Clear Virtual Memory Page File
Many administrators want to have the system clear the page file on shutdown to avoid attackers sniffing through it for interesting data in case the system is stolen. Although we have no problem in principle with this, you really have to ask yourself how likely it is that they will actually (a) steal the system, (b) find something interesting, and (c)actually be able to tell that it is interesting. OK, if you are up against a foreign intelligence service, the answers to these questions may dictate that you should clear the page file. If they do, you still need to consider shutdown times, however. It could take up to an additional 40 minutes to clear the page file at shutdown. Do you really want your laptop to take an additional 40 minutes to shut down after the flight attendants announce that "we have now reached an altitude where portable electronics devices may no longer be used?"
In this tutorial:
- Protecting Hosts
- Security Configuration Myths
- Myth 1: Security Guides Make Your System Secure
- Myth 2: If We Hide It, they Not Find It
- Myth 3: The More Tweaks, the Better
- Myth 4: Tweaks Are Necessary
- Myth 5: All Environments Should At Least Use <Insert Favorite Guide Here>
- Myth 6: "High Security" Is an End Goal for All Environments
- Myth 7: Start Securing Your Environment by Applying a Security Guide
- Myth 8: Security Tweaks Can Fix Physical Security Problems
- Myth 9: Security Tweaks Will Stop Worms/Viruses
- Myth 10: An Expert Recommended This Tweak as Defense in Depth
- Server Security Tweaks
- Software Restriction Policies
- Do Not Store LAN Manager Hash Value
- Anonymous Restrictions
- Security Identifiers (SIDs)
- Password Policies
- SMB Message Signing
- Networking LAN Manager Authentication Level
- TCP Hardening
- Restricted Groups
- Audit Settings
- Client Security Tweaks
- Firewalls
- IPsec Filters
- SafeDllSearchMode
- Local Administrator Account Control
- Limit Local Account Use of Blank Passwords to Console Logon Only
- Logon Events
- Allowed to Format and Eject Removable Media
- The Caution ListChanges You Should Not Make
- Crash on Audit Failure
- Clear Virtual Memory Page File
- Security Configuration Tools