CVE
- Id
- 559
- CVE No.
- CVE-1999-0577
- Status
- Candidate
- Description
- A Windows NT system"s file audit policy does not log an event success or failure for non-critical files or directories.
- Phase
- Proposed (19990721)
- Votes
- ACCEPT(2) Shostack, Wall | MODIFY(3) Baker, Frech, Ozancin | REJECT(1) Northcutt
- Comments
- Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Perhaps only failure should be logged. | Frech> XF:nt-object-audit | CHANGE> [Baker changed vote from REVIEWING to MODIFY] | Baker> Failure on non-critical files is what should be monitored.