17.9.3 (L1) Ensure 'Audit Security State Change' is set to include 'Success' (Automated)

System_AuditSecurityStateChange

This policy setting allows you to audit events generated by changes in the security state of the computer such as the following events: Startup and shutdown of the computer. Change of system time. Recovering the system from CrashOnAuditFail, which is logged after a system restarts when the security event log is full and the CrashOnAuditFail registry entry is configured.

Last updated