nt 4 wkstation registry lockdown

From: neil (nlehrer@yahoo.com)
Date: 01/18/02


From: nlehrer@yahoo.com (neil)
Date: 17 Jan 2002 15:09:56 -0800

hi,

what do people do to lock down hklm\software after the pc has been in
use for a long time? the nsa guidelines say to give everyone read on
hklm\software, but does not specify recursing down. however, once
software has been loaded the cow is out of the barn. for example:

Software\Adobe\Acrobat Reader\5.0
        Owner: Administrators (lg)
        Administrators (lg) (Full)*1
        CREATOR OWNER ()*(Full)
        Everyone (QWCENDR)*1
        SYSTEM (Full)*1

everyone has almost everything.

should i recurse down hklm\software and set all entries for everyone
to 'read'?

thanks.