Created
August 27, 2026 15:48
-
-
Save drrk/ec189750ebe4f13cd0b1a4ab542cde6a to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # InSpec waivers for Scenario 6 demo subset profile. | |
| # | |
| # Controls 18.9.28.3 and 18.9.28.4 govern domain-joined computer enumeration | |
| # behaviour. They are not applicable on standalone (non-domain-joined) servers. | |
| # Failures on these controls are expected and governed — not ignored. | |
| # | |
| # Usage: | |
| # inspec exec . --waiver-file waivers.yml -t winrm://... | |
| # Or upload alongside the profile to Automate when assigning to the cohort. | |
| xccdf_org.cisecurity.benchmarks_rule_18.9.28.3_L1_Ensure_Do_not_enumerate_connected_users_on_domain-joined_computers_is_set_to_Enabled: | |
| expiration_date: "2027-01-31" | |
| run: false | |
| justification: > | |
| This control requires the node to be domain-joined. The demo environment | |
| uses standalone (workgroup) Windows Server 2022 nodes that are not members | |
| of an Active Directory domain. The policy registry key | |
| HKLM\Software\Policies\Microsoft\Windows\System\DontEnumerateConnectedUsers | |
| is only meaningful and enforceable in a domain context. This waiver is | |
| time-bound, explicitly approved and documents the non-applicability — it | |
| is not a suppression of a genuine security gap. | |
| xccdf_org.cisecurity.benchmarks_rule_18.9.28.4_L1_Ensure_Enumerate_local_users_on_domain-joined_computers_is_set_to_Disabled_MS_only: | |
| expiration_date: "2027-01-31" | |
| run: false | |
| justification: > | |
| This control is scoped to domain-joined computers (MS only). The demo | |
| environment uses standalone (workgroup) Windows Server 2022 nodes. The | |
| EnumerateLocalUsers registry value under | |
| HKLM\Software\Policies\Microsoft\Windows\System has no security relevance | |
| on non-domain-joined hosts. This waiver is time-bound and explicitly | |
| documents the architectural non-applicability of the control. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment