Check DEP Security Configuration
Hardening method: Access to "Control Panel, System and security system" advanced system settings-on the Advanced tab, under Performance, under Settings. Go to the Data Execution Protection tab. Set to "Enable DEP only for basic Windows operating system programs and services"
Check whether NTP is configured
Hardening Method: cmd Command Window execution w32tm/config/update
Modify the key value of the following options in Hkey_local_machine\system\currentcontrolset\services\w32time\timeproviders\ntpserver [Enabled] is set to 1. Function: Turns on the NTP server feature (the default is not to turn on the NTP Server service unless the computer is upgraded to a domain control station).
Modify the following key values Hkey_local_machine\system\currentcontrolset\services\w32time\config\announceflags set to 5. Function: This setting forces the host to announce itself as a reliable time source, thereby using the built-in complementary metal oxide semiconductor (CMOS) clock. Use the default a value if you want to use the outside time server.
Modify the following key value in the Hkey_local_machine\system\currentcontrolset\services\w32time\parameters\type [Type] set to NTP. 4. Restart the Win32time service: Turn off the Windows Time service before turning on the service. It can be done under the services interface of the administrative tools, or you can enter "net stop W32Time", "net start W32Time" in DOS.
Check critical permission assignment security requirements-take ownership of files or other objects
Hardening method: Access to User rights assignment, local policy, local security policy, start-and management tools, "Get ownership of files or other objects" set to "assign only to Administrators groups"
Check the password lock policy to determine the condition: "Account lockout threshold" is set to less than or equal to 6 times
Reinforcement method:
This article is from the "httpblog.mvp-610163.com" blog, make sure to keep this source http://341103.blog.51cto.com/331103/1852104
Windows R2 System Hardening