SKYFORT
CYBERSECURITY
🏰 Shield FRAMEWORK
Windows Server 2019 Security Baseline

Security controls for Windows Server 2019 based on CIS Benchmark, NIST 800-53, Microsoft Security Baselines, and industry best practices.

Level: Shield

Controls: 150+ Maximum Controls

Compliance: CIS, NIST, PCI DSS, ISO 27001

Version: 1.0.0 | March 2026

📑 TABLE OF CONTENTS
150+
Total Controls
6
Categories
4+
Compliance
100%
Documented
🔐AUTH - Authentication - Password policies and account management
📁FILE - File System - NTFS and file permissions
🌐NET - Network - Firewall and connectivity security
📊AUDIT - Auditing - Logging and monitoring
⚙️SYS - System - Services and updates
🔍MON - Monitoring - Active protection
🔐 AUTH - AUTHENTICATION CONTROLS

Shield-AUTH-001 Minimum Password Length of 14 Characters

DESCRIPTION
Ensure that the password policy requires a minimum of 14 characters for all user accounts.
JUSTIFICATION
Short passwords are easily compromised through brute force and dictionary attacks. CIS Benchmark and NIST standards recommend 14+ characters as minimum for adequate security. A 14-character password provides trillions of possible combinations, making brute force attacks impractical.
REMEDIATION
GPO: Password Policy → Minimum password length = 14
PowerShell: net accounts /minpwlen:14

Shield-AUTH-002 Account Lockout After 5 Failed Attempts

DESCRIPTION
Configure automatic account lockout after 5 consecutive failed login attempts.
JUSTIFICATION
Account lockout prevents brute force and password spraying attacks. Without this protection, an attacker can try infinite password combinations through automated tools.
REMEDIATION
GPO: Account Lockout Policy → Account lockout threshold = 5
PowerShell: net accounts /lockoutthreshold:5

Shield-AUTH-003 Guest Account Disabled

DESCRIPTION
The Guest account must be disabled on all systems.
JUSTIFICATION
The Guest account allows anonymous access, representing a significant security risk. Attackers frequently use this account to gain initial access and escalate privileges.
REMEDIATION
PowerShell: net user guest /active:no

Shield-AUTH-004 Password Complexity Required

DESCRIPTION
Require passwords to include uppercase, lowercase, numbers, and special characters.
JUSTIFICATION
Password complexity significantly increases entropy, making dictionary and brute force attacks much more difficult. A 14-character password with complexity has trillions of combinations.
REMEDIATION
GPO: Password must meet complexity requirements = Enabled
🌐 NET - NETWORK CONTROLS

Shield-NET-001 Windows Firewall Active

DESCRIPTION
Windows Firewall must be enabled for all network profiles.
JUSTIFICATION
The firewall is the first line of defense against unauthorized access. It blocks unsolicited inbound connections and prevents malware propagation.
REMEDIATION
PowerShell: Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True

Shield-NET-002 SMBv1 Disabled

DESCRIPTION
SMB version 1 protocol must be completely disabled.
JUSTIFICATION
SMBv1 is vulnerable to critical attacks like EternalBlue, WannaCry, and NotPetya. This legacy protocol does not offer encryption or protection against MITM attacks.
REMEDIATION
PowerShell: Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force

Shield-NET-003 RDP Requires NLA

DESCRIPTION
Remote Desktop must require Network Level Authentication.
JUSTIFICATION
NLA authenticates before establishing the full RDP session, preventing MITM attacks and exploitation of RDP vulnerabilities.
REMEDIATION
GPO: Require user authentication for remote connections = Enabled
⚙️ SYS - SYSTEM CONTROLS

Shield-SYS-001 Automatic Windows Update

DESCRIPTION
The system must be configured to install security updates automatically.
JUSTIFICATION
Updates fix known vulnerabilities. Outdated systems are easy targets for malware and exploits. Automation ensures timely patch application.
REMEDIATION
GPO: Configure Automatic Updates = Enabled (Option 4)

Shield-SYS-002 PowerShell v2 Disabled

DESCRIPTION
PowerShell version 2 must be disabled or removed.
JUSTIFICATION
PowerShell v2 does not support modern security features like script block logging. Attackers use v2 to evade detection.
REMEDIATION
PowerShell: Disable-WindowsOptionalFeature -Online -FeatureName MicrosoftWindowsPowerShellV2
🔍 MON - MONITORING CONTROLS

Shield-MON-001 Wazuh Agent Active

DESCRIPTION
The Wazuh monitoring agent must be installed and communicating.
JUSTIFICATION
Centralized monitoring is essential for real-time threat detection, incident response, and compliance. Without monitoring, compromises go unnoticed.
REMEDIATION
Download agent from wazuh.skyfortcyber.com and configure server IP.

Shield-MON-002 Windows Defender Active

DESCRIPTION
Windows Defender must be enabled with real-time protection.
JUSTIFICATION
Windows Defender offers native, free, effective anti-malware protection. Systems without protection are quickly compromised.
REMEDIATION
PowerShell: Set-MpPreference -DisableRealtimeMonitoring $false