Normal 2 20 19 2~ Normal 2 20 2Normal 2 20 20Normal 2 20 20 2Normal 2 20 21Normal 2 20 21 2Normal 2 20 22Normal 2 20 22 2Normal 2 20 23Normal 2 20 23 2Normal 2 20 24Normal 2 20 25Normal 2 20 26Normal 2 20 27 Normal 2 20 3Normal 2 20 3 2Normal 2 20 3 3 Normal 2 20 4Normal 2 20 4 2Normal 2 20 4 3 Normal 2 20 5Normal 2 20 5 2Normal 2 20 5 3 Normal 2 20 6Normal 2 20 6 2Normal 2 20 6 3 Normal 2 20 7Normal 2 20 7 2Normal 2 20 7 3 Normal 2 20 8Normal 2 20 8 2Normal 2 20 8 3 Normal 2 20 9Normal 2 20 9 2Normal 2 20 9 3 Normal 2 21Normal 2 21 10Normal 2 21 10 2Normal 2 21 10 3Normal 2 21 11Normal 2 21 11 2Normal 2 21 12Normal 2 21 12 2Normal 2 21 13Normal 2 21 13 2Normal 2 21 14Normal 2 21 14 2Normal 2 21 15Normal 2 21 15 2Normal 2 21 16Normal 2 21 16 2Normal 2 21 17Normal 2 21 17 2Normal 2 21 18Normal 2 21 18 2Normal 2 21 19Normal 2 21 19 2 Normal 2 21 2Normal 2 21 20Normal 2 21 20 2Normal 2 21 21Normal 2 21 21 2Normal 2 21 22Normal 2 21 22 2Normal 2 21 23Normal 2 21 23 2Normal 2 21 24Normal 2 21 25Normal 2 21 26Normal 2 21 27 Normal 2 21 3Normal 2 21 3 2Normal 2 21 3 3 Normal 2 21 4Normal 2 21 4 2Normal 2 21 4 3 Normal 2 21 5Normal 2 21 5 2Normal 2 21 5 3 Normal 2 21 6Normal 2 21 6 2Normal 2 21 6 3 Normal 2 21 7Normal 2 21 7 2Normal 2 21 7 3 Normal 2 21 8Normal 2 21 8 2Normal 2 21 8 3 Normal 2 21 9Normal 2 21 9 2Normal 2 21 9 3 Normal 2 22Normal 2 22 10Normal 2 22 10 2Normal 2 22 10 3Normal 2 22 11Normal 2 22 11 2Normal 2 22 12Normal 2 22 12 2Normal 2 22 13Normal 2 22 13 2Normal 2 22 14Normal 2 22 14 2Normal 2 22 15Normal 2 22 15 2Normal 2 22 16Normal 2 22 16 2Normal 2 22 17Normal 2 22 17 2Normal 2 22 18Normal 2 22 18 2Normal 2 22 19Normal 2 22 19 2 Normal 2 22 2Normal 2 22 20Normal 2 22 20 2Normal 2 22 21Normal 2 22 21 2Normal 2 22 22Normal 2 22 22 2Normal 2 22 23Normal 2 22 23 2Normal 2 22 24Normal 2 22 25Normal 2 22 26Normal 2 22 27 Normal 2 22 3Normal 2 22 3 2Normal 2 22 3 3 Normal 2 22 4Normal 2 22 4 2Normal 2 22 4 3 Normal 2 22 5Normal 2 22 5 2Normal 2 22 5 3 Normal 2 22 6Normal 2 22 6 2Normal 2 22 6 3 Normal 2 22 7Normal 2 22 7 2 Normal 2 22 7 3  Normal 2 22 8 Normal 2 22 8 2 Normal 2 22 8 3  Normal 2 22 9Normal 2 22 9 2Normal 2 22 9 3 Normal 2 23Normal 2 23 10Normal 2 23 10 2Normal 2 23 10 3Normal 2 23 11Normal 2 23 11 2Normal 2 23 12Normal 2 23 12 2Normal 2 23 13Normal 2 23 13 2Normal 2 23 14Normal 2 23 14 2Normal 2 23 15Normal 2 23 15 2Normal 2 23 16Normal 2 23 16 2 Normal 2 23 17!Normal 2 23 17 2"Normal 2 23 18#Normal 2 23 18 2$Normal 2 23 19%Normal 2 23 19 2& Normal 2 23 2'Normal 2 23 20(Normal 2 23 20 2)Normal 2 23 21*Normal 2 23 21 2+Normal 2 23 22,Normal 2 23 22 2-Normal 2 23 23.Normal 2 23 23 2/Normal 2 23 240Normal 2 23 251Normal 2 23 262Normal 2 23 273 Normal 2 23 34Normal 2 23 3 25Normal 2 23 3 36 Normal 2 23 47Normal 2 23 4 28Normal 2 23 4 39 Normal 2 23 5:Normal 2 23 5 2;Normal 2 23 5 3< Normal 2 23 6=Normal 2 23 6 2>Normal 2 23 6 3? Normal 2 23 7@Normal 2 23 7 2ANormal 2 23 7 3B Normal 2 23 8CNormal 2 23 8 2DNormal 2 23 8 3E Normal 2 23 9FNormal 2 23 9 2GNormal 2 23 9 3H Normal 2 24INormal 2 24 10JNormal 2 24 10 2KNormal 2 24 10 3LNormal 2 24 11MNormal 2 24 11 2NNormal 2 24 12ONormal 2 24 12 2PNormal 2 24 13QNormal 2 24 13 2RNormal 2 24 14SNormal 2 24 14 2TNormal 2 24 15UNormal 2 24 15 2VNormal 2 24 16WNormal 2 24 16 2XNormal 2 24 17YNormal 2 24 17 2ZNormal 2 24 18[Normal 2 24 18 2\Normal 2 24 19]Normal 2 24 19 2^ Normal 2 24 2_Normal 2 24 20`Normal 2 24 20 2aNormal 2 24 21bNormal 2 24 21 2cNormal 2 24 22dNormal 2 24 22 2eNormal 2 24 23fNormal 2 24 23 2gNormal 2 24 24hNormal 2 24 25iNormal 2 24 26jNormal 2 24 27k Normal 2 24 3lNormal 2 24 3 2mNormal 2 24 3 3n Normal 2 24 4oNormal 2 24 4 2pNormal 2 24 4 3q Normal 2 24 5rNormal 2 24 5 2sNormal 2 24 5 3t Normal 2 24 6uNormal 2 24 6 2vNormal 2 24 6 3w Normal 2 24 7xNormal 2 24 7 2yNormal 2 24 7 3z Normal 2 24 8{Normal 2 24 8 2|Normal 2 24 8 3} Normal 2 24 9~Normal 2 24 9 2Normal 2 24 9 3 Normal 2 25Normal 2 25 10Normal 2 25 10 2Normal 2 25 10 3Normal 2 25 11Normal 2 25 11 2Normal 2 25 12Normal 2 25 12 2Normal 2 25 13Normal 2 25 13 2Normal 2 25 14Normal 2 25 14 2Normal 2 25 15Normal 2 25 15 2Normal 2 25 16Normal 2 25 16 2Normal 2 25 17Normal 2 25 17 2Normal 2 25 18Normal 2 25 18 2Normal 2 25 19Normal 2 25 19 2 Normal 2 25 2Normal 2 25 20Normal 2 25 20 2Normal 2 25 21Normal 2 25 21 2Normal 2 25 22Normal 2 25 22 2Normal 2 25 23Normal 2 25 23 2Normal 2 25 24Normal 2 25 25Normal 2 25 26Normal 2 25 27 Normal 2 25 3Normal 2 25 3 2Normal 2 25 3 3 Normal 2 25 4Normal 2 25 4 2Normal 2 25 4 3 Normal 2 25 5Normal 2 25 5 2Normal 2 25 5 3 Normal 2 25 6Normal 2 25 6 2Normal 2 25 6 3 Normal 2 25 7Normal 2 25 7 2Normal 2 25 7 3 Normal 2 25 8Normal 2 25 8 2Normal 2 25 8 3 Normal 2 25 9Normal 2 25 9 2Normal 2 25 9 3 Normal 2 26Normal 2 26 10Normal 2 26 10 2Normal 2 26 10 3Normal 2 26 11Normal 2 26 11 2Normal 2 26 12Normal 2 26 12 2Normal 2 26 13Normal 2 26 13 2Normal 2 26 14Normal 2 26 14 2Normal 2 26 15Normal 2 26 15 2Normal 2 26 16Normal 2 26 16 2Normal 2 26 17Normal 2 26 17 2Normal 2 26 18Normal 2 26 18 2Normal 2 26 19Normal 2 26 19 2 Normal 2 26 2Normal 2 26 20Normal 2 26 20 2Normal 2 26 21Normal 2 26 21 2Normal 2 26 22Normal 2 26 22 2Normal 2 26 23Normal 2 26 23 2Normal 2 26 24Normal 2 26 25Normal 2 26 26Normal 2 26 27 Normal 2 26 3Normal 2 26 3 2Normal 2 26 3 3 Normal 2 26 4Normal 2 26 4 2Normal 2 26 4 3 Normal 2 26 5Normal 2 26 5 2Normal 2 26 5 3 Normal 2 26 6Normal 2 26 6 2Normal 2 26 6 3 Normal 2 26 7Normal 2 26 7 2Normal 2 26 7 3 Normal 2 26 8Normal 2 26 8 2Normal 2 26 8 3 Normal 2 26 9Normal 2 26 9 2Normal 2 26 9 3 Normal 2 27Normal 2 27 10Normal 2 27 10 2Normal 2 27 10 3Normal 2 27 11Normal 2 27 11 2Normal 2 27 12Normal 2 27 12 2Normal 2 27 13Normal 2 27 13 2Normal 2 27 14Normal 2 27 14 2Normal 2 27 15Normal 2 27 15 2Normal 2 27 16Normal 2 27 16 2Normal 2 27 17Normal 2 27 17 2Normal 2 27 18Normal 2 27 18 2Normal 2 27 19Normal 2 27 19 2 Normal 2 27 2Normal 2 27 20Normal 2 27 20 2 Normal 2 27 21 Normal 2 27 21 2 Normal 2 27 22 Normal 2 27 22 2 Normal 2 27 23Normal 2 27 23 2Normal 2 27 24Normal 2 27 25Normal 2 27 26Normal 2 27 27 Normal 2 27 3Normal 2 27 3 2Normal 2 27 3 3 Normal 2 27 4Normal 2 27 4 2Normal 2 27 4 3 Normal 2 27 5Normal 2 27 5 2Normal 2 27 5 3 Normal 2 27 6Normal 2 27 6 2Normal 2 27 6 3 Normal 2 27 7 Normal 2 27 7 2!Normal 2 27 7 3" Normal 2 27 8#Normal 2 27 8 2$Normal 2 27 8 3% Normal 2 27 9&Normal 2 27 9 2'Normal 2 27 9 3( Normal 2 28)Normal 2 28 10*Normal 2 28 10 2+Normal 2 28 10 3,Normal 2 28 11-Normal 2 28 11 2.Normal 2 28 12/Normal 2 28 12 20Normal 2 28 131Normal 2 28 13 22Normal 2 28 143Normal 2 28 14 24Normal 2 28 155Normal 2 28 15 26Normal 2 28 167Normal 2 28 16 28Normal 2 28 179Normal 2 28 17 2:Normal 2 28 18;Normal 2 28 18 2<Normal 2 28 19=Normal 2 28 19 2> Normal 2 28 2?Normal 2 28 20@Normal 2 28 20 2ANormal 2 28 21BNormal 2 28 21 2CNormal 2 28 22DNormal 2 28 22 2ENormal 2 28 23FNormal 2 28 23 2GNormal 2 28 24HNormal 2 28 25INormal 2 28 26JNormal 2 28 27K Normal 2 28 3LNormal 2 28 3 2MNormal 2 28 3 3N Normal 2 28 4ONormal 2 28 4 2PNormal 2 28 4 3Q Normal 2 28 5RNormal 2 28 5 2SNormal 2 28 5 3T Normal 2 28 6UNormal 2 28 6 2VNormal 2 28 6 3W Normal 2 28 7XNormal 2 28 7 2YNormal 2 28 7 3Z Normal 2 28 8[Normal 2 28 8 2\Normal 2 28 8 3] Normal 2 28 9^Normal 2 28 9 2_Normal 2 28 9 3` Normal 2 29a Normal 2 3b Normal 2 30cNormal 2 30 10dNormal 2 30 10 2eNormal 2 30 10 3fNormal 2 30 11gNormal 2 30 11 2hNormal 2 30 12iNormal 2 30 12 2jNormal 2 30 13kNormal 2 30 13 2lNormal 2 30 14mNormal 2 30 14 2nNormal 2 30 15oNormal 2 30 15 2pNormal 2 30 16qNormal 2 30 16 2rNormal 2 30 17sNormal 2 30 17 2tNormal 2 30 18uNormal 2 30 18 2vNormal 2 30 19wNormal 2 30 19 2x Normal 2 30 2yNormal 2 30 20zNormal 2 30 20 2{Normal 2 30 21|Normal 2 30 21 2}Normal 2 30 22~Normal 2 30 22 2Normal 2 30 23Normal 2 30 23 2Normal 2 30 24Normal 2 30 25Normal 2 30 26Normal 2 30 27 Normal 2 30 3Normal 2 30 3 2Normal 2 30 3 3 Normal 2 30 4Normal 2 30 4 2Normal 2 30 4 3 Normal 2 30 5Normal 2 30 5 2Normal 2 30 5 3 Normal 2 30 6Normal 2 30 6 2Normal 2 30 6 3 Normal 2 30 7Normal 2 30 7 2Normal 2 30 7 3 Normal 2 30 8Normal 2 30 8 2Normal 2 30 8 3 Normal 2 30 9Normal 2 30 9 2Normal 2 30 9 3 Normal 2 31Normal 2 31 10Normal 2 31 10 2Normal 2 31 10 3Normal 2 31 11Normal 2 31 11 2Normal 2 31 12Normal 2 31 12 2Normal 2 31 13Normal 2 31 13 2Normal 2 31 14Normal 2 31 14 2Normal 2 31 15Normal 2 31 15 2Normal 2 31 16Normal 2 31 16 2Normal 2 31 17Normal 2 31 17 2Normal 2 31 18Normal 2 31 18 2Normal 2 31 19Normal 2 31 19 2 Normal 2 31 2Normal 2 31 20Normal 2 31 20 2Normal 2 31 21Normal 2 31 21 2Normal 2 31 22Normal 2 31 22 2Normal 2 31 23Normal 2 31 23 2Normal 2 31 24Normal 2 31 25Normal 2 31 26Normal 2 31 27 Normal 2 31 3Normal 2 31 3 2Normal 2 31 3 3 Normal 2 31 4Normal 2 31 4 2Normal 2 31 4 3 Normal 2 31 5Normal 2 31 5 2Normal 2 31 5 3 Normal 2 31 6Normal 2 31 6 2Normal 2 31 6 3 Normal 2 31 7Normal 2 31 7 2Normal 2 31 7 3 Normal 2 31 8Normal 2 31 8 2Normal 2 31 8 3 Normal 2 31 9Normal 2 31 9 2Normal 2 31 9 3 Normal 2 32Normal 2 32 10Normal 2 32 10 2Normal 2 32 10 3Normal 2 32 11Normal 2 32 11 2Normal 2 32 12Normal 2 32 12 2Normal 2 32 13Normal 2 32 13 2Normal 2 32 14Normal 2 32 14 2Normal 2 32 15Normal 2 32 15 2Normal 2 32 16Normal 2 32 16 2Normal 2 32 17Normal 2 32 17 2Normal 2 32 18Normal 2 32 18 2Normal 2 32 19Normal 2 32 19 2 Normal 2 32 2Normal 2 32 20Normal 2 32 20 2Normal 2 32 21Normal 2 32 21 2Normal 2 32 22Normal 2 32 22 2Normal 2 32 23Normal 2 32 23 2Normal 2 32 24Normal 2 32 25Normal 2 32 26Normal 2 32 27 Normal 2 32 3Normal 2 32 3 2Normal 2 32 3 3 Normal 2 32 4Normal 2 32 4 2Normal 2 32 4 3 Normal 2 32 5Normal 2 32 5 2Normal 2 32 5 3 Normal 2 32 6Normal 2 32 6 2Normal 2 32 6 3 Normal 2 32 7Normal 2 32 7 2Normal 2 32 7 3 Normal 2 32 8Normal 2 32 8 2Normal 2 32 8 3 Normal 2 32 9Normal 2 32 9 2 Normal 2 32 9 3  Normal 2 33 Normal 2 33 10 Normal 2 33 10 2 Normal 2 33 10 3Normal 2 33 11Normal 2 33 11 2Normal 2 33 12Normal 2 33 12 2Normal 2 33 13Normal 2 33 13 2Normal 2 33 14Normal 2 33 14 2Normal 2 33 15Normal 2 33 15 2Normal 2 33 16Normal 2 33 16 2Normal 2 33 17Normal 2 33 17 2Normal 2 33 18Normal 2 33 18 2Normal 2 33 19Normal 2 33 19 2  Normal 2 33 2!Normal 2 33 20"Normal 2 33 20 2#Normal 2 33 21$Normal 2 33 21 2%Normal 2 33 22&Normal 2 33 22 2'Normal 2 33 23(Normal 2 33 23 2)Normal 2 33 24*Normal 2 33 25+Normal 2 33 26,Normal 2 33 27- Normal 2 33 3.Normal 2 33 3 2/Normal 2 33 3 30 Normal 2 33 41Normal 2 33 4 22Normal 2 33 4 33 Normal 2 33 54Normal 2 33 5 25Normal 2 33 5 36 Normal 2 33 67Normal 2 33 6 28Normal 2 33 6 39 Normal 2 33 7:Normal 2 33 7 2;Normal 2 33 7 3< Normal 2 33 8=Normal 2 33 8 2>Normal 2 33 8 3? Normal 2 33 9@Normal 2 33 9 2ANormal 2 33 9 3B Normal 2 34CNormal 2 34 10DNormal 2 34 10 2ENormal 2 34 10 3FNormal 2 34 11GNormal 2 34 11 2HNormal 2 34 12INormal 2 34 12 2JNormal 2 34 13KNormal 2 34 13 2LNormal 2 34 14MNormal 2 34 14 2NNormal 2 34 15ONormal 2 34 15 2PNormal 2 34 16QNormal 2 34 16 2RNormal 2 34 17SNormal 2 34 17 2TNormal 2 34 18UNormal 2 34 18 2VNormal 2 34 19WNormal 2 34 19 2X Normal 2 34 2YNormal 2 34 20ZNormal 2 34 20 2[Normal 2 34 21\Normal 2 34 21 2]Normal 2 34 22^Normal 2 34 22 2_Normal 2 34 23`Normal 2 34 23 2aNormal 2 34 24bNormal 2 34 25cNormal 2 34 26dNormal 2 34 27e Normal 2 34 3fNormal 2 34 3 2gNormal 2 34 3 3h Normal 2 34 4iNormal 2 34 4 2jNormal 2 34 4 3k Normal 2 34 5lNormal 2 34 5 2mNormal 2 34 5 3n Normal 2 34 6oNormal 2 34 6 2pNormal 2 34 6 3q Normal 2 34 7rNormal 2 34 7 2sNormal 2 34 7 3t Normal 2 34 8uNormal 2 34 8 2vNormal 2 34 8 3w Normal 2 34 9xNormal 2 34 9 2yNormal 2 34 9 3z Normal 2 35{Normal 2 35 10|Normal 2 35 10 2}Normal 2 35 10 3~Normal 2 35 11Normal 2 35 11 2Normal 2 35 12Normal 2 35 12 2Normal 2 35 13Normal 2 35 13 2Normal 2 35 14Normal 2 35 14 2Normal 2 35 15Normal 2 35 15 2Normal 2 35 16Normal 2 35 16 2Normal 2 35 17Normal 2 35 17 2Normal 2 35 18Normal 2 35 18 2Normal 2 35 19Normal 2 35 19 2 Normal 2 35 2Normal 2 35 20Normal 2 35 20 2Normal 2 35 21Normal 2 35 21 2Normal 2 35 22Normal 2 35 22 2Normal 2 35 23Normal 2 35 23 2Normal 2 35 24Normal 2 35 25Normal 2 35 26Normal 2 35 27 Normal 2 35 3Normal 2 35 3 2Normal 2 35 3 3 Normal 2 35 4Normal 2 35 4 2Normal 2 35 4 3 Normal 2 35 5Normal 2 35 5 2Normal 2 35 5 3 Normal 2 35 6Normal 2 35 6 2Normal 2 35 6 3 Normal 2 35 7Normal 2 35 7 2Normal 2 35 7 3 Normal 2 35 8Normal 2 35 8 2Normal 2 35 8 3 Normal 2 35 9Normal 2 35 9 2Normal 2 35 9 3 Normal 2 36 Normal 2 36 2Normal 2 36 2 10Normal 2 36 2 10 2Normal 2 36 2 11Normal 2 36 2 11 2Normal 2 36 2 12Normal 2 36 2 12 2Normal 2 36 2 13Normal 2 36 2 13 2Normal 2 36 2 14Normal 2 36 2 14 2Normal 2 36 2 15Normal 2 36 2 15 2Normal 2 36 2 16Normal 2 36 2 16 2Normal 2 36 2 17Normal 2 36 2 17 2Normal 2 36 2 18Normal 2 36 2 18 2Normal 2 36 2 19Normal 2 36 2 19 2Normal 2 36 2 2Normal 2 36 2 2 2Normal 2 36 2 2 3Normal 2 36 2 20Normal 2 36 2 20 2Normal 2 36 2 21Normal 2 36 2 21 2Normal 2 36 2 22Normal 2 36 2 22 2Normal 2 36 2 23Normal 2 36 2 24Normal 2 36 2 3Normal 2 36 2 3 2Normal 2 36 2 3 3Normal 2 36 2 4Normal 2 36 2 4 2Normal 2 36 2 4 3Normal 2 36 2 5Normal 2 36 2 5 2Normal 2 36 2 5 3Normal 2 36 2 6Normal 2 36 2 6 2Normal 2 36 2 6 3Normal 2 36 2 7Normal 2 36 2 7 2Normal 2 36 2 7 3Normal 2 36 2 8Normal 2 36 2 8 2Normal 2 36 2 8 3Normal 2 36 2 9Normal 2 36 2 9 2Normal 2 36 2 9 3 Normal 2 36 3 Normal 2 36 4 Normal 2 36 5 Normal 2 36 6 Normal 2 37 Normal 2 37 2Normal 2 37 2 10Normal 2 37 2 10 2Normal 2 37 2 11Normal 2 37 2 11 2Normal 2 37 2 12Normal 2 37 2 12 2Normal 2 37 2 13Normal 2 37 2 13 2Normal 2 37 2 14Normal 2 37 2 14 2Normal 2 37 2 15Normal 2 37 2 15 2Normal 2 37 2 16Normal 2 37 2 16 2Normal 2 37 2 17Normal 2 37 2 17 2Normal 2 37 2 18Normal 2 37 2 18 2Normal 2 37 2 19Normal 2 37 2 19 2Normal 2 37 2 2Normal 2 37 2 2 2Normal 2 37 2 2 3Normal 2 37 2 20Normal 2 37 2 20 2Normal 2 37 2 21Normal 2 37 2 21 2 Normal 2 37 2 22 Normal 2 37 2 22 2 Normal 2 37 2 23 Normal 2 37 2 24 Normal 2 37 2 3Normal 2 37 2 3 2Normal 2 37 2 3 3Normal 2 37 2 4Normal 2 37 2 4 2Normal 2 37 2 4 3Normal 2 37 2 5Normal 2 37 2 5 2Normal 2 37 2 5 3Normal 2 37 2 6Normal 2 37 2 6 2Normal 2 37 2 6 3Normal 2 37 2 7Normal 2 37 2 7 2Normal 2 37 2 7 3Normal 2 37 2 8Normal 2 37 2 8 2Normal 2 37 2 8 3Normal 2 37 2 9 Normal 2 37 2 9 2!Normal 2 37 2 9 3" Normal 2 37 3# Normal 2 37 4$ Normal 2 37 5% Normal 2 37 6& Normal 2 38' Normal 2 38 2(Normal 2 38 2 10)Normal 2 38 2 10 2*Normal 2 38 2 11+Normal 2 38 2 11 2,Normal 2 38 2 12-Normal 2 38 2 12 2.Normal 2 38 2 13/Normal 2 38 2 13 20Normal 2 38 2 141Normal 2 38 2 14 22Normal 2 38 2 153Normal 2 38 2 15 24Normal 2 38 2 165Normal 2 38 2 16 26Normal 2 38 2 177Normal 2 38 2 17 28Normal 2 38 2 189Normal 2 38 2 18 2:Normal 2 38 2 19;Normal 2 38 2 19 2<Normal 2 38 2 2=Normal 2 38 2 2 2>Normal 2 38 2 2 3?Normal 2 38 2 20@Normal 2 38 2 20 2ANormal 2 38 2 21BNormal 2 38 2 21 2CNormal 2 38 2 22DNormal 2 38 2 22 2ENormal 2 38 2 23FNormal 2 38 2 24GNormal 2 38 2 3HNormal 2 38 2 3 2INormal 2 38 2 3 3JNormal 2 38 2 4KNormal 2 38 2 4 2LNormal 2 38 2 4 3MNormal 2 38 2 5NNormal 2 38 2 5 2ONormal 2 38 2 5 3PNormal 2 38 2 6QNormal 2 38 2 6 2RNormal 2 38 2 6 3SNormal 2 38 2 7TNormal 2 38 2 7 2UNormal 2 38 2 7 3VNormal 2 38 2 8WNormal 2 38 2 8 2XNormal 2 38 2 8 3YNormal 2 38 2 9ZNormal 2 38 2 9 2[Normal 2 38 2 9 3\ Normal 2 39] Normal 2 39 2^Normal 2 39 2 10_Normal 2 39 2 10 2`Normal 2 39 2 11aNormal 2 39 2 11 2bNormal 2 39 2 12cNormal 2 39 2 12 2dNormal 2 39 2 13eNormal 2 39 2 13 2fNormal 2 39 2 14gNormal 2 39 2 14 2hNormal 2 39 2 15iNormal 2 39 2 15 2jNormal 2 39 2 16kNormal 2 39 2 16 2lNormal 2 39 2 17mNormal 2 39 2 17 2nNormal 2 39 2 18oNormal 2 39 2 18 2pNormal 2 39 2 19qNormal 2 39 2 19 2rNormal 2 39 2 2sNormal 2 39 2 2 2tNormal 2 39 2 2 3uNormal 2 39 2 20vNormal 2 39 2 20 2wNormal 2 39 2 21xNormal 2 39 2 21 2yNormal 2 39 2 22zNormal 2 39 2 22 2{Normal 2 39 2 23|Normal 2 39 2 24}Normal 2 39 2 3~Normal 2 39 2 3 2Normal 2 39 2 3 3Normal 2 39 2 4Normal 2 39 2 4 2Normal 2 39 2 4 3Normal 2 39 2 5Normal 2 39 2 5 2Normal 2 39 2 5 3Normal 2 39 2 6Normal 2 39 2 6 2Normal 2 39 2 6 3Normal 2 39 2 7Normal 2 39 2 7 2Normal 2 39 2 7 3Normal 2 39 2 8Normal 2 39 2 8 2Normal 2 39 2 8 3Normal 2 39 2 9Normal 2 39 2 9 2Normal 2 39 2 9 3 Normal 2 4 Normal 2 40Normal 2 40 10Normal 2 40 10 2Normal 2 40 11Normal 2 40 11 2Normal 2 40 12Normal 2 40 12 2Normal 2 40 13Normal 2 40 13 2Normal 2 40 14Normal 2 40 14 2Normal 2 40 15Normal 2 40 15 2Normal 2 40 16Normal 2 40 16 2Normal 2 40 17Normal 2 40 17 2Normal 2 40 18Normal 2 40 18 2Normal 2 40 19Normal 2 40 19 2 Normal 2 40 2Normal 2 40 2 2Normal 2 40 2 3Normal 2 40 20Normal 2 40 20 2Normal 2 40 21Normal 2 40 21 2Normal 2 40 22Normal 2 40 22 2Normal 2 40 23Normal 2 40 24 Normal 2 40 3Normal 2 40 3 2Normal 2 40 3 3 Normal 2 40 4Normal 2 40 4 2Normal 2 40 4 3 Normal 2 40 5Normal 2 40 5 2Normal 2 40 5 3 Normal 2 40 6Normal 2 40 6 2Normal 2 40 6 3 Normal 2 40 7Normal 2 40 7 2Normal 2 40 7 3 Normal 2 40 8Normal 2 40 8 2Normal 2 40 8 3 Normal 2 40 9Normal 2 40 9 2Normal 2 40 9 3 Normal 2 41Normal 2 41 10Normal 2 41 10 2Normal 2 41 11Normal 2 41 11 2Normal 2 41 12Normal 2 41 12 2Normal 2 41 13Normal 2 41 13 2Normal 2 41 14Normal 2 41 14 2Normal 2 41 15Normal 2 41 15 2Normal 2 41 16Normal 2 41 16 2Normal 2 41 17Normal 2 41 17 2Normal 2 41 18Normal 2 41 18 2Normal 2 41 19Normal 2 41 19 2 Normal 2 41 2Normal 2 41 2 2Normal 2 41 2 3Normal 2 41 20Normal 2 41 20 2Normal 2 41 21Normal 2 41 21 2Normal 2 41 22Normal 2 41 22 2 Normal 2 41 3Normal 2 41 3 2Normal 2 41 3 3 Normal 2 41 4Normal 2 41 4 2Normal 2 41 4 3 Normal 2 41 5Normal 2 41 5 2Normal 2 41 5 3 Normal 2 41 6Normal 2 41 6 2Normal 2 41 6 3 Normal 2 41 7Normal 2 41 7 2Normal 2 41 7 3 Normal 2 41 8Normal 2 41 8 2Normal 2 41 8 3 Normal 2 41 9Normal 2 41 9 2Normal 2 41 9 3 Normal 2 42 Normal 2 43 Normal 2 44 Normal 2 45 Normal 2 46 Normal 2 47 Normal 2 48 Normal 2 49 Normal 2 5 Normal 2 50 Normal 2 51 Normal 2 52 Normal 2 6 Normal 2 7  Normal 2 8  Normal 2 808 Normal 2 80   Normal 2 9  Normal 20  Normal 21 Normal 22 Normal 23 Normal 24 Normal 25 Normal 26 Normal 27 Normal 28 Normal 29 Normal 3 Normal 3 10 Normal 3 11 Normal 3 12 Normal 3 13 Normal 3 14 Normal 3 15 Normal 3 16 Normal 3 17 Normal 3 18  Normal 3 19! Normal 3 2" Normal 3 20# Normal 3 21$ Normal 3 22% Normal 3 23& Normal 3 24' Normal 3 25( Normal 3 26) Normal 3 27* Normal 3 28+ Normal 3 29, Normal 3 3- Normal 3 30. Normal 3 4/ Normal 3 50 Normal 3 61 Normal 3 72 Normal 3 83 Normal 3 94 Normal 305 Normal 316 Normal 327 Normal 338 Normal 349 Normal 35: Normal 36; Normal 37< Normal 38= Normal 39 >Normal 4? Normal 40@ Normal 41A Normal 42B Normal 43C Normal 44D Normal 45E Normal 46F Normal 47G Normal 48H Normal 49 INormal 5J Normal 50K Normal 51L Normal 52M Normal 53N Normal 54O Normal 55P Normal 56Q Normal 57R Normal 58S Normal 59 TNormal 6U Normal 6 2V Normal 6 2 10WNormal 6 2 10 2XNormal 6 2 10 3Y Normal 6 2 11ZNormal 6 2 11 2[ Normal 6 2 12\Normal 6 2 12 2] Normal 6 2 13^Normal 6 2 13 2_ Normal 6 2 14`Normal 6 2 14 2a Normal 6 2 15bNormal 6 2 15 2c Normal 6 2 16dNormal 6 2 16 2e Normal 6 2 17fNormal 6 2 17 2g Normal 6 2 18hNormal 6 2 18 2i Normal 6 2 19jNormal 6 2 19 2k Normal 6 2 2l Normal 6 2 20mNormal 6 2 20 2n Normal 6 2 21oNormal 6 2 21 2p Normal 6 2 22qNormal 6 2 22 2r Normal 6 2 23sNormal 6 2 23 2t Normal 6 2 24u Normal 6 2 25v Normal 6 2 26w Normal 6 2 27x Normal 6 2 3yNormal 6 2 3 2zNormal 6 2 3 3{ Normal 6 2 4|Normal 6 2 4 2}Normal 6 2 4 3~ Normal 6 2 5Normal 6 2 5 2Normal 6 2 5 3 Normal 6 2 6Normal 6 2 6 2Normal 6 2 6 3 Normal 6 2 7Normal 6 2 7 2Normal 6 2 7 3 Normal 6 2 8Normal 6 2 8 2Normal 6 2 8 3 Normal 6 2 9Normal 6 2 9 2Normal 6 2 9 3 Normal 6 3 Normal 60 Normal 61 Normal 62 Normal 63 Normal 64 Normal 65 Normal 66 Normal 67 Normal 68 Normal 69 Normal 7 108 Normal 7 10  Normal 7 118 Normal 7 11  Normal 7 128 Normal 7 12  Normal 7 138 Normal 7 13  Normal 7 148 Normal 7 14  Normal 7 158 Normal 7 15  Normal 7 168 Normal 7 16  Normal 7 178 Normal 7 17  Normal 7 188 Normal 7 18  Normal 7 198 Normal 7 19  Normal 7 2 Normal 7 2 10 Normal 7 2 11 Normal 7 2 12 Normal 7 2 13 Normal 7 2 14 Normal 7 2 15 Normal 7 2 16 Normal 7 2 17 Normal 7 2 18 Normal 7 2 19 Normal 7 2 2Normal 7 2 2 2Normal 7 2 2 3Normal 7 2 2 4Normal 7 2 2 5Normal 7 2 2 6 Normal 7 2 20 Normal 7 2 21 Normal 7 2 22 Normal 7 2 23 Normal 7 2 24 Normal 7 2 25 Normal 7 2 26 Normal 7 2 27 Normal 7 2 28 Normal 7 2 29 Normal 7 2 3 Normal 7 2 30 Normal 7 2 31 Normal 7 2 32 Normal 7 2 33 Normal 7 2 34 Normal 7 2 35 Normal 7 2 36 Normal 7 2 37 Normal 7 2 38 Normal 7 2 39 Normal 7 2 4 Normal 7 2 40 Normal 7 2 41 Normal 7 2 42 Normal 7 2 43 Normal 7 2 44 Normal 7 2 45 Normal 7 2 46 Normal 7 2 47 Normal 7 2 48< Normal 7 2 48 Normal 7 2 48 2@Normal 7 2 48 2 Normal 7 2 48 3@Normal 7 2 48 3 Normal 7 2 48 4@Normal 7 2 48 4 Normal 7 2 48 5@Normal 7 2 48 5 Normal 7 2 48 6@Normal 7 2 48 6 Normal 7 2 48 7@Normal 7 2 48 7 Normal 7 2 48 8@Normal 7 2 48 8  Normal 7 2 49< Normal 7 2 49  Normal 7 2 5 Normal 7 2 50< Normal 7 2 50  Normal 7 2 51< Normal 7 2 51  Normal 7 2 52 Normal 7 2 53 Normal 7 2 54 Normal 7 2 55 Normal 7 2 56 Normal 7 2 57 Normal 7 2 6 Normal 7 2 7 Normal 7 2 8 Normal 7 2 9 Normal 7 208 Normal 7 20  Normal 7 218 Normal 7 21  Normal 7 228 Normal 7 22  Normal 7 238 Normal 7 23  Normal 7 248 Normal 7 24  Normal 7 258 Normal 7 25  Normal 7 268 Normal 7 26  Normal 7 278 Normal 7 27  Normal 7 288 Normal 7 28  Normal 7 298 Normal 7 29  Normal 7 3 Normal 7 308 Normal 7 30  Normal 7 318 Normal 7 31  Normal 7 328 Normal 7 32  Normal 7 338 Normal 7 33  Normal 7 348 Normal 7 34  Normal 7 358 Normal 7 35  Normal 7 368 Normal 7 36  Normal 7 378 Normal 7 37  Normal 7 388 Normal 7 38  Normal 7 398 Normal 7 39  Normal 7 4 Normal 7 408 Normal 7 40  Normal 7 418 Normal 7 41  Normal 7 428 Normal 7 42  Normal 7 438 Normal 7 43  Normal 7 448 Normal 7 44  Normal 7 458 Normal 7 45  Normal 7 468 Normal 7 46  Normal 7 478 Normal 7 47  Normal 7 488 Normal 7 48  Normal 7 498 Normal 7 49  Normal 7 5; Normal 7 5 % Normal 7 508 Normal 7 50   Normal 7 51  Normal 7 66 Normal 7 6   Normal 7 76 Normal 7 7   Normal 7 86 Normal 7 8   Normal 7 96 Normal 7 9  Normal 70 Normal 71 Normal 72 Normal 73 Normal 74 Normal 75 Normal 76 Normal 76 2 Normal 77 Normal 78 Normal 78 2 Normal 79 Normal 8 Normal 80 Normal 81 Normal 82 Normal 83 Normal 84  Normal 85! Normal 86" Normal 87# Normal 88$ Normal 89 %Normal 9& Normal 9 2' Normal 9 3( Normal 9 4) Normal 90* Normal 91+ Normal 92, Normal 93- Normal 94. Normal 95/ Normal 960 Normal 971 Normal_Sheet2 2Noteb Note   3Note 2fNote 2   4OutputwOutput  ???%????????? ???5$Percent 6Style 1 7Title1Title I}% 8TotalMTotal %OO9 Warning Text? Warning Text %XTableStyleMedium2PivotStyleLight16` win2kcce-COMBINED-5.xlsaix5.3 hpux11.23ie7ie8 office2k7 office2010rhel4rhel5solaris8solaris9 solaris10weblogicserver11gwin2kwinxpwin2k3vistawin2k8win7win2k8r2YYYYYYYYYY Y Y Y Y YYYYYb:B1\:G4b1:8  Last modified: 2009-05-15Version: 5.20100428CCE IDCCE DescriptionCCE ParametersCCE Technical Mechanisms Old v4 CCE ID'CIS W2K Server Level 2 Benchmark v2.2.1;DISA Gold Disk Check Name for W2K (golddisk.win2k.ecve.txt)>IRS Internal Revenue Manual (IRM) -- (http://www.irs.gov/irm/) CCE-3858-8EThe required auditing for %SystemDrive% directory should be enabled. ;(1) set of accounts (2) events to audit (3) applicability!(1) defined by the object's SACL CCE-25x4.4.3.1 %System Drive% - Everyone: Failures (this folder, propagate inheritable permissions to all subfolders and files)? CCE-3748-1ZThe required auditing for the registry key HKEY_LOCAL_MACHINE\SOFTWARE should be enabled. <(1) set of accounts (2) events to audit (3) applicabilityCCE-899f4.4.3.2 HKLM\Software  Everyone: Failures (this key, propagate inheritable permission to all subkeys)Reg Auditing Local Machine CCE-3770-5XThe required auditing for the registry key HKEY_LOCAL_MACHINE\SYSTEM should be enabled. CCE-727d4.4.3.3 HKLM\System  Everyone: Failures (this key, propagate inheritable permission to all subkeys) CCE-3809-1OThe required permissions for the directory %ProgramFiles% should be assigned. ?(1) set of accounts (2) list of permissions (3) applicability"(1) defined by the object's DACL CCE-24p4.4.1.15 %ProgramFiles% - Administrators: Full; System: Full; Creator Owner: Full; Users: Read and Execute, ListProgram Files ACL CCE-3869-5\The required permissions for the directory %ProgramFiles%\Resource Kit should be assigned. CCE-570J4.4.1.16 %Program Files%\Resource Kit  Administrators: Full; System: Full Resource Kit ACL Servers and DCs CCE-3785-3`The required permissions for the directory %ProgramFiles%\Resource Pro Kit should be assigned. CCE-204N4.4.1.17 %Program Files%\Resource Pro Kit  Administrators: Full; System: FullResource Kit ACL Workstation CCE-3807-5NThe required permissions for the directory %SystemDrive% should be assigned. CCE-411o4.4.1.1 %SystemDrive%\ - Administrators: Full; System: Full; Creator Owner: Full; Users: Read and Execute, ListSystemDrive ACL CCE-2879-5VThe required permissions for the file %SystemDrive%\AUTOEXEC.BAT should be assigned. CCE-816F4.4.1.2 %SystemDrive%\autoexec.bat - Administrator: Full; System: FullAutoexec.bat ACL CCE-3344-9RThe required permissions for the file %SystemDrive%\BOOT.INI should be assigned. CCE-746C4.4.1.3 %SystemDrive%\boot.ini  Administrators: Full; System: Full BOOT.INI ACL CCE-3864-6TThe required permissions for the file %SystemDrive%\CONFIG.SYS should be assigned. CCE-987E4.4.1.4 %SystemDrive%\config.sys - Administrators: Full; System: FullCONFIG.SYS ACL CCE-3080-9`The required permissions for the file %SystemDrive%\Documents and Settings should be assigned. CCE-419q4.4.1.10 %SystemDrive%\Documents and Settings - Administrators: Full; System: Full; Users: Read and Execute, ListDocuments and Settings ACL CCE-3873-7sThe required permissions for the directory %SystemDrive%\Documents and Settings\Administrator should be assigned. CCE-120`4.4.1.11 %SystemDrive%\Documents and Settings\Administrator - Administrators: Full; System: Full(Documents and Settings\Administrator ACL CCE-3419-9oThe required permissions for the directory %SystemDrive%\Documents and Settings\All Users should be assigned. CCE-181{4.4.1.12 %SystemDrive%\Documents and Settings\All Users  Administrators: Full; System: Full; Users: Read and Execute, List$Documents and Settings\All Users ACL CCE-3763-0The required permissions for the directory %SystemDrive%\Documents and Settings\All Users\Documents\DrWatson should be assigned. CCE-8684.4.1.13 %SystemDrive%\Documents and Settings\All Users\Documents\DrWatson  Administrators: Full; System: Full;Creator Owner: Full; Users: Traverse Folder/Execute File, List Folder/Read Data, Read Attributes, Read Extended Attributes, Read Permissions (This folder, subfolders, and files); Users: Traverse Folder/Execute Files, CreateFiles/Write Data, Create Folder/Append Data (Subfolders and files only) DrWatson ACL CCE-3657-4The required permissions for the file %SystemDrive%\Documents and Settings\All Users\Documents\DrWatson\drwtsn32.log should be assigned. CCE-776DrWatson Log ACL CCE-3697-0rThe required permissions for the directory %SystemDrive%\Documents and Settings\Default User should be assigned. CCE-714~4.4.1.14 %SystemDrive%\Documents and Settings\Default User - Administrators: Full; System: Full; Users: Read and Execute, ListDefault User ACL CCE-3789-5PThe required permissions for the file %SystemDrive%\IO.SYS should be assigned. CCE-540A4.4.1.5 %SystemDrive%\io.sys - Administrators: Full; System: Full IO.SYS ACL CCE-3560-0SThe required permissions for the file %SystemDrive%\MSDOS.SYS should be assigned. CCE-602D4.4.1.6 %SystemDrive%\msdos.sys - Administrators: Full; System: Full MSDOS.SYS ACL CCE-3335-7VThe required permissions for the file %SystemDrive%\NTBOOTDD.SYS should be assigned. CCE-399G4.4.1.7 %SystemDrive%\ntbootdd.sys - Administrators: Full; System: FullNTBOOTDD.SYS ACL CCE-3749-9VThe required permissions for the file %SystemDrive%\NTDETECT.COM should be assigned. CCE-192G4.4.1.8 %SystemDrive%\ntdetect.com  Administrators: Full; System: FullNTDETECT.COM ACL CCE-3771-3OThe required permissions for the file %SystemDrive%\NTLDR should be assigned. CCE-561@4.4.1.9 %SystemDrive%\ntldr - Administrators: Full; System: Full NTLDR ACL CCE-2895-1SThe required permissions for the directory %SystemDrive%\Temp should be assigned. CCE-755Temp ACL CCE-3686-3`The required permissions for the directory %SystemDrive%\My Download Files should be assigned. CCE-341My Download ACL CCE-3083-3cThe required permissions for the file %SystemDrive%\System Volume Information should be assigned. CCE-971k4.4.1.47 %SystemDrive%\System Volume Information  (Do not allow permissions on this folder to be replaced) CCE-3105-4MThe required permissions for the directory %SystemRoot% should be assigned. CCE-645n4.4.1.18 %SystemRoot%  Administrators: Full; System: Full; Creator Onwer: Full; Users: Read and Execute, ListSystem Root ACL CCE-3876-0jThe required permissions for the directory %SystemRoot%\Driver Cache\I386\Driver.cab should be assigned. CCE-579Driver.cab ACL CCE-3519-6fThe required permissions for the directory %SystemRoot%\$NtServicePackUninstall$ should be assigned. CCE-505 CCE-3197-1CCE-640S4.4.1.19 %SystemRoot%\$NtServicePackUninstall$  Administrators: Full; System: Full%%SystemRoot%\$NtServicePackUninstall$ CCE-3342-3dThe required permissions for any of the %SystemRoot< %\$NtUninstall* directories should be assigned. CCE-328NT SP Uninstall ACL CCE-3505-5QThe required permissions for the directory %SystemRoot%\CSC should be assigned. CCE-134>4.4.1.20 %SystemRoot%\CSC  Administrators: Full; System: FullCSC ACL CCE-3791-1SThe required permissions for the directory %SystemRoot%\Debug should be assigned. CCE-293t4.4.1.21 %SystemRoot%\Debug - Administrators: Full; System: Full; Creator Owner: Full; Users: Read and Execute, List Debug ACL CCE-3192-2\The required permissions for the directory %SystemRoot%\Debug\UserMode should be assigned. CCE-944.4.1.22 %SystemRoot%\Debug\UserMode - Administrators: Full; System: Full; Users: Traverse Folder/Execute File, Listfolder/Read data, Create files/Write data (This folder, only); Create files/Write data, Create folders/Append data(Files only)UserMode Directory ACL CCE-3836-4TThe required permissions for the file %SystemRoot%\regedit.exe should be assigned. CCE-795F4.4.1.31 %SystemRoot%\regedit.exe  Administrators: Full; System: Fullregedit.exe ACL CCE-3091-6SThe required permissions for the directory %SystemDrive%\NTDS should be assigned. CCE-248NTDS ACL CCE-3862-0_The required permissions for the directory %SystemRoot%\Offline Web Pages should be assigned. CCE-398J4.4.1.23 %SystemRoot%\Offline Web Pages  Ignore Parent Permission Changes CCE-3867-9ZThe required permissions for the directory %SystemRoot%\Registration should be assigned. CCE-155T4.4.1.24 %SystemRoot%\Registration - Administrators: Full; System: Full; Users: ReadRegistration ACL CCE-3404-1TThe required permissions for the directory %SystemRoot%\repair should be assigned. CCE-873A4.4.1.25 %SystemRoot%\repair - Administrators: Full; System: Full Repair ACL CCE-3052-8VThe required permissions for the directory %SystemRoot%\security should be assigned. CCE-67X4.4.1.26 %SystemRoot%\security - Administrators: Full; System: Full; Creator Owner: Full Security ACL CCE-3879-4UThe required permissions for the directory %SystemRoot%\SYSVOL should be assigned. CCE-979 SYSVOL ACL CCE-3544-4dThe required permissions for the directory %SystemRoot%\SYSVOL\domain\Policies should be assigned. CCE-701#%SystemRoot%\SYSVOL\domain\Policies CCE-3408-2RThe required permissions for the directory %SystemRoot%\Temp should be assigned. CCE-380 CCE-3800-0VThe required permissions for the directory %SystemRoot%\System32 should be assigned. CCE-45w4.4.1.27 %SystemRoot%\system32 - Administrators: Full; System: Full; Creator Owner: Full; Users: Read and Execute, List System32 ACL CCE-3571-7^The required permissions for the directory %SystemRoot%\System32\arp.exe should be assigned. CCE-600j4.4.1.36 %SystemRoot%\system32\appmgmt  Administrators: Full; System: Full; Users: Read and Execute, List appmgmt ACL CCE-3712-7XThe required permissions for the file %SystemRoot%\System32\at.exe should be assigned. CCE-393J4.4.1.28 %SystemRoot%\system32\at.exe  Administrators: Full; System: Full at.exe ACL CCE-3716-8XThe required permissions for the file %SystemRoot%\System32\CONFIG should be assigned. CCE-197J4.4.1.37 %SystemRoot%\system32\config  Administrators: Full; System: Full CONFIG ACL CCE-3734-1eThe required permissions for the file %SystemRoot%\System32\CONFIG\AppEvent.evt should be assigned. CCE-765)%SystemRoot%\System32\CONFIG\AppEvent.evt CCE-3641-8^The required permissions for the file %SystemRoot%\System32\CONFIG\*.evt should be assigned. CCE-334)%SystemRoot%\System32\CONFIG\SecEvent.evt CCE-3540-2_The required permissions for the directory %SystemRoot%\System32\dllcache should be assigned. CCE-350a4.4.1.38 %SystemRoot%\system32\dllcache  Administrators: Full; System: Full; Creator Owner: Full dllcache ACL CCE-3831-5]The required permissions for the directory %SystemRoot%\System32\DTCLog should be assigned. CCE-361}4.4.1.39 %SystemRoot%\system32\DTCLog - Administrators: Full; System: Full; Creator Owner: Full; Users: Read andExecute, List CCE-3745-7bThe required permissions for the directory %SystemRoot%\System32\GroupPolicy should be assigned. CCE-789|4.4.1.40 %SystemRoot%\system32\Group Policy - Administrators: Full; System: Full; Authenticated Users: Read andExecute, ListGroupPolicy ACL CCE-3890-1ZThe required permissions for the directory %SystemRoot%\System32\ias should be assigned. CCE-894\4.4.1.41 %SystemRoot%\system32\ias - Administrators: Full; System: Full; Creator Owner: Fullias ACL CCE-3784-6^The required permissions for the file %SystemRoot%\System32\Ntbackup.exe should be assigned. CCE-821P4.4.1.29 %SystemRoot%\system32\Ntbackup.exe  Administrators: Full; System: FullNTbackup.exe ACL CCE-3793-7_The required permissions for the directory %SystemRoot%\System32\NTMSData should be assigned. CCE-486L4.4.1.42 %SystemRoot%\system32\NTMSData  Administrators: Full; System: Full NTMSData ACL CCE-3815-8YThe required permissions for the file %SystemRoot%\System32\Rcp.exe should be assigned. CCE-997K4.4.1.30 %SystemRoot%\system32\rcp.exe  Administrators: Full; System: Full Rcp.exe ACL CCE-3824-0^The required permissions for the file %SystemRoot%\System32\Regedt32.exe should be assigned. CCE-865P4.4.1.32 %SystemRoot%\system32\regedt32.exe  Administrators: Full; System: FullRegedt32.exe ACL CCE-3595-6gThe required permissions for the directory %SystemRoot%\system32\ReinstallBackups should be assigned. CCE-894.4.1.43 %SystemRoot%\system32\reinstallbackups  Administrators: Full; System: Full; Creator Owner: Full; PowerUsers: Read and Execute, List CCE-3516-2[The required permissions for the file %SystemRoot%\System32\Rexec.exe should be assigned. CCE-274M4.4.1.33 %SystemRoot%\system32\rexec.exe  Administrators: Full; System: Full Rexec.exe ACL CCE-3520-4YThe required permissions for the file %SystemRoot%\System32\Rsh.exe should be assigned. CCE-353K4.4.1.34 %SystemRoot%\system32\rsh.exe  Administrators: Full; System: Full Rsh.exe ACL CCE-3776-2]The required permissions for the file %SystemRoot%\System32\Secedit.exe should be assigned. CCE-922O4.4.1.35 %SystemRoot%\system32\secedit.exe  Administrators: Full; System: Full CCE-3670-7\The required permissions for the directory %SystemRoot%\System32\Setup should be assigned. CCE-587h4.4.1.44 %SystemRoot%\system32\Setup  Administrators: Full; System: Full; Users: Read and Execute, List Setup ACL CCE-3340-7[The required permissions for the directory %SystemRoot%\System32\repl should be assigned. CCE-326repl ACL CCE-3780-4bThe required permissions for the directory %SystemRoot%\System32\repl\export should be assigned. < CCE-357 Export ACL CCE-3423-1bThe required permissions for the directory %SystemRoot%\System32\repl\import should be assigned. CCE-291 Import ACL CCE-3802-6eThe required permissions for the directory %SystemRoot%\System32\spool\Printers should be assigned. CCE-6924.4.1.45 %SystemRoot%\system32\spool\printers  Administrators: Full; System: Full; Creator Owner: Full; Users:Traverse Folder, Execute File, Read, Read Extended Attributes, Create folders, Append DataSpool\Printers ACL CCE-3079-1SThe required permissions for the directory %SystemRoot%\Tasks should be assigned. CCE-322V4.4.1.46 %SystemRoot%\Tasks - (Do not allow permissions on this folder to be replaced) CCE-3727-5]The required permissions for the directory %ALL%\Program Files\MQSeries should be assigned. CCE-864 MQSeries ACL CCE-3493-4cThe required permissions for the directory %ALL%\Program Files\MQSeries\qmggr should be assigned. CCE-364MQSeries Queue ACL CCE-3872-9The required permissions for the directory %SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\HTML Help ACL should be assigned. CCE-46 CCE-3656-6vThe required permissions for the directory %SystemDrive%\WINNT\SECURITY\Database\SECEDIT.SDB ACL should be assigned. CCE-447SECEDIT.SDB ACL CCE-2929-8UThe required permissions for the registry key HKEY_CLASSES_ROOT should be assigned. CCE-760Registry ACL Check CLASSES_ROOT CCE-3308-4_The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE should be assigned. CCE-279[4.4.2.2 HKLM\Software  Administrators Full; System: Full; Creator Owner: Full; Users: ReadRegistry ACL Check Software CCE-3723-4gThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes should be assigned. CCE-843d4.4.2.1 HKLM\Software\Classes - Administrators: Full; System: Full; Creator Owner: Full; Users: Read CCE-3868-7The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Regfile\Shell\Open\Command should be assigned. CCE-253-\SOFTWARE\Classes\Regfile\Shell\Open\Command CCE-3563-4pThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetDDE should be assigned. CCE-394L4.4.2.3 HKLM\Software\Microsoft\Net DDE  Administrators: Full; System: FullReg ACL NetDDE Check test CCE-3691-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OS/2 Subsystem for NT should be assigned. CCE-240o4.4.2.4 HKLM\Software\Microsoft\OS/2 Subsystem for NT  Administrators: Full; System: Full; Creator Owner: FullReg ACL OS2 Check test CCE-3735-8The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\Commands should be assigned. CCE-6184.4.2.5 HKLM\Software\Microsoft\Windows NT\CurrentVersion\AsrCommands  Administrators: Full; System: Full;Creator Owner: Full; Users: Read; Backup Operators: Query Value, Set Value, Create Subkey, EnumerateSubkeys, Notify, Delete, Read (this key and subkeys)Reg ACL Check AsrCommands CCE-3242-5The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib should be assigned. CCE-194.4.2.6 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Perflib  Administrators: Full; System: Full; CreatorOwner: Full; Interactive: Read (this key and subkeys)Registry ACL Check Perflib CCE-3374-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy should be assigned. CCE-7904.4.2.7 HKLM\Software\Microsoft\Windows\CurrentVersion\Group Policy - Administrators: Full; System: Full;Authenticated Users: ReadReg ACL Check Group Policy CCE-3167-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer should be assigned. CCE-268q4.4.2.8 HKLM\Software\Microsoft\Windows\CurrentVersion\Installer - Administrators Full; System: Full; Users: ReadReg ACL Check Installer CCE-3533-7The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies should be assigned. CCE-321~4.4.2.9 HKLM\Software\Microsoft\Windows\CurrentVersion\Policies - Administrators: Full; System: Full; AuthenticatedUsers: ReadReg ACL Check Policies CCE-2897-7]The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM should be assigned. CCE-135Z4.4.2.10 HKLM\System - Administrators Full; System: Full; Creator Owner: Full; Users: ReadRegistry ACL Check SYSTEM CCE-3839-8cThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\clone should be assigned. CCE-558V4.4.2.11 HKLM\System\Clone  Allow inheritable permissions to propagate to this object CCE-3865-3kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset001 should be assigned. CCE-867h4.4.2.12 HKLM\System\ControlSet001 - Administrators Full; System: Full; Creator Owner: Full; Users: Read Registry ACL Check controlset001 CCE-3513-9kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset002 should be assigned. CCE-545h4.4.2.13 HKLM\System\ControlSet00x - Administrators Full; System: Full; Creator Owner: Full; Users: Read Registry ACL Check controlset002 CCE-3896-8kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset003 should be assigned. CCE-289 Registry ACL Check controlset003 CCE-3838-0kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset004 should be assigned. CCE-465 Registry ACL Check controlset004 CCE-3750-7kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset005 should be assigned. CCE-254 Registry ACL Check controlset005 CCE-3384-5kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset006 should be assigned. CCE-606 Registry ACL Check controlset006 CCE-3680-6kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset007 should be assigned. CCE-694 Registry ACL Check controlset007 CCE-3816-6kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset008 should be assigned. CCE-500 Registry ACL Check controlset008 CCE-3318-3kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset009 should be assigned. CCE-809 Registry ACL Check controlset009 CCE-3882-8kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\controlset010 should be assigned. CCE-99 Registry ACL Check controlset010 CCE-3521-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg should be assigned. CCE-934^4.4.2.14 HKLM\System\CurrentControlSet\Control\SecurePipeServers\WinReg  Administrators: Full Winreg ACL CCE-2932-2The required permissions for the < registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Wmi\Security should be assigned. CCE-534.4.2.15 HKLM\System\CurrentControlSet\Control\WMI\Security  Administrators: Full; System: Full; Creator Owner: Full(this key and subkeys)Registry ACL Check Security CCE-3651-7tThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum should be assigned. CCE-269c4.4.2.16 HKLM\System\CurrentControlSet\Enum - (Do not allow permissions on this key to be replaced) CCE-3210-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles should be assigned. CCE-960}4.4.2.17 HKLM\System\CurrentControlSet\Hardware Profiles  Administrators Full; System: Full; Creator Owner: Full;Users: Read$Registry ACL Check Hardware Profiles CCE-3466-0The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\PermittedManagers should be assigned. CCE-3304.4.2.18 HKLM\System\CurrentControlSet\Services\SNMP\Parameters\PermittedManagers - Administrators Full; System: Full;Creator Owner: Full%Registry ACL Check Permitted Managers CCE-2978-5The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities should be assigned. CCE-5944.4.2.19 HKLM\System\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities - Administrators Full; System: Full;Creator Owner: Full#Registry ACL Check ValidCommunities CCE-3957-8XThe required permissions for the registry key HKEY_USERS\.DEFAULT should be assigned. CCE-127[4.4.2.20 HKU\.Default - Administrators Full; System: Full; Creator Owner: Full; Users: ReadRegistry ACL Check Default CCE-3961-0qThe required permissions for the registry key HKEY_USERS\.DEFAULT\Software\Microsoft\NetDDE should be assigned. CCE-483S4.4.2.21 HKU\.Default\Software\Microsoft\NetDDE - Administrators Full; System: FullRegistry ACL Check NetDDE CCE-3732-5The required permissions for the registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Protected Storage System Provider should be assigned. CCE-796W4.4.2.22 HKU\.Default\Software\Microsoft\Protected Storage System Provider  No entries CCE-3737-4CCE-845 CCE-3503-0jThe "deny access to this computer from the network" user right should be assigned to the correct accounts.(1) set of accountsM(1) defined by the SeDenyNetworkLogonRight setting in Local or Group Policy CCE-898<4.2.11 Deny access to this computer from the network: Guests)User Right Check deny access from network CCE-3917-2dThe "access this computer from the network" user right should be assigned to the correct accounts. I(1) defined by the SeNetworkLogonRight setting in Local or Group Policy CCE-532L4.2.1 Access this computer from the network: Users, Administrators (or none)User Right Check Network Logon CCE-3736-6bThe "act as part of the operating system" user right should be assigned to the correct accounts. D(1) defined the SeTcbPrivilege setting in by Local or Group Policy CCE-162/4.2.2 Act as part of the operating system: NoneUser Right Check Act as OS CCE-3393-6\The "back up files and directories" user right should be assigned to the correct accounts. G(1) defined the SeBackupPrivilege setting in by Local or Group Policy CCE-93134.2.4 Back up files and directories: AdministratorsUser Right Check Backup CCE-3653-3WThe "bypass traverse checking" user right should be assigned to the correct accounts. M(1) defined the SeChangeNotifyPrivilege setting in by Local or Group Policy CCE-376%4.2.5 Bypass traverse checking: Users)User Right Check Bypass Traverse checking CCE-3296-1UThe "change the system time" user right should be assigned to the correct accounts. K(1) defined the SeSystemTimePrivilege setting in by Local or Group Policy CCE-799,4.2.6 Change the system time: Administrators#User Right Check change system time CCE-3943-8PThe "create a pagefile" user right should be assigned to the correct accounts. O(1) defined the SeCreatePagefilePrivilege setting in by Local or Group Policy CCE-895'4.2.7 Create a pagefile: Administrators User Right Check create pagefile CCE-3860-4TThe "Create a token object" user right should be assigned to the correct accounts. L(1) defined the SeCreateTokenPrivilege setting in by Local or Group Policy CCE-926!4.2.8 Create a token object: None$User Right Check create token object CCE-3767-1^The "create permanent shared objects" user right should be assigned to the correct accounts. P(1) defined the SeCreatePermanentPrivilege setting in by Local or Group Policy CCE-335+4.2.9 Create permanent shared objects: None0User Right Check create permanent shared objects CCE-3772-1MThe "debug programs" user right should be assigned to the correct accounts. F(1) defined the SeDebugPrivilege setting in by Local or Group Policy CCE-8424.2.10 Debug Programs: NoneUser Right Check debug programs CCE-3904-0bThe "force shutdown from a remote system" user right should be assigned to the correct accounts. O(1) defined the SeRemoteShutdownPrivilege setting in by Local or Group Policy CCE-754:4.2.16 Force shutdown from a remote system: Administrators User Right Check remote shutdown CCE-3811-7WThe "generate security audits" user right should be assigned to the correct accounts. F(1) defined the SeAuditPrivilege setting in by Local or Group Policy CCE-939%4.2.17 Generate security audits: None)User Right Check generate security audits CCE-3688-9aThe "adjust memory quotas for a process" user right should be assigned to the correct accounts. N(1) defined the SeIncreaseQuotaPrivilege setting in by Local or Group Policy CCE-807&4.2.18 Increase quotas: Administrators User Right Check increase quotas CCE-3630-1[The "increase scheduling priority" user right should be assigned to the correct accounts. U(1) defined the SeIncreaseBasePriorityPrivilege setting in by Local or Group Policy CCE-34934.2.19 Increase scheduling priority: Administrators-User Right Check increase scheduling priority CCE-3798-6]The "load and unload device drivers" user right should be assigned to the correct accounts. K(1) defined the SeLoadDriverPrivilege setting in by Local or Group Policy CCE-86054.2.20 Load and unload device drivers: Administrators/User Right Check load and unload device drivers CCE-3317-5SThe "lock pages in memory" user right should be assigned to the correct accounts. K(1) defined the SeLockMemoryPrivilege setting in by Local or Group Policy CCE-749!4.2.21 Lock pages in memory: None%User Right Check lock pages in memory CCE-3965-1TThe "log on as a batch job" user right should be assigned to the correct accounts. G(1) defined the SeBatchLogonRight setting in by Local or Group Policy CCE-177"4.2.22 Log on as a batch job: None&User Right Check log on as a batch job CCE-3877-8RThe "log on as a service" user right should be assigned to the correct accounts. I(1) defined the SeServiceLogonRight setting in by Local or Group Policy CCE-216 4.2.23 Log on as a service: None(User Right Check log on as a service job CCE-3238-3MThe "log on locally" user right should be assigned to the correct accounts. M(1) defined the SeInteractiveLogonRight setting in by Local or Group Policy CCE-965L4.2.24 Log on locally: Users, Administrators (further restriction allowable)User Right Check log on locally CCE-3507-1_The "manage auditing and security log" user right should be assigned to the correct accounts. I(1) defined the SeSecurityPrivilege setting in by Local or Gr< oup Policy CCE-85074.2.25 Manage auditing and security log: Administrators4Manage Auditing and Security Logs on a Member Server CCE-3903-2aThe "modify firmware environment values" user right should be assigned to the correct accounts. R(1) defined the SeSystemEnvironmentPrivilege setting in by Local or Group Policy CCE-1794.2.26 Modify firmware environment values: Administrators User Right Check modify firmware CCE-3926-3UThe "profile single process" user right should be assigned to the correct accounts. U(1) defined the SeProfileSingleProcessPrivilege setting in by Local or Group Policy CCE-260-4.2.27 Profile single process: Administrators'User Right Check Profile single process CCE-3445-4YThe "profile system performance" user right should be assigned to the correct accounts. N(1) defined the SeSystemProfilePrivilege setting in by Local or Group Policy CCE-59914.2.28 Profile system performance: Administrators+User Right Check Profile system performance CCE-3829-9cThe "remove computer from docking station" user right should be assigned to the correct accounts. G(1) defined the SeUndockPrivilege setting in by Local or Group Policy CCE-656B4.2.29 Remove computer from docking station: Users, AdministratorsUser Right Check undock CCE-3970-1\The "replace a process-level token" user right should be assigned to the correct accounts. S(1) defined the SeAssignPrimaryTokenPrivilege setting in by Local or Group Policy CCE-667*4.2.30 Replace a process level token: None!User Right replace process token CCE-3912-3\The "restore files and directories" user right should be assigned to the correct accounts. H(1) defined the SeRestorePrivilege setting in by Local or Group Policy CCE-55344.2.31 Restore files and directories: AdministratorsUser Right restore CCE-3934-7SThe "shut down the system" user right should be assigned to the correct accounts. I(1) defined the SeShutdownPrivilege setting in by Local or Group Policy CCE-83924.2.32 Shut down the system: Users, AdministratorsUser Right shut down CCE-3471-0gThe "take ownership of files or other objects" user right should be assigned to the correct accounts. N(1) defined the SeTakeOwnershipPrivilege setting in by Local or Group Policy CCE-492>4.2.34 Take ownership of file or other objects: AdministratorsUser Right take ownership CCE-3850-5aThe "synchronize directory service data" user right should be assigned to the correct accounts. K(1) defined the SeSynchAgentPrivilege setting in by Local or Group Policy CCE-38194.2.33 Synchronize directory service data: Not ApplicableUser Right synch directory CCE-3489-2QThe "deny logon locally" user right should be assigned to the correct accounts. Q(1) defined the SeDenyInteractiveLogonRight setting in by Local or Group Policy CCE-64L4.2.14 Deny logon locally: None by default (others allowable as appropriate)#User Right Check deny logon locally CCE-3282-1}The "enable computer and user accounts to be trusted for delegation" user right should be assigned to the correct accounts. Q(1) defined the SeEnableDelegationPrivilege setting in by Local or Group Policy CCE-15U4.2.15 Enable computer and user accounts to be trusted for delegation: Not Applicable+User Right Check allow trust for delegation CCE-3542-8YThe "add workstations to domain" user right should be assigned to the correct accounts. O(1) defined the SeMachineAccountPrivilege setting in by Local or Group Policy CCE-18304.2.3 Add workstations to domain: Not applicable$User Right Check Add wkstn to domain CCE-3687-1TThe "reset account lockout counter after" policy should meet minimum requirements. (1) number of minutes&(1) defined by Local or Group Policy CCE-7331Reset Account Lockout After: 15 Minutes (minimum)Lockout Reset (15) CCE-3960-2IThe "account lockout duration" policy should meet minimum requirements. CCE-980.Account Lockout Duration: 15 Minutes (minimum)Lockout Duration (15) CCE-3229-2JThe "account lockout threshold" policy should meet minimum requirements. (1) number of attemptsCCE-6589Account Lockout Threshold: 3 Bad Login Attempts (maximum)Lockout Count (3) CCE-3859-6\Auditing of "account logon" events on success should be enabled or disabled as appropriate..(1) enabled/disabledCCE-2628/Audit Account Logon Events: Success and FailureAccount logon auditing CCE-3881-0\Auditing of "account logon" events on failure should be enabled or disabled as appropriate..CCE-2543 CCE-3753-1aAuditing of "account management" events on success should be enabled or disabled as appropriate..CCE-2000-Audit Account Management: Success and FailureAccount management auditing CCE-3885-1aAuditing of "account management" events on failure should be enabled or disabled as appropriate..CCE-1646 CCE-3907-3TAuditing of "logon" events on success should be enabled or disabled as appropriate..%(1) defined by Local or Group Policy CCE-1686'Audit Logon Events: Success and Failurelogon auditing CCE-3678-0TAuditing of "logon" events on failure should be enabled or disabled as appropriate..CCE-1744 CCE-3313-4\Auditing of "object access" events on success should be enabled or disabled as appropriate..CCE-2640&Audit Object Access: Failure (minimum)object access auditing CCE-3846-3\Auditing of "object access" events on failure should be enabled or disabled as appropriate..CCE-1991 CCE-3366-2\Auditing of "policy change" events on success should be enabled or disabled as appropriate..CCE-2412&Audit Policy Change: Failure (minimum)policy change auditing CCE-2995-9\Auditing of "policy change" events on failure should be enabled or disabled as appropriate..CCE-2347 CCE-3779-6\Auditing of "privilege use" events on success should be enabled or disabled as appropriate..CCE-2431&Audit Privilege Use: Failure (minimum)priv use auditing CCE-3925-5\Auditing of "privilege use" events on failure should be enabled or disabled as appropriate..CCE-2584 CCE-3215-1_Auditing of "process tracking" events on success should be enabled or disabled as appropriate..CCE-2529#Audit Process Tracking: Not Defined CCE-3911-5_Auditing of "process tracking" events on failure should be enabled or disabled as appropriate..CCE-2617 CCE-3792-9UAuditing of "system" events on success should be enabled or disabled as appropriate..CCE-2420(Audit System Events: Success and FailureSystem Event auditing CCE-3937-0UAuditing of "system" events on failure should be enabled or disabled as appropriate..CCE-1680 CCE-3959-4]The "Allow System to be Shut Down Without Having to Log On" policy should be set correctly. CCE-3965Allow System to be Shut Down Without Having to Log On CCE-3470-2HThe "Decoy Admin Account Not Disabled" policy should be set correctly. CCE-916Decoy Admin, Account Exists CCE-3880-2PThe "restrict guest access to application log" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\RestrictGuestAccess (2) defined by Group Policy CCE-2997Application Log: Restrict Guest Access to Logs: Enabled3Anonymous Access to the Application Event Log value CCE-3775-4CThe application log maximum size should be configured correctly.. (1) size of file(1) defined by the Windows Event Log (2) defined by Group Policy (3) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\MaxSize CCE-1858Application Log: Maximum Event Log Size: 80 Mb (minimum)$Application Event Log size key value CCE-3797-8bThe "when maximum log size is reached" property should be set correctly for the Application log. (1) type of retentionv(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Retention (2) defined by Group Policy CCE-285CApplication Log: Log Retention Method:  Overwrite Events As Needed )Application Event Log< retention key value CCE-3444-7If the Application log's retention method is set to "Overwrite events by days," an appropriate value should be set for the number of days' logs to keep.(1) number of daysCCE-951 CCE-3964-4MThe "restrict guest access to security log" policy should be set correctly. }(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security\RestrictGuestAccess (2) defined by Group Policy CCE-4624Security Log: Restrict Guest Access to Logs: Enabled0Anonymous Access to the Security Event Log value CCE-3096-5@The security log maximum size should be configured correctly.. (1) defined by the Windows Event Log (2) defined by Group Policy (3) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security\MaxSize CCE-7575Security Log: Maximum Event Log Size: 80 Mb (minimum)!Security Event Log size key value CCE-3589-9_The "when maximum log size is reached" property should be set correctly for the Security log. (1) type of retentionCCE-523@Security Log: Log Retention Method:  Overwrite Events As Needed &Security Event Log retention key value CCE-3968-5If the Security log's retention method is set to "Overwrite events by days," an appropriate value should be set for the number of days' logs to keep.CCE-682 CCE-3990-9KThe "restrict guest access to system log" policy should be set correctly. {(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\RestrictGuestAccess (2) defined by Group Policy CCE-7262System Log: Restrict Guest Access to Logs: Enabled.Anonymous Access to the System Event Log value CCE-3889-3>The system log maximum size should be configured correctly.. (1) defined by the Windows Event Log (2) defined by Group Policy (3) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\MaxSize CCE-7353System Log: Maximum Event Log Size: 80 Mb (minimum)System Event Log size key value CCE-3805-9]The "when maximum log size is reached" property should be set correctly for the System log. CCE-664>System Log: Log Retention Method:  Overwrite Events As Needed $System Event Log retention key value CCE-3823-2If the System log's retention method is set to "Overwrite events by days," an appropriate value should be set for the number of days' logs to keep.CCE-210 CCE-3827-3EThe "maximum password age" policy should meet minimum requirements. CCE-8715All passwords are no more than 90 days old (maximum).Maximum Password Age (90) CCE-3224-3EThe "minimum password age" policy should meet minimum requirements. CCE-324Minimum Password Age: 1 dayMinimum Password Age CCE-3228-4HThe "minimum password length" policy should meet minimum requirements. CCE-1007All passwords are at least 8 characters long (minimum).Password Length (8) CCE-3986-79The correct password filtering DLL should be installed. 8(1) file name (2) version (3) file size (4) file hash((1) determined by the local filesystem CCE-514Check for Enpasflt.dll CCE-3042-9QThe "password must meet complexity requirments" policy should be set correctly. CCE-633Password Complexity: EnabledEnPasFlt Check CCE-3588-1IThe "enforce password history" policy should meet minimum requirements. "(1) number of passwords rememberedCCE-60)Password History: 24 Passwords RememberedPassword History (24) CCE-3852-1nThe "store password using reversible encryption for all users in the domain" policy should be set correctly. CCE-4795Store Passwords using Reversible Encryption: DisabledReversible Pwd Encryption CCE-3372-0<The startup type of the Alerter service should be correct. (1) disabled/manual/automatic(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4874.1.1 Alerter  Disabled CCE-3892-7=The startup type of the ClipBook service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-9544.1.2 Clipbook  Disabled CCE-4041-0EThe startup type of the Computer Browser service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-294!4.1.3 Computer Browser  DisabledComputer Browser Disabled CCE-3059-38The startup type of the Fax service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fax\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-784.1.4 Fax Service  Disabled CCE-3830-7CThe startup type of the FTP Publishing service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSFTPSVC\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-712'4.1.5 FTP Publishing Service  Disabled CCE-3835-6>The startup type of the IIS Admin service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IISADMIN\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-311"4.1.6 IIS Admin Service  Disabled CCE-3738-2>The startup type of the Messenger service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-7294.1.8 Messenger  Disabled CCE-4035-2VThe startup type of the NetMeeting Remote Desktop Sharing service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmsrvc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-23224.1.9 NetMeeting Remote Desktop Sharing  Disabled*NetMeeting Remote Desktop Sharing Disabled CCE-3554-3PThe startup type of the Internet Connection Sharing service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-672,4.1.7 Internet Connection Sharing  Disabled CCE-3572-5DThe startup type of the Remote Registry service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-73)4.1.10 Remote Registry Service  Disabled CCE-3973-5NThe startup type of the Routing and Remote Access service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-223+4.1.11 Routing and Remote Access  Disabled.Remote Access Auto Connection Manager Disabled CCE-3995-8AThe startup type of the Remote Shell service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RshSvc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-522Remote Shell Service CCE-3515-4BThe startup type of the Simple TCP/IP service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SIMPTCP\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-531Simple TCP/IP Service CCE-3643-4ZThe startup type of the Simple Mail Transport Protocol (SMTP) service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMTPSVC\Start (2) defi< ned by the Services Administrative Tool (3) definied by Group Policy CCE-87064.1.12 Simple Mail Transfer Protocol (SMTP)  Disabled CCE-3524-6AThe startup type of the SNMP Service service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-975C4.1.13 Simple Network Management Protocol (SNMP) Service  Disabled CCE-3819-0FThe startup type of the SNMP Trap Service service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMPTRAP\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-892@4.1.14 Simple Network Management Protocol (SNMP) Trap  Disabled CCE-3951-1;The startup type of the Telnet service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-754.1.15 Telnet  DisabledTelnet Disabled CCE-3722-6NThe startup type of the World Wide Web Publishing service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-75844.1.16 World Wide Web Publishing Services  Disabled CCE-3634-3EThe startup type of the Automatic Update service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv (2) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdate (3) defined by the Services Administrative Tool (4) definied by Group Policy CCE-559&4.1.17 Automatic Updates  Not Defined CCE-3721-8cThe startup type of the Background Intelligent Transfer Service (BITS) service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-445<4.1.18 Background Intelligent Transfer Service  Not Defined CCE-3069-2LThe startup type of the Print Services for Unix service should be correct. O(1) defined by the Services Administrative Tool (2) definied by Group Policy CCE-115Print Services for UNIX CCE-3898-4MThe correct service permissions for the Printer service should be assigned. ,(1) set of accounts (2) list of permissions>(1) set via Security Templates (2) definied by Group Policy CCE-109Printer Permissions CCE-3418-1TThe correct service permissions for the Task Scheduler service should be assigned. CCE-4070"Schedule" service is run as the system account. CCE-3938-8YThe "Additional restrictions for anonymous connections" policy should be set correctly. CCE-310eAdditional Restrictions for Anonymous Connections:  No Access Without Explicit Anonymous Permissions CCE-3837-2sThe behavior surrounding Anonymous users' abiliity to display lists of SAM accounts and shares should be correct. (1) restricted/unrestrictedv(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous (2) defined by Local or Group Policy CCE-195Restrict Anonymous value CCE-3982-6RThe "Anonymous access to the security event log" policy should be set correctly. *(1) exist/not exist (2) enabled/disabledL(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security CCE-6535Anonymous access to the event logs is not restricted. CCE-4004-8HThe "Anonymous access to the registry" policy should be set correctly. R(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg CCE-4643Anonymous access to the Registry is not restricted. CCE-3766-3OUse of the built-in Guest account should be enabled or disabled as appropriate. (1) Local Users and Groups MMC CCE-332Guest Account Disabled CCE-3669-9TThe "Message title for users attempting to log on" policy should be set correctly. (1) text caption(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption (2) defined by Local or Group Policy CCE-23IMessage Title for Users Attempting to Log On:  Warning: or custom title.?Legal notice is not configured to display before console logon. CCE-4012-1SThe "Message text for users attempting to log on" policy should be set correctly. (1) text statement(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText (2) defined by Local or Group Policy CCE-829EMessage Text for Users Attempting to Log On: Custom Message or  This CCE-3893-5CAdministrative Shares should be enabled or disabled as appropriate._(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\AutoShareWks CCE-512Remove administrative shares on workstation (Professional): HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters\AutoShareWks (REG_DWORD) 0 CCE-4039-4KAutomatic Execution of the System Debugger should be properly configured. R(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDebug\Auto CCE-243Disable Automatic Execution of the System Debugger: HKLM\ Software\Microsoft\Windows NT\CurrentVersion\AEDebug\Auto (REG_DWORD) 05CIS: Automatic Execution of the System Debugger value CCE-3559-20Automatic Logon should be properly configured. ](1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoAdminLogon CCE-283pDisable Automatic Logon: HKLM\ Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoAdminLogon(REG_DWORD) 0Admin Autologon Value CCE-4061-8DAutomatic Reboot After System Crash should be properly configured. Q(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\AutoReboot CCE-137Disable automatic reboots after a Blue Screen of Death: HKLM\System\CurrentControlSet\Control\CrashControl\AutoReboot (REG_DWORD) 0%CIS: Disable Reboot After Crash value CCE-3726-7<Autoplay on all Drive Types should be properly configured. g(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun CCE-44Disable autoplay from any disk type, regardless of application: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun (REG_DWORD) 255Autoplay value CCE-3871-1:Autoplay for Current User should be properly configured. f(1) HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun CCE-36Disable autoplay for current user: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun (REG_DWORD) 255 CCE-3528-7:Autoplay for Default User should be properly configured. g(1) HKEY_USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun CCE-820Disable autoplay for new users by default: HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun (REG_DWORD) Not Defined0CIS: Disable Media Autoplay (HKU-.Default hive) CCE-3555-0/CD-ROM Autorun should be properly configured. H(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CDrom\Autorun CCE-344VDisable CD Autorun: HKLM\System\CurrentControlSet\Services\CDrom\Autorun (REG_DWORD) 0 CCE-3682-2EComputer Browser ResetBrowser Frames should be properly configured. (1) enabled/ignoredX(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MrxSmb\Parameters\RefuseReset CCE-282Protect against Computer Brow< ser Spoofing Attacks: HKLM\System\CurrentControlSet\Services\MrxSmb\Parameters\RefuseReset (REG_DWORD) 1!Computer Browser Spoofing Attacks CCE-3704-4/ICMP Redirects should be properly configured. ](1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ServicesTcpip\Parameters\EnableICMPRedirect CCE-150Ensure ICMP Routing via shortest path first: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableICMPRedirect (REG_DWORD) 0Disable ICMP Redirect CCE-3915-62IP Source Routing should be properly configured. b(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DisableIPSourceRouting CCE-564Protect against source-routing spoofing: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableIPSourceRouting (REG_DWORD) 2Disable IP Source Routing CCE-4065-9%IRDP should be properly configured. b(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\PerformRouterDiscovery CCE-952Ensure Router Discovery is Disabled: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\PerformRouterDiscovery (REG_DWORD) 0Disable Router Discovery CCE-3942-0MKerberos and RSVP Traffic Protected by IPSec should be properly configured. P(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSEC\NoDefaultExempt CCE-501yEnable IPSec to protect Kerberos RSVP Traffic: HKLM\System\CurrentControlSet\Services\IPSEC\NoDefaultExempt (REG_DWORD) 1:CIS: Enable IPSec security for Kerberos RSVP Traffic value CCE-3981-87Dr. Watson Crash Dumps should be properly configured. D(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DrWatson\CreateCrashDump CCE-536_Suppress Dr. Watson Crash Dumps: HKLM\Software\Microsoft\DrWatson\CreateCrashDump (REG_DWORD) 0'CIS: Allow Dr. Watson Crash Dumps value CCE-3646-7GDisplay Last User Name in Logon Screen should be properly configured. f(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DontDisplayLastUserName CCE-65Don t display username of last successful logon at the logon screen: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\DontDisplayLastUserName (REG_SZ) Not Defined; 3.2.1.15 Do Not Display Last User Name in Logon Screen: Enabled CCE-3920-6?File System Checker and Popups should be properly configured. Y(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable CCE-544Enable the File System Checker and Disable Popups: HKLM\ Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable (REG_DWORD) Not Defined CCE-3095-74System File Checker should be properly configured. V(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCScan CCE-580Enable the System File Checker to verify all operating system files at boot time: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCScan (REG_DWORD) Not DefinedNote: Due to the processor-intensive nature of the System File Checker, it is no longer required on startup. CCE-3972-7CSystem File Checker Progress Meter should be properly configured. (1) visible/invisible^(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCShowProgress CCE-236Do not show the System File Checker progress meter: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCShowProgress (REG_DWORD) Not Defined CCE-3620-2FSystem availability to Master Browser should be properly configured. (1) available/hiddenY(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Lanmanserver\Parameters\Hidden CCE-1393.2.2.24 Do not announce this computer to domain master browsers: HKLM\System\CurrentControlSet\Services\Lanmanserver\Parameters\Hidden (REG_DWORD) 1;CIS: Hide computer Name from other domain controllers value CCE-3884-4>TCP/IP Dead Gateway Detection should be properly configured. ^(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableDeadGWDetect CCE-897Protect the Default Gateway network setting: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableDeadGWDetect (REG_DWORD) 0Disable Dead Gateway Detection CCE-3600-45The TCP/IP KeepAlive Time should be set correctly . (1) number of millisecondsY(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\KeepAliveTime CCE-188pManage Keep-alive times: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\KeepAliveTime(REG_DWORD) 300000TCP Connection Keep-Alive Time CCE-3878-6TThe permitted number of TCP/IP Maximum Half-open Sockets should be set correctly . (1) number of socketsZ(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TcpMaxHalfOpen CCE-333SYN Attack protection  Manage TCP Maximum half-open sockets: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\TcpMaxHalfOpen (REG_DWORD) 100Half-open TCP Sockets CCE-4027-9\The permitted number of TCP/IP Maximum Retried Half-open Sockets should be set correctly . a(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TcpMaxHalfOpenRetried CCE-751SYN Attack protection  Manage TCP Maximum half-open retired sockets: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\TcpMaxHalfOpenRetired (REG_DWORD) 80Half-open retired TCP Sockets CCE-3922-2QTCP/IP NetBIOS Name Release on Request Prevented should be properly configured. a(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netbt\Parameters\NoNameReleaseOnDemand CCE-817Protect Against Malicious Name-Release Attacks: HKLM\System\CurrentControlSet\Services\Netbt\Parameters\NoNameReleaseOnDemand (REG_DWORD) 1Name-Release Attacks CCE-3939-66TCP/IP PMTU Discovery should be properly configured. _(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnablePMTUDiscovery CCE-998Help protect against packet fragmentation: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnablePMTUDiscovery (REG_DWORD) 0 CCE-4085-7CTCP/IP SYN Flood Attack Protection should be properly configured. \(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SynAttackProtect CCE-284yProtect against SYN Flood attacks: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\SynAttackProtect (REG_DWORD) 2SYN Attack Protection CCE-3948-7AProtect Kernel object attributes should be properly configured. (1) security level_(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\EnhancedSecurityLevel CCE-112 Protect Kernel object attributes CCE-3966-9ASecurity Audit log warning level should be properly configured. (1) warning levelY(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Security\WarningLevel CCE-125Audit Log Warning Level CCE-4010-5DDisable saving of dial-up passwords should be properly configured. `(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasman\Parameters\DisableSavePassword CCE-156"Disable saving of dial up password CCE-3900-8mThe "Secure Channel: Digitally Encrypt Secure Channel Data (When Possible)" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SealSecureChannel (2) defined by Local or Group Policy CCE-601$Encrypt Secure Channel Traffic Value CCE-4063-4jThe "Secure Channel: Digitally Sign Secure Channel Data (When Possible)" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SignSecureChannel (2) defined by Local or Group Policy CCE-614!Sign Secure Channel Traffic Value< CCE-4005-5PThe "Allow Server Operators to Schedule Tasks" policy should be set correctly. CCE-2578Allow Server Operators to Schedule Tasks: Not Applicable CCE-3899-2?The built-in Administrator account should be correctly named. (1) valid namesCCE-438BRename Administrator Account: Any value other than  Administrator Administrator Account Renamed CCE-4045-17The built-in Guest account should be correctly named. CCE-8342Rename Guest Account: Any value other than  Guest Guest Account Renamed CCE-3921-4ZThe amount of idle time required before disconnecting a session should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\AutoDisconnect (2) defined by Local or Group Policy CCE-222OAmount of Idle Time Required Before Disconnecting Session: 30 Minutes (minimum)6Amount of idle time before disconnecting value (<= 15) CCE-4049-3QThe "Audit the access of global system objects" policy should be set correctly. t(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\AuditBaseObjects (2) defined by Local or Group Policy CCE-26Audit the access of global system objects: Not Defined CCE-3476-9UThe "Audit the use of backup and restore privilege" policy should be set correctly. y(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FullPrivilegeAuditing (2) defined by Local or Group Policy CCE-905:Audit the use of backup and restore privilege: Not Defined CCE-3886-9UThe "Disable CTRL+ALT+Delete Requirement for Logon" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCAD (2) defined by Local or Group Policy CCE-1337Disable CTRL+ALT+Delete Requirement for Logon: Disabled5Ctrl+Alt+Del security attention sequence is Disabled. CCE-4014-7HThe "LAN Manager Authentication Level" policy should be set correctly. (1) authentication levelx(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\LMCompatibilityLevel (2) defined by Local or Group Policy CCE-719GLAN Manager Authentication Level:  Send NTLMv2 response only (minimum)LMCompatibility Value CCE-3908-1OThe "Send LanMan compatible password" setting should be configured correctly. h(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\LMCompatibilityLevel Paramenters:(1) levelCCE-275pThe Send download LanMan compatible password option is not set to "Send LM and NTLM - Use NTLMv2 if Negotiated." CCE-3675-6UThe "Prevent Users from Installing Printer Drivers" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Providers\LanMan Print Services\Servers\AddPrinterDrivers (2) defined by Local or Group Policy CCE-4026Prevent Users from Installing Printer Drivers: EnabledPrint Driver Installation value CCE-4067-5^The "Recovery Console: Allow Automatic Administrative Logon" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SecurityLevel (2) defined by Local or Group Policy CCE-410@Recovery Console: Allow Automatic Administrative Logon: Disabled Recovery Console Autologon value CCE-3463-7tThe "Recovery Console: Allow Floppy Copy and Access to All Drives and All Folders" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SetCommand (2) defined by Local or Group Policy CCE-76VRecovery Console: Allow Floppy Copy and Access to All Drives and All Folders: Disabled"Recovery Console Full Access Value CCE-3529-5]The "Restrict CD-ROM Access to Locally Logged-On User Only" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AllocateCDRoms (2) defined by Local or Group Policy CCE-565>Restrict CD-ROM Access to Locally Logged-On User Only: Enabled CCE-3185-6]The "Restrict Floppy Access to Locally Logged-On User Only" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AllocateFloppies (2) defined by Local or Group Policy CCE-463>Restrict Floppy Access to Locally Logged-On User Only: EnabledFloppy Allocation CCE-3956-0_The "Strengthen Default Permissions of Global System Objects" policy should be set correctly. ~(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\ProtectionMode (2) defined by Local or Group Policy CCE-508VStrengthen Default Permissions of Global System Objects (e.g. Symbolic Links): Enabled!Strength permissions on GSO value CCE-3978-4jThe "Secure Channel: Require Strong (Windows 2000 or later) Session Key" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireStrongKey (2) defined by Local or Group Policy CCE-417OSecure Channel: Require Strong (Windows 2000 or later) Session Key: Not Defined CCE-3392-8gThe "Send Unencrypted Password to Connect to Third-Party SMB Servers" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnablePlainTextPassword (2) defined by Local or Group Policy CCE-228ISend Unencrypted Password to Connect to Third-Party SMB Servers: Disabled0Send unencrypted password to 3rd party SMB value CCE-3648-3MThe "Unsigned Driver Installation Behavior" policy should be set correctly. (1) behaviorg(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Driver Signing\Policy (2) defined by Local or Group Policy CCE-413oUnsigned Driver Installation Behavior:  Warn, but allow installation (minimum) or  Do Not Allow Installation .Unsigned Driver Behavior Value CCE-3401-7QThe "Unsigned Non-Driver Installation Behavior" policy should be set correctly. CCE-307rUnsigned Non-Driver Installation Behavior:  Warn, but allow installation (minimum) or  Do Not Allow Installation "Unsigned Non-Driver Behavior Value CCE-3098-1ZThe "Users Prompted to Change Password Before Expiration" policy should be set correctly. &(1) number of days prior to expiration(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\PasswordExpiryWarning (2) defined by Local or Group Policy CCE-814CPrompt User to Change Password Before Expiration: 14 Days (minimum)Password Expiration value CCE-4070-9eThe "Shut Down system immediately if unable to log security audits" policy should be set correctly. t(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\CrashOnAuditFail (2) defined by Local or Group Policy CCE-92JShut Down system immediately if unable to log security audits: Not DefinedCrash on audit fail Value CCE-3629-3(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ShutdownWithoutLogon (2) defined by Local or Group Policy CCE-224?Allow System to be Shut Down Without Having to Log On: Disabled4The system allows shutdown from the logon dialog box CCE-3813-3cThe "Automatically Log Off Users When Logon Time Expires (local)" policy should be set correctly. CCE-360DAutomatically Log Off Users When Logon Time Expires (local): EnabledLogon Time Enforcement (0) CCE-3333-2QThe "Clear Virtual Memory Pagefile at shutdown" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Memory Management\ClearPageFileAtShutdown (2) defined by Local or Group Policy CCE-422=Clear Virtual Memory Pagefile When System Shuts Down: EnabledClear Pagefile value CCE-3747-3TThe "Digitally Sign Client Communication (Always)" policy should be set correctly. < (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\RequireSecuritySignature (2) defined by Local or Group Policy CCE-5769Digitally Sign Client Communication (Always): Not Defined CCE-3994-1[The "Digitally Sign Client Communication (When Possible)" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnableSecuritySignature (2) defined by Local or Group Policy CCE-519<Digitally Sign Client Communication (When Possible): EnabledEnable Security Signature Value CCE-3783-8TThe "Digitally Sign Server Communication (Always)" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RequireSecuritySignature (2) defined by Local or Group Policy CCE-1719Digitally Sign Server Communication (Always): Not Defined CCE-3928-9[The "Digitally Sign Server Communication (When Possible)" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableSecuritySignature (2) defined by Local or Group Policy CCE-104<Digitally Sign Server Communication (When Possible): EnabledSMB Server Packet Signing Value CCE-3545-1JThe "Number of Previous Logons to Cache" policy should be set correctly. (1) number of logons(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\CachedLogonsCount (2) defined by Local or Group Policy CCE-773/Number of Previous Logons to Cache: 1 (maximum)Logon Caching value (<= 2) CCE-4069-1XThe "Allowed to Format and Eject Removable NTFS Media" policy should be set correctly. (1) Group(s)(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AllocateDASD (2) defined by Local or Group Policy CCE-9195Allowed to Eject Removable NTFS Media: AdministratorsNTFS Media Ejection value CCE-3607-9nThe "Secure Channel: Digitally Encrypt or Sign Secure Channel Data (Always)" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal (2) defined by Local or Group Policy CCE-549SSecure Channel: Digitally Encrypt or Sign Secure Channel Data (Always): Not Defined CCE-3849-7CCE-161NSecure Channel: Digitally Encrypt Secure Channel Data (When Possible): Enabled CCE-4025-3CCE-918KSecure Channel: Digitally Sign Secure Channel Data (When Possible): Enabled CCE-3596-4CThe "Smart Card Removal Behavior" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ScRemoveOption (2) defined by Local or Group Policy CCE-4439Smart Card Removal Behavior:  Lock Workstation (minimum)!Smart Card Removal Behavior Value CCE-3145-0_The "Prevent System Maintenance of Computer Account Password" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\DisablePasswordChange (2) defined by Local or Group Policy CCE-831APrevent System Maintenance of Computer Account Password: DisabledDisable password change Value CCE-3947-9.Local volumes should be formatted correctly. (1) type of formatting(1) Disk Management MMC CCE-621<4.3.1 Ensure all disk volumes are using the NTFS file systemNon-NTFS Partition CCE-3863-8?Unused USB Ports should be enabled or disabled as appropriate. (1) ? CCE-546"Unused USB ports are not disabled. CCE-4008-9_The "Screen Saver Executable Name" setting should be configured correctly for the current user.:(1) HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE CCE-764current user scrnsave.exe CCE-4000-6WThe "Screen Saver Timeout" setting should be configured correctly for the current user.(1) time in seconds?(1) HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveTimeOut CCE-830 Current user screensaver timeout CCE-4145-9dThe "Password protect the screen saver" setting should be configured correctly for the current user.(1) HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaverIsSecure (2) HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop\ScreenSaverIsSecure (3) User Configuration\Administrative Templates\Control Panel\Display\Password protect the screen saverCCE-949Current user screensaver secure CCE-3149-2SThe screen saver should be enabled or disabled as appropriate for the current user.>(1) HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveActive CCE-742Current user screensaver active CCE-3152-6OThe "Always Install with Elevated Privileges" policy should be set correctly. \(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated CCE-736'Always Install with Elevated Privileges CCE-4108-7>The "Set Safe for Scripting" policy should be set correctly. X(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\SafeForScripting\ CCE-2618Disable IE Security Prompt for Windows Installer Scripts CCE-3861-2IThe "Enable User Control Over Installs" policy should be set correctly. X(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\EnableUserControl CCE-415!Enable User Control Over Installs CCE-3931-3XThe "Enable User to Browser for Source While Elevated" policy should be set correctly. Z(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\AllowLockDownBrowse CCE-794/Enable User to Browse for Source While Elevated CCE-4094-9VThe "Enable User to Use Media Source While Elevated" policy should be set correctly. Y(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\AllowLockDownMedia CCE-107.Enable User to Use Media Source While Elevated CCE-4116-0eThe "Allow Administrator to Install from Terminal Services Session" policy should be set correctly. Z(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\EnableAdminTSRemote CCE-2565Allow Admin to Install from Terminal Services Session CCE-3980-0NThe "Enable User to Patch Elevated Products" policy should be set correctly. Y(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\AllowLockDownPatch CCE-662&Enable User to Patch Elevated Products CCE-4002-2KThe "Cache Transforms in Secure Location" policy should be set correctly. V(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer\TransformSecure CCE-4242Cache Transforms in Secure Location on Workstation CCE-4033-7GInternet access for Windows Messenger should be configured correctly. (1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Messenger\Client\{9b017612-c9f1-11d2-8d9f-0000f875c541}\Disabled (2) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MessengerService CCE-525!Windows Messenger Internet Access CCE-4055-0RThe "Hide Property Pages" policy should be set correctly for the Task Scheduler. ](1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Task Scheduler5.0\Property Pages CCE-785Hide Property Pages CCE-3451-2WThe "Prohibit New Task Creation" policy should be set correctly for the Task Scheduler.\(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Task Scheduler5.0\Task Creation CCE-578Prohibit New Task Creation CCE-3971-9WThe "Security Zones: Use Only Machine Settings" setting should be configured correctly.Y(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Use_HKLM_only (2) Local Internet Options: (3) GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer (4) Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_onlyCCE-5)Security Zones: Use Only Machine Settings CCE-4117-8dThe "Security Zones: Do Not Allow Users to Add/Delete Sites" setting should be configured correctly.h(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_Zones_Map_Edit (2) Local Internet Options: (3) GPO< Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer (4) Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_zones_map_editCCE-1466Security Zones: Do Not Allow Users to Add/Delete Sites CCE-3874-5kThe "Disable Periodic Check For Internet Explorer Software Updates" setting should be configured correctly.Z(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoUpdateCheck (2) Local Internet Options: (3) GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer (4) Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoUpdateCheckCCE-212=Disable Periodic Check for Internet Explorer Software Updates CCE-3517-0kThe "Disable Software Update Shell Notifications on Program Launch" setting should be configured correctly.(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoMSAppLogo5ChannelNotify (2) Local Internet Options: (3) GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict File Download (4) Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved) (5) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe (6) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exeCCE-622=Disable Software Update Shell Notifications on Program Launch CCE-3962-8gThe "Disable Automatic Install of Internet Explorer Components" setting should be configured correctly.R(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoJITSetup (2) Local Internet Options: (3) GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer (4) Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoJITSetupCCE-6849Disable Automatic Install of Internet Explorer Components CCE-4125-1dThe "Make Proxy Settings Per-Machine (Rather Then Per-User)" setting should be configured correctly.(1) number of proxy settings`(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser (2) Local Internet Options: (3) GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer (4) Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUserCCE-693Make Proxy Settings Per Machine CCE-4019-6cThe "Security Zones: Do Not Allow Users to Change Policies" setting should be configured correctly.d(1) HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit (2) Local Internet Options: (3) GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer (4) Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit CCE-8335Security Zones: Do Not Allow Users to Change Policies CCE-4812-4.DEPRECATED in favor of CCE-5236-5, CCE-4719-1.CCE-10 CCE-5236-5gAuditing of "directory service access" events on success should be enabled or disabled as appropriate..(1) via auditpolCCE-2118Audit Directory Service Access CCE-4719-1gAuditing of "directory service access" events on failure should be enabled or disabled as appropriate..CCE-2390 CCE-4874-4KThe Smart Card Helper service should be enabled or disabled as appropriate.CCE-1001"Smart Card Helper Service Disabled CCE-4777-9IThe License Logging service should be enabled or disabled as appropriate.CCE-1298 License Logging Service Disabled CCE-4156-6XThe "deny logon as a batch job" user right should be assigned to the correct accounts. N(1) defined by the SeDenyBatchLogonRight setting in by Local or Group Policy CCE-165Denied Logon As A Batch Job CCE-4825-6PThe Application Management service should be enabled or disabled as appropriate.CCE-167'Application Management Service Disabled CCE-4720-9aThe Resultant Set of Policy (RSoP) Provider Service should be enabled or disabled as appropriate.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSoPProv\Start (2) defined by the Services Administrative Tool (3) definied by Group PolicyCCE-17861Resultant Set of Policy Provider Service Disabled CCE-4848-8UUse of the Recycle Bin on file deletion should be enabled or disabled as appropriate.R(1) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\NukeOnDeleteCCE-1984=Recycle Bin Configured to Delete Files (Servers) Requirements CCE-4729-0`The Network News Transport Protocol (NNTP) service should be enabled or disabled as appropriate.CCE-21660Network News Transport Protocol Service Disabled CCE-4495-8]The Network Dynamic Data Exchange (DDE) service should be enabled or disabled as appropriate.CCE-2174Network Dynamic Data Exchange (DDE) Service Disabled CCE-4768-8RThe "Interactive logon: Requre smart card" setting should be configured correctly.MHKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\SCForceOption CCE-828-CAC logon required (NIPRNet only) Requirement CCE-4253-1ZThe Distributed Link Tracking Server service should be enabled or disabled as appropriate.CCE-22581Distributed Link Tracking Server Service Disabled CCE-4539-3ZThe startup type of the Remote Access Auto connection Manager service should be correct. CCE-2676Remote Access Auto Connection Manager Service Disabled CCE-4786-0RThe "Disconnect clients when logon hours expire" policy should be set correctly. (1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableForcedLogoff (2) defined by Local or Group Policy CCE-2788Forcibly Disconnect when Logon Hours Expire Requirements CCE-4447-9]The Distributed Transaction Coordinator service should be enabled or disabled as appropriate.CCE-3034Distributed Transaction Coordinator Service Disabled CCE-4332-3gThe "Impersonate a client after authentication" user right should be assigned to the correct accounts.CCE-304)Impersonate a Client After Authentication CCE-4830-6[The required permissions for the file %SystemRoot%\System32\runas.exe should be assigned. CCE-340DCOM - RunAs Value Requirements CCE-4751-4VThe Uninterruptable Power Supply service should be enabled or disabled as appropriate.CCE-366+Uninterrupted Power Supply Service Disabled CCE-4645-8GThe "Enforce user logon restrictions" policy should be set correctly. CCE-2274Kerberos - User Logon Restrictions (DC) Requirements CCE-4750-6DThe "Maximum User Ticket Lifetime" policy should be set correctly. (1) number of hoursCCE-371Kerberos - User Ticket Lifetime (DC) Requirements CCE-4865-2HThe "Maximum Service Ticket Litfetime" policy should be set correctly. CCE-64Kerberos - Service Ticket Lifetime (DC) Requirements CCE-4684-7EThe "Maximum User Renewal Lifetime" policy should be set correctly. CCE-338Kerberos - User Ticket Renewal Lifetime (DC Requirements CCE-4715-9\The "Maximum tolerance for computer clock synchronization" policy should be set correctly. CCE-588;Kerberos - Computer Clock Synchronization (DC) Requirements CCE-4790-2RThe "Create global objects" user right should be assigned to the correct accounts.CCE-383Right To Create Global Objects CCE-4667-2CThe startup type of the Task Scheduler service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-40Task Scheduler Service Disabled CCE-4882-7CThe Telephony service should be enabled or disabled as appropriate.CCE-428Telephony Service Disabled CCE-4799-3The "DCOM: Machine access Restr< ictions in Security Descriptor Definition Language (SDDL) syntax" setting should be configured correctly.CCE-458ZDCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax CCE-4195-4EThe DHCP Server service should be enabled or disabled as appropriate.DHCP Server Service Disabled CCE-4235-8VThe "deny logon as a service" user right should be assigned to the correct accounts. M(1) defined the SeDenyServiceLogonRight setting in by Local or Group Policy CCE-597Denied Logon As A Service CCE-4244-0UThe Wireless Zero Configuration service should be enabled or disabled as appropriate.CCE-604Wireless Zero Configuration CCE-4764-7CThe startup type of the .NET Framework service should be correct. CCE-650ASP .NET State Service Disabled CCE-4803-3ZThe Distributed Link Tracking Client service should be enabled or disabled as appropriate.CCE-6511Distributed Link Tracking Client Service Disabled CCE-4794-4=The startup type of the Indexing service should be correct. (1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CiSvc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-738Indexing Service Disabled CCE-4689-6The "DCOM: Machine Launch Restrictions in the Security Descriptor Definition Language (SDDL) syntax" security option should be set correctly.CCE-740ZDCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax CCE-4779-5ZThe Remote Access Connection Manager service should be enabled or disabled as appropriate.CCE-7501Remote Access Connection Manager Service Disabled CCE-4801-7gThe Network DDE DDE Share Database Manager (DSDM) service should be enabled or disabled as appropriate.CCE-768>Network DDE DDE Share Database Manager (DSDM) Service Disabled CCE-4453-7NThe Certificate Services service should be enabled or disabled as appropriate.Certificate Service Disabled CCE-4096-4DThe Smart Card service should be enabled or disabled as appropriate.CCE-98Smart Card Service Disabled CCE-4003-0SMembership in the Power Users group should be assigned to the appropriate accounts.(1) list of accountsCCE-990Power Users Restricted Group CCE-4890-0NThe "Delete Cached Copies of Roaming Profiles" policy should be set correctly.(1) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\DeleteRoamingCache (2) defined by Local or Group Policy 10.8.20-14 CCE-5141-7JThe "AutoBackupLogFiles" policy for security logs should be set correctly.](1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security\AutoBackupLogFiles CCE-4709-2MThe "AutoBackupLogFiles" policy for application logs should be set correctly.`(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\AutoBackupLogFiles CCE-4986-6HThe "AutoBackupLogFiles" policy for system logs should be set correctly.[(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\AutoBackupLogFiles CCE-4929-6TThe "Named Pipes that can be accessed anonymously" policy should be set correctly. (1) list of named pipesa(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\NullSessionPipes 10.8.20-04 CCE-5282-9The time in seconds before the screen saver grace period expires (ScreenSaverGracePeriod) setting should be configured correctly.(1) number of secondsc(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ScreenSaverGracePeriod CCE-5153-2fThe setting determining the location of the key and password for the Syskey Encryption Key is correct.(1) locally/startup/floppyF(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\SecureBoot CCE-5123-5AThe POSIX subsystem should be enabled or disabled as appropriate.(1) enabled / disabled[(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\optional CCE-5139-1@The OS/2 subsystem should be enabled or disabled as appropriate. CCE-5184-7IThe environment variable "Os2LibPath" should exist or not as appropriate.(1) exists / undefined(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\Os2LibPath (2) Control Panel: System\Advanced\Environment Variables CCE-5176-3SThe path to the Microsoft OS/2 version 1.x library should be defined appropriately.(1) path(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\Os2LibPath (2) Control Panel: System\Advanced\Environment Variables\Os2LibPath CCE-4400-8BSafe DLL search mode should be enabled or disabled as appropriate.Y(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SafeDllSearchMode CCE-4999-9JThe "Remotely accessible registry paths" policy should be set correctly. (1) list of registry keyse(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths\Machine CCE-5126-8yThe registry key HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\Os2 should exist or not as appropriate.I(1) HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\Os2 CCE-4772-0<The location of the OS/2 subsystem should be set correctly. CCE-4972-6=The location of the POSIX subsystem should be set correctly. (1) file pathX(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Subsystems\POSIX CCE-5100-3OThe "Shares that can be accessed anonymously" policy should be set correctly. (1) list of sharesb(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\NullSessionShares CCE-4946-0The registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDebug\Debugger should exist or not as appropriate.T(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDebug\Debugger CCE-5382-7UThe path to the debugger used for Just-In-Time debugging should be set appropriately. CCE-5281-1[The Distributed Component Object Model (DCOM) should be enabled or disabled as appropriate.N(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\EnableDCOM (2) via dcomcnfg.exe CCE-5073-2aThe automatic generation of 8.3 file names for NTFS should be enabled or disabled as appropriate._(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisable8dot3NameCreation CCE-5148-2NThe "Refuse machine account password change" policy should be set correctly. (1) accept/reject(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\RefusePasswordChange (2) defined by Local or Group Policy10.8.20-04, 10.8.20-15 CCE-5045-0EThe encryption algorithm to be used by EFS should be properly chosen.encryption typeS(1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS\AlgorithmID CCE-4736-5?The TCPMaxPortsExhausted setting should be properly configured.)(1) number of dropped connection requests^(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TCPMaxPortsExhausted CCE-4961-9DThe TcpMaxDataRetransmissions setting should be properly configured.(1) number of retransmissionsc(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\TcpMaxDataRetransmissions CCE-4489-1CTcpMaxConnectResponseRetransmissions should be properly configured.n(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TcpMaxConnectResponseRetransmissions CCE-4555-9LThe startup type of the File Server For Macintosh service should be correct.(1) automatic/manual/disabled(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MacFile\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy 10.8.20-23 CCE-4771-2DThe startup type of the ATI hotkey poller service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ati HotKey Poller\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5062-5LThe startup type of the Interix Subsystem Startup service should be correct.M(1) defined by the Services Admin< istrative Tool (2) definied by Group Policy CCE-5150-8BThe startup type of the Cluster Service service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClusSvc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5149-0MThe startup type of the IPSEC (IPsec Policy Agent) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4749-8JThe startup type of the IAS Jet Database Access service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IASJet\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4964-36The startup type of the IAS service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IAS\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4601-1FThe startup type of the IP Version 6 Helper service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4782-9BThe startup type of the Message Queuing service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQ\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4821-5UThe startup type of the Message Queuing Down Level Clients service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mqds\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4685-4KThe startup type of the Message Queuing Triggers service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSMQTriggers\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5002-1MThe startup type of the Client Service for Netware service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4653-2gThe startup type of the Windows Management Instrumentation Driver Extensions service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMI\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5103-7HThe startup type of the TCP/IP NetBIOS Helper service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LmHosts\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5270-4;The startup type of the Terminal service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5098-9BThe startup type of the Utility Manager service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UtilMan\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5173-0BThe startup type of the Secondary Logon service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seclogon\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4699-5UThe startup type of the Windows Management Instrumentation service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinMgmt\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5162-3AThe startup type of the SSDP Discovery service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4307-5>The startup type of the Workstation service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4762-1PThe startup type of the Remote Administration Service service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrvcSurg\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4974-2IThe startup type of the Microsoft POP3 Service service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\POP3svc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5251-4DThe startup type of the Windows Installer service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4987-4YThe startup type of the Windows System Resource Manager (WSRM) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WindowsSystemResourceManager\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5299-3SThe startup type of the WinHTTP Web Proxy Auto-Discovery service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4524-5^The startup type of the Services for Unix Trivial FTP Daemon (TFTP) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TFTPD\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5268-8SThe startup type of the Services for Unix Client for NFS service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Client for NFS\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4894-2UThe startup type of the Services for Unix Server for PCNFS service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KePcnfsd\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5220-9PThe startup type of the Services for Unix Perl Socket service should be correct. CCE-5127-6^The startup type of the Services for Unix User Name Mapping service service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Mapsvc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5429-6QThe startup type of the Services for Unix Windows Cron service should be correct. CCE-4686-2MThe startup type of the Print Server for Macintosh service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MacPrint\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4316-6The startup type of the Remote Installation Services (aka Boot Information Negotiation Layer or BNLSVC) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BINLSVC\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5050-0HThe startup type of the Remote Server Manager service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgr\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5125-0HThe startup type of the Remote Server Monitor service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Appmon\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4640-9NThe startup type of the Remote Storage Notification service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Remote_Storage_User_Link\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4326-5HThe startup type of the Remote Storage Server service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Remote_Storage_Server\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5218-3IThe startup type of the Windows Media < Services service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMServer\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4632-6pThe startup type of the Services for Netware Service Advertising Protocol (SAP) Agent service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwSapAgent\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5209-2FThe startup type of the Web Element Manager service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\elementmgr\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5222-5vThe startup type of the Remote Installation Services Single Instance Storage (SIS) Groveler service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Groveler\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4993-2gThe startup type of the TCP/IP Print Server (aka lpd print server or LPDSVC) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LPDSVC\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5165-6NThe startup type of the Terminal Services Licensing service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermServLicensing\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5013-8iThe startup type of the client-side Domain Name Service cache (aka DNS Client) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNSCache\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5105-2DThe startup type of the COM+ Event System service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventSystem\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4391-9<The startup type of the Event Log service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4735-7KThe startup type of the Infrared Monitor service service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Irmon\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5295-1>The startup type of the DHCP Client service should be correct. CCE-4329-9SThe startup type of the Services for Unix Server for NFS service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nfssrvr\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4328-1LThe startup type of the System Event Notification service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SENS\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4943-7QThe startup type of the NTLM Security Support Provider service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtLmSsp\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4340-6NThe startup type of the Performance Logs and Alerts service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4506-2@The startup type of the Plug and Play service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPLay\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5033-6DThe startup type of the Protected Storage service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5112-8OThe startup type of the QoS Admission Control (RSVP) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RSVP\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5064-1NThe startup type of the Remote Procedure Call (RPC) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5328-0@The startup type of the Print Spooler service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5174-8DThe startup type of the Removable Storage service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtmsSvc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5208-49The startup type of the Server service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Lanmanserver\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4343-0LThe startup type of the Security Accounts Manager service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SamSs\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4740-7FThe startup type of the Network Connections service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4349-7GThe startup type of the Logical Disk Manager service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dmserver\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5248-0VThe startup type of the Logical Disk Manager Administrative service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dmadmin\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5155-7<The startup type of the Net Logon service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5124-3CThe startup type of the File Replication service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WNtFrs\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy10.8.20-23, 10.8.20-16 CCE-5345-4SThe startup type of the Kerberos Key Distribution Center service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kdc\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-4613-6FThe startup type of the Intersite Messaging service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IsmServ\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5186-2VThe startup type of the Remote Procedure Call (RPC) Locator service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rpclocator\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5331-4JThe startup type of the Distributed File System service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dfs\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy CCE-5190-4WThe startup type of the Windows Internet Name Service (WINS) service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WINS\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy10.8.20-23, 10.8.20-26 CCE-5269-6?The startup type of the Windows Time service should be correct.(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Start (2) defined by the Services Administrative Tool (3) definied by Group Policy10.8.20-23, 10.8.20-28< CCE-5286-0BThe Terminal Services fDisableCdm setting should be set correctly.(1) Terminal Service Configuration Tool (2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\fDisableCdm 10.8.20-20 CCE-4864-5DThe Terminal Services fDisableClip setting should be set correctly.(1) Terminal Service Configuration Tool (2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\fDisableClip CCE-4773-8xInheritance of the shadow setting on the terminal server for remote control from another source should be set correctly.(1) Terminal Service Configuration Tool (2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\fInheritShadow CCE-5113-6EThe Terminal Services remote control configuration is set correctly.N(1) deny/obtain-interact/not-obtain-interact/obtain-display/not-obtain-display(1) Terminal Service Configuration Tool (2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\Shadow CCE-5298-5CThe Terminal Services fDisableCam setting should be set correctly.(1) Terminal Service Configuration Tool (2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\fDisableCam CCE-4733-2CThe Terminal Services fDisableCcm setting should be set correctly.(1) Terminal Service Configuration Tool (2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\fDisableCcm CCE-5183-9CThe Terminal Services fDisableLPT setting should be set correctly.(1) Terminal Service Configuration Tool (2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\fDisableLPT CCE-5258-9UThe required permissions for the directory %SystemDrive%\perflogs should be assigned. (1) defined by the object's DACL 10.8.20-08 CCE-5271-2QThe required permissions for the directory %SystemDrive%\i386 should be assigned. CCE-4357-0lThe required permissions for the directory %ProgramFiles%\Common Files\SpeechEngines\TTS should be assigned. 10.8.20-06 CCE-5031-0SThe required permissions for the file %SystemRoot%\_default.plf should be assigned. 10.8.20-09 CCE-4485-9RThe required permissions for the directory %SystemRoot%\addins should be assigned. CCE-5314-0TThe required permissions for the directory %SystemRoot%\appPatch should be assigned. CCE-5325-6PThe required permissions for the file %SystemRoot%\clock.avi should be assigned. CCE-4937-9]The required permissions for the directory %SystemRoot%\Connection Wizard should be assigned. CCE-4954-4SThe required permissions for the file %SystemRoot%\Driver Cache should be assigned. CCE-4531-0SThe required permissions for the file %SystemRoot%\explorer.scf should be assigned. CCE-5237-3SThe required permissions for the file %SystemRoot%\explorer.exe should be assigned. CCE-5143-3PThe required permissions for the directory %SystemRoot%\Help should be assigned. CCE-4862-9WThe required permissions for the file %SystemRoot%\inf\unregmp2.exe should be assigned. CCE-4989-0PThe required permissions for the directory %SystemRoot%\Java should be assigned. CCE-5227-4NThe required permissions for the file %SystemRoot%\mib.bin should be assigned. CCE-5051-8SThe required permissions for the directory %SystemRoot%\msagent should be assigned. CCE-5207-6RThe required permissions for the file %SystemRoot%\msdfmap.ini should be assigned. CCE-4392-7OThe required permissions for the directory %SystemRoot%\mui should be assigned. CCE-5111-0^The required permissions for the directory %SystemRoot%\security\templates should be assigned. CCE-4520-3RThe required permissions for the directory %SystemRoot%\speech should be assigned. CCE-5225-8QThe required permissions for the file %SystemRoot%\system.ini should be assigned. CCE-4374-5WThe required permissions for the file %SystemRoot%\system\setup.inf should be assigned. CCE-4585-6XThe required permissions for the file %SystemRoot%\system\stdole.tlb should be assigned. CCE-4823-1TThe required permissions for the directory %SystemRoot%\twain_32 should be assigned. CCE-5338-9^The required permissions for the directory %SystemRoot%\System32\cacls.exe should be assigned. CCE-4668-0_The required permissions for the directory %SystemRoot%\System32\attrib.exe should be assigned. CCE-5210-0\The required permissions for the directory %SystemRoot%\System32\CatRoot should be assigned. 10.8.20-07 CCE-4558-3iThe required permissions for the directory %SystemRoot%\System32\config\systemprofile should be assigned. CCE-4381-0YThe required permissions for the file %SystemRoot%\System32\debug.exe should be assigned. CCE-4908-0YThe required permissions for the directory %SystemRoot%\System32\dhcp should be assigned. CCE-5001-3\The required permissions for the directory %SystemRoot%\System32\drivers should be assigned. CCE-4785-2aThe required permissions for the file %SystemRoot%\System32\eventtriggers.exe should be assigned. CCE-5379-3YThe required permissions for the file %SystemRoot%\System32\edlin.exe should be assigned. CCE-5318-1_The required permissions for the file %SystemRoot%\System32\eventcreate.exe should be assigned. CCE-4850-4[The required permissions for the directory %SystemRoot%\System32\Export should be assigned. CCE-4820-7\The required permissions for the file %SystemRoot%\System32\ipconfig.exe should be assigned. CCE-5333-0]The required permissions for the file %SystemRoot%\System32\nslookup.exee should be assigned. CCE-4787-8[The required permissions for the file %SystemRoot%\System32\netstat.exe should be assigned. CCE-4985-8[The required permissions for the file %SystemRoot%\System32\nbtstat.exe should be assigned. CCE-5037-7WThe required permissions for the file %SystemRoot%\System32\ftp.exe should be assigned. CCE-5104-5]The required permissions for the directory %SystemRoot%\System32\LogFiles should be assigned. CCE-5196-1YThe required permissions for the file %SystemRoot%\System32\mshta.exe should be assigned. CCE-4460-2XThe required permissions for the directory %SystemRoot%\System32\mui should be assigned. CCE-4681-3WThe required permissions for the file %SystemRoot%\System32\net.exe should be assigned. CCE-5213-4YThe required permissions for the file %SystemRoot%\System32\netsh.exe should be assigned. CCE-4398-4XThe required permissions for the file %SystemRoot%\System32\net1.exe should be assigned. CCE-4619-3WThe required permissions for the file %SystemRoot%\System32\reg.exe should be assigned. CCE-5118-5ZThe required permissions for the file %SystemRoot%\System32\regini.exe should be assigned. CCE-5211-8\The required permissions for the file %SystemRoot%\System32\regsvr32.exe should be assigned. CCE-5308-2YThe required permissions for the file %SystemRoot%\System32\route.exe should be assigned. CCE-5202-7VThe required permissions for the file %SystemRoot%\System32\sc.exe should be assigned. CCE-4528-6]The required permissions for the directory %SystemRoot%\System32\ShellExt should be assigned. CCE-4545-0YThe required permissions for the file %SystemRoot%\System32\subst.exe should be assigned. CCE-4906-4^The required permissions for the file %SystemRoot%\System32\systeminfo.exe should be assigned. CCE-5232-4ZThe required permissions for the file %SystemRoot%\System32\telnet.exe should be assigned. CCE-5133-4XThe required permissions for the file %SystemRoot%\System32\tftp.exe should be assigned. CCE-4697-9YThe required permissions for the directory %SystemRoot%\System32\wbem should be assigned. CCE-4860-3[The required permissions for the file %SystemRoot%\System32\tlntsvr.exe should be assigned. CCE-4383-6]The required permissions for the directory %SystemRoot%\System32\wbem\mof should be assigned. CCE-5267-0dThe required permissions for the directory %SystemRoot%\System32\wbem\repository should be assigned. CCE-5046-8^The required permissions for the directory %SystemRoot%\System32\wbem\logs should be a< ssigned. CCE-5373-6tThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography should be assigned. 10.8.20-13 CCE-4738-1jThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hlp should be assigned. CCE-4394-3nThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\helpfile should be assigned. CCE-4590-6oThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing should be assigned. CCE-5159-9{The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Calais should be assigned. CCE-4859-5The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell should be assigned. CCE-5313-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony should be assigned. CCE-4414-9The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability should be assigned. CCE-4839-7The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell should be assigned. CCE-5354-6~The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion should be assigned. CCE-5306-6nThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Speech should be assigned. CCE-5006-2mThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC should be assigned. CCE-5041-9sThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EventSystem should be assigned. CCE-4636-7~The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates should be assigned. CCE-4634-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports should be assigned. CCE-4977-5vThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Driver Signing should be assigned. CCE-5321-5fThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Policies should be assigned. CCE-4981-7yThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor should be assigned. CCE-5413-0{The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ads\Providers\WinNT should be assigned. CCE-5383-5~The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ADs\Providers\NWCOMPAT should be assigned. CCE-4430-5yThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ADs\Providers\NDS should be assigned. CCE-5262-1The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ADs\Providers\LDAP\Extensions should be assigned. CCE-4776-1The required permissions for the registry key HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots should be assigned. CCE-5230-8The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager should be assigned. CCE-4966-8tThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help should be assigned. CCE-4457-8|The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip should be assigned. CCE-4788-6zThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Non-Driver Signing should be assigned. CCE-5179-7uThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DeviceManager should be assigned. CCE-4646-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Security should be assigned. CCE-5241-5{The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DHCP should be assigned. CCE-4765-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent should be assigned. CCE-5109-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security should be assigned. CCE-4892-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WMI\Security should be assigned. CCE-4446-1The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Security should be assigned. CCE-4688-8The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Security should be assigned. CCE-5201-9The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Security should be assigned. CCE-5417-1The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Samss\Security should be assigned. CCE-5060-9The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security should be assigned. CCE-4888-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm\Security should be assigned. CCE-5214-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility should be assigned. CCE-4637-5The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kdc\Security should be assigned. CCE-5342-1The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security should be assigned. CCE-5421-3vThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services should be assigned. CCE-4936-1The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers should be assigned. CCE-5029-4}The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network should be assigned. CCE-4853-8~The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Data should be assigned. CCE-4804-1}The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\GBG should be assigned. CCE-5293-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Skew1 should be assigned. CCE-4452-9|The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\JD should be assigned. CCE-5405-6uThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control should be assigned. CCE-5409-8lThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\wbem should be assigned. CCE-5246-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE\Security should be assigned. CCE-5096-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font should be assigned. CCE-5360-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog should be assigned. CCE-5065-8The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares should be assigned. CCE-5305-8zThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Windows 3.1 Migration Status should be assigned. CCE-5168-0dThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Secure should be assigned. CCE-5371-0lThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Program Groups should be a<ssigned. CCE-4886-8The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon should be assigned. CCE-4983-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones should be assigned. CCE-5370-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping should be assigned. CCE-5093-0zThe required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UPS should be assigned. CCE-4780-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper should be assigned. CCE-4463-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility should be assigned. CCE-5416-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDebug should be assigned. CCE-5385-0The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx should be assigned. CCE-5256-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce should be assigned. CCE-5353-8The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run should be assigned. CCE-5387-6oThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows should be assigned. CCE-5462-7nThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Secure should be assigned. CCE-5167-2kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RPC should be assigned. CCE-5330-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options should be assigned. CCE-5422-1The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole should be assigned. CCE-5312-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ProductOptions should be assigned. CCE-4469-3The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout should be assigned. CCE-5095-5The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex should be assigned. CCE-4567-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName should be assigned. CCE-4496-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy should be assigned. CCE-5219-1The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule should be assigned. CCE-5285-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost should be assigned. CCE-4752-2The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SecEdit should be assigned. CCE-5408-0The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList should be assigned. CCE-5364-5The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS should be assigned. CCE-5390-0The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 should be assigned. CCE-4504-7The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Classes should be assigned. CCE-5411-4The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion should be assigned. CCE-4949-4zThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates should be assigned. CCE-5151-6The required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows should be assigned. CCE-5501-2OThe required permissions for the directory %SystemRoot%\Web should be assigned. CCE-5294-4kThe required permissions for the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole should be assigned. CCE-5069-0The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers should be assigned. CCE-4897-5The required permissions for the registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies should be assigned.! P; T?z WN "& +.by5:b ?HBCFL8P HT WZaA^aG+eiwlpj sK vy||Q&yJo P җ Q3jE u ( :MAT-s RAVE9 b6 : } 0 L3  e8#<*8*4 6^u:=@YAC?GTJM\PK =U Y#]@bPfk5Sr w9A~cːÖg?ai8@  emrV B&o nccB f2 dM1B-Te)w}Ǚ)?;O!.<'GoMGN  dMbP?_*+%&?'?('}'}?)'}'}?Mb\\mbps1\1S147A-HPS odXXLetterPRIV0'''' \KhCN 7SMTJHP LaserJet 9050 PSESPRITSupportedTrueHPOrientationHPOrientationPortraitHPOrientRotate180FalsePostScriptCustomPageSizeFalseHPConsumerCustomPaperPSCustomHPSmartDuplexSinglePageJobTrueHPSmartDuplexOddPageJobTrueDuplexDuplexNoTumbleHPDuplicateJobNameOverrideSWFWPageSizeLETTERPageRegionLeadingEdgeInputSlot*UseFormTrayTableMediaTypeAutoHPNUseDiffFirstPageChoiceTrueHPPageExceptionsFileHPCPE5r1HPPageExceptionsInterfaceShowPageExceptionsHPPageExceptionsLowEndHPPageExceptionsLowEndVerHPPageExceptionsCoverInsertionHPMediaTypeDuplexConstraintsEXTRA_HEAVYHPDocUISUITruePSAlignmentFileHPCLS5r1PSServices_DeviceandSuppliesStatusTRUEHPSmartHub_OnlinediagnostictoolsTRUEHPSmartHub_SupportandtroubleshootingTRUEHPSmartHub_ProductmanualsTRUEHPSmartHub_CheckfordriverupdatesTRUEPSServicesOptionPrnStat_SID_242_BID_270_HID_15521HPSmartHubInet_SID_263_BID_276_HID_265JCLOptimizeForPLAINCollateFalseOutputBinAutoStapleLocationNoneAlternateLetterHeadFalseHPPaperSizeALMConstraintsENV_10TextAsBlackFalseHPEnableRAWSpoolingTrueHPDocPropResourceDataHPCabFileNameJCLEconomodeFalseJCLResolution600dpiJCLFastResTrueJCLHPPrintOnBothSidesManuallyFalseHPEdgeToEdgeTrueHPPJLEncodingUTF8HPJobAccountingHPJOBACCT_JOBACNTPrintQualityGroupPQGroup_1HPBornOnDateHPBODHPJobByJobOverrideJBJOHPColorModeMONOCHROME_MODEHPXMLFileUsedhpc9050s.xmlHPSendPJLUsageCmdCURIJRConstraintsJRCHDPartialJRHDInstalledJRHDOffJRHDNotInstalledJRHDOffHPJobAccWoPinTrueIUPHxoAǿ 1&M i .SJ\)U@ Bpă1 'xxmx&˖5!Җ!;XfGk@Z`Aq-PkY~S @p|sB4"I$mtx1qˍMK BH2~>p&qiDPu9;޴ =΀Eu6ꐖ~(?cMHQ]MX?W _ ukbGⷫHr_ hu aGA/z9Mec멯;G_hӍ;_V]w{VEwLׂ    ["d,, ` `? ` `?&`U} b} c} c} 2c} d}  e} I3f} $)g} #h} $ L  = = E                         O  O O O: ; ;;< >>?: ; ;;< >>? @ A A AB A C C D F G G G H I J JK F G G G H I J JK F G G G H I J JK F G G GH I J J!K F" G# G GH I$ J% J&K F' G( G GH I) J* J+K F, G- G G H I. J/ J0 K F1 G2 G G H I3 J4 J5 K F6 G7 G G H I8 J9 J: K F; G< G G H I= J> J? K F@ GA G G H IB JC JD K FE GF G GH IG JH JIK FJ GK G GH IL JM JNK FO GP G GH IQ MR JSK FT GU G GH IV J JWK FX GY G GH IZ J[ J\K F] G^ G GH I_ J` JaK Fb Gc G GH Id Je JfK Fg Gh G GH Ii Jj JkK Fl Gm G GH In Jo JpK Fq Gr G GH Is Jt JuK Fv Gw G GH Ix J JyK Fz G{ G GH I| J J}K F~ G G GH I J NK F G G GH I J JK F G G GH IP QK F G G GH I J JK F G G GH I J JK F G G GH I J JKDl88zvvvvvvvvvvvvvvvvvvvvvvvlvrvv ! " # $ % & ' ( ) * + , - . / 0 1 2 3 4 5 6 7 8 9 : ; < = > ?  F G G G H I J J K !F !G !G !G!H !I !J !J!K "F "G "G "G"H "I "J "J"K #F #G #G #G#H #I #J #J#K $F $G $G $G$H $I $J $J$K %F %G %G %G%H %I %J %JK &F &G &G &G&H &I &J &J&K 'F 'G 'G 'G'H 'I 'J 'J'K (F (G (G (G(H (I (J (J(K )F )G )G )G)H )I )J )J)K *F *G *G *G*H *I *J *J*K +F +G +G +G+H +I +J +Jy+K ,F ,G ,G ,G,H ,I ,J ,J,K -F -G -G -G-H -I -J -J-K .F .G .G .G.H .I .J .J.K /F /G /G /G/H /I /J /J/K 0F 0G 0G 0G0H 0I 0J 0J0K 1F 1G 1G 1G1H 1I 1J 1J1K 2F 2G 2G 2G2H 2I 2J 2J2K 3F 3G 3G 3G3H 3I 3J 3NK 4F 4G 4G 4G4H 4I 4J 4J4K 5F 5G 5G 5G5H 5I 5J 5J5K 6F 6G 6G 6G6H 6I 6J 6J6K 7F 7G 7G 7G7H 7I 7J 7J7K 8F 8G 8G 8G8H 8I 8J 8J 8K 9F  9G  9G 9G9H 9I  9J  9J9K :F :G :G :G:H :I :J :RK ;F ;G ;G ;G;H ;I ;J ;J;K <F <G <G <G<H <I <J <J<K =F =G =G =G=H =I =J  =J=K >F! >G" >G >G>H >I# >J$ >J%>K ?F& ?G' ?G ?G?H ?I( ?J ?J)?KD"lvvvvvlvvvvvvvvvvvvvlvvvvvvlvvvv@ A B C D E F G H I J K L M N O P Q R S T U SV SW SX SY SZ S[ S\ S] S^ S_  @F* @G+ @G @G@H @I, @J @J-@K AF. AG/ AG AGAH AI0 AJ AJ1AK BF2 BG3 BG BGBH BI4 BJ5 BJ6BK CF7 CG8 CG CGCH CI9 CJ: CJCK DF; DG< DG DGDH DI= DJ DJ>DK EF? EG@ EG EGEH EIA EJ EJBEK FFC FGD FG FGFH FIEFJ~ FJp@FK GFF GGG GG GGGH GIHGJ GJIGK HFJ HGK HG HGHH HIL HJ HJMHK IFN IGO IG IGIH IIP IJQ IJRIK JFS JGT JG JGJH JIU JJV JJJK KFW KGX KG KGKH KIY KJ KJZKK LF[ LG\ LG LGLH LI] LJ^ LJ_LK MF` MGa MG MGMH MIb MJc MJdMK NFe NGf NG NGNH NIg NMh NJiNK OFj OGk OG OGOH OIl OJm OJnOK PFo PGp PG PGPH PIq PJr PJsPK QFt QGu QG QGQH QIv QJw QJxQK RFy RGz RG RGRH RI{ RJ| RJ}RK SF~ SG SG SGSH SI SJ SJSK TF TG TG TGTH TI TJ TNK UF UG UG UGUH UI UJ UJUK VF VG VG VGVH VI VJ VJVK WF WG WG WGWH WI WJ WJWK XF XG XG XGXH XI XJ XJXK YF YG YG YGYH YI YJ YJYK ZF ZG ZG ZGZH ZI ZJ ZJZK [F [G [G [G[H [I [J [J[K \F \G \G \G\H \I \J \J\K ]F ]G ]G ]G]H ]I ]J ]J]K ^F ^G ^G ^G^H ^I ^J ^J^K _F _G _G _G_H _I _J _J_KD.lvvvvvvrrvvvvvvvvvvvvlvvvvvvvvvv` a b c d e f g h i j k l m n o p q r s t u v w x y z { | } ~   `F `G `G `G`H `I `J `J`K aF aG aG aGaH aI aJ aNK bF bG bG bGbH bI bJ bJbK cF cG cG cGcH cI cJ cJcK dF dG dG dGdH dI dJ dJdK eF eG eG eGeH eI eJ eJeK fF fG fG fGfH fI fJ fJfK gF gG gG gGgH gI gJ gJK hF hGK hG hGhH hI hJ hJMhK iF iG iG iGiH iI iJ iJiK jF jG jG jGjH jI jJ jJjK kF kG kG kGkH kI kJ kJkK lF lG lG lGlH lI lJ lJlK mF mG mG mGmH mI mJ mJmK nF nG nG nGnH nI nJ nJnK oF oG oG oGoH oI oJ oJoK pF  pG  pG pG pH pI  pJ  pJpK qF qG qG qGqH qI qJ qJqK rF rG rG rGrH rI rJ rJrK sF sG sG sGsH sI sJ sJ sK tF! tG" tG tG#tH tI$ tJ% tJ&tK uF' uG( uG uG)uH uI* uJ+ uJ,uK vF- vG. vG vG/vH vI0 vJ1 vJ2vK wF3 wG4 wG wG5wH wI6 wJ7 wJ8wK xF9 xG: xG xG;xH xI< xJ= xJ>xK yF? yG@ yG yGAyH yIB yJC yJDyK zFE zGF zG zGGzH zIH zJI zJJzK {FK {GL {G {GM{H {IN {JO {JP{K |FQ |GR |G |GS|H |IT |JU |JV|K }FW }GX }G }GY}H }IZ }J[ }J\}K ~F] ~G^ ~G ~G_~H ~I` ~Ja ~Jb~K Fc Gd G GeH If Jg JhKD,lvlvvvvvlvvvvvvvvvvvvvvvvvvvvvvv                     T T           Fi Gj G GkH Il Jm JnK Fo Gp G GqH Ir Js JtK Fu Gv G GwH Ix Jy JzK F{ G| G G}H I~ J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J RK F G G GH I J JK F G G GH I J JKD@lvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv U U   U U   U U                       F G G  G H I  J  J K F G G GH IJ J K F G G GH I J JK F G G GH I J JK F G G  G H I! J" J#K F$ G% G GH I&J J#K F' G( G G)H I* J+ J,K F- G. G G/H I0 J1 J2K F3 G4 G  G H I5 J6 J7K F8 G9 G GH I:J J7K F; G< G GH I= J> J?K F@ GA G GH IB JC JDK FE GF G GH IG JH JIK FJ GK GL GMH IN J JOK FP GQ G GH IR JS JTK FU GV GW GH IX JY JZK F[ G\ G GH I] J^ J_K F` Ga Gb GcH Id Je JK Ff Gg Gb GhH Ii Jj JK Fk Gl Gb GmH In Jo JpK Fq Gr Gb GsH It Ju JK Fv Gw Gb GxH Iy Jz JK F{ G| Gb G}H I~ J JK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J NK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J JKD lvhvvvhvvvhvvvvvvvvvvvvvvvlvvvvv          O                       F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH I J JK F G Gb GH IJ JK F G G GH IJ JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH IJ JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J J K F  G  G G H I  J JK F G G GH I J JK F G G GH I J JK F G G GH I J  JK F! G" G G#H I$ J% J&K F' G( G G)H I* J+ JK F, G- G. G/H I0 J1 J2K F3 G4 G. G5H I6 J7 J8K F9 G: G G;H I< J= J>K F? G@ G GAH IB JC JDK FE GF G GGH IH JI JJK FK GL G GMH IN JO JPK FQ GR G GSH IT JU JK FV GW G GXH IY JZ JK F[ G\ G G]H I^ J_ JKDlvvvllrrvlvvrvvvvvvvvvvvvvvvvvvl                                 F` Ga Gb GcH Id Je JK Ff Gg Gh GiH Ij Jk JlK Fm Gn G GoH Ip Jq JrK Fs Gt Gu GvH Iw Jx JyK Fz G{ G| G}H I~ J JK F G G| GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F GG GH IJ JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH I J JK F G G G H I  J  JK F  G  G GH I J JK F G G GH I J JKDllvvvvvvvvrrrrrvvvvvvvvnvvvvvvvv     V                                 F G G GH I J JK F G G  G!H I" J# J$K F% G& G G'H I( J) J*K F+ G G G,H I- J. J/K F0 G1 G GH I2 J3 J4K F5 G6 G G7H I8 J9 J:K F; G< G G=H I> J? JK F@ GA G GBH IC JD JEK FF GG G GHH II JJ JK FK GL G GM H IN JO JP K FQ GR GS GT H IU JV JW K FX GY GZ G[ H I\ J] J^ K F_ G` G Ga H Ib Jc J K Fd G G G H Ie Jf J K Fg G G GH Ih Ji JK Fj Gk G GlH Im Jn JoK Fp Gq G GrH Is Jt JuK Fv Gw Gx GyH Iz J{ J|K F} G~ G GH I J JK F W G GH I J JK F W G GH I J JK F G G GH I J JK F G G GH I J JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH IJ JK F G G GH I J JKD lvvvvvvvvvvvvvvvvvvvvvvvrrrrrrrr  ! " # $ % &  '  (  ) * + , - . / 0 1 2 3 4 5 6 7 8 9 : ; < = > ?  F G G G H I J J K !F !G !G !G!H !I!J !J!K "X "Y "Y "Y"H "Z"J "J"K #X #Y #Y #Y#H #Z#J #J#K $X $Y $Y $Y$H $Z$J $J$K %X %[ %Y %Y%H %Z%J %J%K &X &[ &Y &Y&H &Z&J &J&K 'X '[ 'Y 'Y'H 'Z'J 'J'K (X ([ (Y (Y(H (Z(J (J(K )X )\ )GGH )I )JJK *X *G *G *G*H *I*J *J*K +X +G +G +G+H +I+J +J+K ,] ,G ,Gb ,G,H ,I,J ,J,K -] -G -Gb -G-H -I-J -J-K .] .^ .^ .^.H .I.J .J .K /]  /G  /Gb /G/H /I /J /J /K 0] 0G 0Gb 0G0H 0I0J 0J0K 1] 1G 1G 1G1H 1I1J 1J1K 2] 2G 2Gb 2G2H 2I2J 2J2K 3] 3G 3Gb 3G3H 3I3J 3J3K 4]  4^! 4G 4_"4H 4`#4J 4J$4K 5]% 5_& 5Gb 5G5H 5I'5J 5J(5K 6]) 6^* 6^b 6^6H 6I+6J 6J,6K 7]- 7^. 7^ 7^/7H 7I07J 7J17K 8]2 8G3 8Gb 8G8H 8I48J 8J58K 9]6 9^7 9^ 9GH 9I89J 9J99K :]: :^; :^ :^:H :I<:J :J=:K ;]> ;G? ;Gb ;G;H ;I@;J ;JA;K <]B <^C <G <GH <ID<J <JE<K =]F =GG =GH =GH =II=J =JJ=K >]K >GL >G >GH >IM>J >JN>K ?]O ?^P ?G ?GH ?IQ?J ?JR?KDflrrrrrrrrrJrrrrrrrrrrrrrrrhrrhhh@ A B C D 4E F G H I J K 4L M N O P Q R S T U V W X Y Z [ \ ] ^ _  @]S @GT @G @GH @IU@J @JV@K A]W AGX AG AGH AIYAJ AJZAK B][ B^\ B^b B^]BH BI^BJ BJ_BK C]` CGa CGb CGCH CIbCJ CJcCK D]d D^e DGGH DIfDJ DJgDK E]h EGi EGb EG EHIJ EJjEK F]k F^l F^ F^mFH FInFJ FJoFK G]p GGq GGb GGGH GIrGJ GJsGK H]t H^u H^b H^HH HIvHJ HJwHK I]x IGy IGb IGIH IIzIJ IJ{IK J]| J^} J^b J^~JH JIJJ JJJK K] K^ KGGH KIKJ KJKK L] LG LGb LGLH LILJ LJLK M] MG MGb MGMH MIMJ MJMK N] NGNGGHIJ NJNK O] OG OGb OGOH OIOJ OJOK P] PG PG PGH PIPJ PJPK Q] QG QG QGQHaJJ QK R] RG RG RGRHaJJ RK S] SG SG SGSHaJJ SK T] TG TG TGTHaJJ TK U] UG UG UGUHaJJ UK V] VG VG VGVHaJJ VK W] WG WG WGWHaJJ WK X] XG XG XGXHaJJ XK Y] YG YG YGYHaJJ YK Z] ZG ZG ZGZHaJJ ZK [] [G [G [G[HaJJ [K \] \G \G \G\HaJJ \K ]] ]G ]G ]G]HaJJ ]K ^] ^G ^G ^G^HaJJ ^K _] _G _G _G_HaJJ _KDlhhrr\`rrrrr\rrHrhXXXXXXXXXXXXXX` a b c d e f g h i j k l m n o p q r s t u v w x y z { | } ~   `] `G `G `G`HaJJ `K a] aG aG aGaHaJJ aK b] bG bG bGbHaJJ bK c] cG cG cGcHaJJ cK d] dG dG dGdHaJJ dK e] eG eG eGeHaJJ eK f] fG fG fGfHaJJ fK g] gG gG gGgHaJJ gK h] hG hG hGhHaJJ hK i] iG iG iGiHaJJ iK j] jG jG jGjHaJJ jK k] kG kG kGkHaJJ kK l] lG lG lGlHaJJ lK m] mG mG mGmHaJJ mK n] nG nG nGnHaJJ nK o] oG oGb oGoHaJJ oK p] pG pG pGpHaJJ pK q] qG  qG qG qHaJJ qK r]  rG  rG rG rHaJJ rK s] sG sG sGsHaJJ sK t] tG tG tGtHaJJ tK u] uG uG uGuHaJJ uK v] vG vG vGvHaJJ vK w] wG wGb wGwHaJJ wK x] xG xGb xGxHaJJ xK y]  yG! yGb yG"yHaJJ yK z]# zG$ zGb zG%zHaJJ zK {]& {G' {G {G({HaJJ {K |]) |G* |Gb |G+|HaJJ |K }], }G- }G }G.}HaJJ }K ~]/ ~G0 ~Gb ~G1~HaJJ ~K ]2 G3 G G4HaJJ KD lXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX                                 ]5 G6 G G7HaJJ K ]8 G9 Gb G:HaJJ K ]; G< G G=HaJJ K ]> G? G G@HaJJ K ]A GB G GCHaJJ K ]D GE G GFHaJJ K ]G GH G GIHaJJ K ]J GK G GHaJJ K ]L GM G GNHaJJ K ]O GP G GHaJJ K ]Q GR G GSHaJJ K ]T GU G GVHaJJ K ]W GX G GYHaJJ K ]Z G[ G G\HaJJ K ]] G^ G G_HaJJ K ]` Ga G GbHaJJ K ]c Gd G GeHaJJ K ]f Gg G GhHaJJ K ]i Gj G GkHaJJ K ]l Gm G GnHaJJ K ]o Gp G GqHaJJ K ]r Gs G GtHaJJ K ]u Gv G GwHaJJ K ]x Gy G GzHaJJ K ]{ G| G G}HaJJ K ]~ G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G Gb GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ KD lXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX                                 ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJK ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ KDt lXXXXXXXXXXXXXXXXXXXXXLXXXXXXXXX                                 ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G  G GHaJJ K ]  G  G GHaJJ K ]  G  G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G G GHaJJ K ] G  G GHaJJ K ]! G" G GHaJJ K ]# G$ G GHaJJ K ]% G& G GHaJJ K ]' G( G GHaJJ K ]) G* G GHaJJ K ]+ G, G GHaJJ K ]- G. G GHaJJ K ]/ G0 G GHaJJ K ]1 G2 G GHaJJ K ]3 G4 G GHaJJ KD lXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX                                 ]5 G6 G GHaJJ K ]7 G8 G GHaJJ K ]9 G: G GHaJJ K ]; G< G GHaJJ K ]= G> G GHaJJ K ]? G@ G GHaJJ K ]A GB G GHaJJ K ]C GD G GHaJJ K ]E GF G GHaJJ K ]G GH G GHaJJ K ]I GJ G GHaJJ K ]K GL G GHaJJ K ]M GN G GHaJJ K ]O GP G GHaJJ K ]Q GR G GHaJJ K ]S GT G GHaJJ K ]U GV G GHaJJ K ]W GX G GHaJJ K ]Y GZ G GHaJJ K ][ G\ G GHaJJ K ]] G^ G GHaJJ K ]_ G` G GHaJJ K ]a Gb G GHaJJ Kc ]d Ge G GHaJJ Kc ]f Gg G GHaJJ Kc ]h Gi G GHaJJ Kc ]j Gk G GHaJJ Kc ]l Gm G GHaJJ Kc ]n Go G GHaJJ Kc ]p Gq G GHaJJ Kc ]r Gs G GHaJJ Kc ]t Gu G GHaJJ KcD lXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX                                      ]v Gw G GHaJJ Kc ]x Gy G GHaJJ Kc ]z G{ G GHaJJ Kc ]| G} G GHaJJ Kc ]~ G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G G HaJJ Kc ] G G G HaJJ Kc ] G G G HaJJ Kc ] G G G HaJJ Kc ] G G G HaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ Kc ] G G GHaJJ KcD lXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX  ! " # $ % & ' ( ) * + , - . / 0 1 2 3 4 5 6 7 8 9 : ; < = > ?  ] G G G HaJJ Kc !] !G !G !G!HaJJ !Kc "] "G "G "G"HaJJ "Kc #] #G #G #G#HaJJ #Kc $] $G $G $G$HaJJ $Kc %] %G %G %G%HaJJ %Kc &] &G &G &G&HaJJ &Kc '] 'G 'G 'G'HaJJ 'Kc (] (G (G (G(HaJJ (Kc )] )G )G )G)HaJJ )Kc *] *G *G *G*HaJJ *Kc +] +G +G +G+HaJJ +Kc ,] ,G ,G ,G,HaJJ ,Kc -] -G -G -G-HaJJ -Kc .] .G .G .G.HaJJ .Kc /] /G /G /G/HaJJ /Kc 0] 0G 0G 0G0HaJJ 0Kc 1] 1G 1G 1G1HaJJ 1Kc 2] 2G 2G 2G2HaJJ 2Kc 3] 3G 3G 3G3HaJJ 3Kc 4] 4G 4G 4G4HaJJ 4Kc 5] 5G 5G 5G5HaJJ 5Kc 6] 6G 6G 6G6HaJJ 6Kc 7] 7G 7G 7G7HaJJ 7Kc 8] 8G 8G 8G8HaJJ 8Kc 9] 9G 9G 9G9HaJJ 9Kc :] :G :G :G:HaJJ :Kc ;] ;G ;G ;G;HaJJ ;Kc <] <G <G <G<HaJJ <Kc =] =G =G =G=HaJJ =Kc >] >G >G >G>HaJJ >Kc ?] ?G ?G ?G?HaJJ ?KcD lXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX@ A B C D E F G H I J K L M N O P Q R S T U V W X Y Z [ \ ] ^ _  @] @G @G @G@HaJJ @Kc A] AG AG AGAHaJJ AKc B] BG BG BGBHaJJ BKc C] CG CG CGCHaJJ CKc D] DG DG DGDHaJJ DKc E] EG EG EGEHaJJ EKc F] FG FG FGFHaJJ FKc G] GG GG GGGHaJJ GKc H] HG HG HGHHaJJ HKc I] IG IG IGIHaJJ IKc J] JG JG JGJHaJJ JKc K] KG KG KGKHaJJ KKc L] LG LG LGLHaJJ LKc M] MG MG MGMHaJJ MKc NF NG NG NGNHaJJ NK OF OG OG OGOHaJJ OKc PF PG PG PGPHaJJ PKc QF QG QG QGQHaJJ QKcRFGGGHaJJKSFGGGHaJJKTFGGGHaJJKUFGGGHaJJKVFGGGHaJJKWFGGGHaJJKXFGGGHaJJKYFGGGHaJJKZFGGGHaJJK[FGGGHaJJK\FGGGHaJJK]FGGGHaJJK^FGGGHaJJK_FGGGHaJJKD8 lXXXXXXXXXXXXXXXXXX` a b c d e f g h i j k l m n o p q r s t u v w x y z { | } ~  `FGGGHaJJKaFGGGHaJJKbFGGGHaJJKcFGGGHaJJKdFGGGHaJJKeFGGGHaJJKfFGGGHaJJKgFGGGHaJJKhFGGGHaJJKiFGGGHaJJKjFGGGHaJJKkFGGGHaJJKlFGGGHaJJKmFGGGHaJJKnFGGGHaJJKoFGGGHaJJKpFGGGHaJJKqFGGGHaJJKrFGGGHaJJKsFGGGHaJJKtFGGGHaJJKuFGGGHaJJKvFGGGHaJJKwFGGGHaJJKxFGGGHaJJKyFGGGHaJJKzFGGGHaJJK{FGGGHaJJK|FGGGHaJJK}FGGGHaJJK~FGGGHaJJKFGGGHaJJKDl   FGGGHaJJKFGGGHaJJKFGGGHaJJK (>@KGBA ggD Oh+'0@H\p  Sain, Joe Sain, JoeMicrosoft Excel@E$hv@v՜.+,0 PXx  The MITRE Corporation win2k  Worksheets  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~Root Entry FWorkbookNSummaryInformation(DocumentSummaryInformation8