
Chapter 4 Securing the Enterprise 97
Category Events
Logon and Logoff Logon attempts, logoff attempts, and the creating and
breaking of network connections to servers.
File and Object Access Accesses a directory or a file set for auditing in Windows
Explorer; uses of a printer managed by the computer.
Use Of User Rights Successful uses of user rights and failed attempts to use
rights not assigned to users.
User and Group
Management
Creation, deletion, and modification of user and group
accounts.
Security Policy Changes Granting or revoking user rights to users and groups, and
establishing and breaking trust relationships with other
domains.
Restart, Shutdown, and
System
Shutting down and restarting the computer, filling up the
audit log, and discarding audit entries if the audit log is
already full.
Process Tracking Starting and stopping processes on the computer.
You specify what types of system events are audited through the Group Policy
Snap-In. The following table shows the types of folder and file accesses you can
audit.
Folder access File access
Displaying names of files in the folder Displaying the file’s data
Displaying folder attributes Displaying file attributes
Changing folder attributes Displaying the file’s owner and permissions
Creating subfolders and files Changing the file
Going to the folder’s subfolders Changing file attributes
Displaying the folder’s owner and
permissions
Running the file
Deleting the folder Deleting the file
Changing folder permissions Changing the file’s permissions
Changing folder ownership Changing the file’s ownership
Comentarios a estos manuales