National Institute of Standards and Technology (NIST) - Information technology Laboratory (ITL)

The United States Government Configuration Baseline (USGCB) - Windows Vista Firewall Content

Warning Notice

Do not attempt to implement any of the settings without first testing them in a non-operational environment. These recommendations have only been tested on Windows 7 Ultimate 32-bit, Windows 7 Ultimate 64-bit, Windows 7 Enterprise x86, and Windows 7 Enterprise x64. These settings may be applicable to other Windows systems and service packs; however, NIST has not tested other Windows based systems with these settings. Please see the National Checklist Program (NCP) website for configuration guides related to other Windows Based systems and applications.

The draft download packages contain recommended security settings; they are not meant to replace well-structured policy or sound judgment. Furthermore, these recommendations do not address site-specific configuration issues. Care must be taken when implementing these settings to address local operational and policy concerns.

These recommendations were developed at the National Institute of Standards and Technology, which collaborated with DoD and Microsoft to produce the Windows 7, Windows 7 Firewall, Internet Explorer 8 USGCB. Pursuant to title 17 Section 105 of the United States Code, these recommendations are not subject to copyright protection and are in the public domain. NIST assumes no responsibility whatsoever for their use by other parties, and makes no guarantees, expressed or implied, about their quality, reliability, or any other characteristic. We would appreciate acknowledgement if the recommendations are used.


Download Packages

The following table provides the downloads for the Windows Vista Firewall USGCB Content. VHDs are also available to use for testing. Additional information can be found in the FAQ.

Documentation GPOs SCAP Content CCE to 800-53 Mappings
  • USGCB Major Version 1.2.x.0 Settings
    Please refer to the top-level Microsoft Content Page for the listing of all USGCB settings and associated hash values.
  • USGCB Major Version 1.2.x.0 Known Issues
    Please refer to the top-level Microsoft Content Page for the listing of all known issues relating to USGCB content and associated hash values.
  • USGCB Windows Vista Firewall GPOs - 2011.11.10
    sha1
    4AD900F2262C692299439251E4116EEA46D7347E
    sha256
    F524E9E1455426757F9A56A0B7805E538E1DD45805144903F49DEB2A99913375
  • SCAP 1.2 (Oval 5.10)

    Windows Vista Firewall Content - 2012.11.28
    sha1
    A9CB70EE50D80BD40402D2F65686CCB77484F9F5
    sha256
    858DA9DC1D5E7D1E23B14E50BBF81F9F82A08611457566525AB8922FA4D84B6E
  • SCAP 1.0 (Oval 5.4)

    Windows Vista Firewall Content - 2012.05.21
    sha1
    3ECC8E3C3AB128BCD17EB025182C07FA0B7553FF
    sha256
    B69C056670E573F38E7BA722BE3380746FBCF0856DF07D67072991B4418F30AC
  • SCAP 1.0 (Oval 5.3)

    Windows Vista Firewall Content - 2012.05.21
    sha1
    AFAF5F2B1ECEB11B17519D4C723B78548D3A2953
    sha256
    8F66645324C1E8A33CE8F130E8BE6383F4B592724122A00393672887F7646744

Update History
Date Documentation GPOs SCAP Content CCE to 800-53 Mappings
November 28, 2012 No changes No changes SCAP 1.2 (Oval 5.10) content signature updated; no other change to content. No changes
May 21, 2012 No changes No changes Content bundle repackaged, no content changes. No changes
April 23, 2012 No changes No changes Content bundle repackaged, no content changes. No changes
March 22, 2012 No changes No changes Content bundle repackaged, no content changes. No changes
November 14, 2011 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
November 10, 2011 No changes USGCB GPOs posted No changes No changes
October 17, 2011 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
October 05, 2011 No changes No changes No changes National Checklist Program's Machine-readable CCE to 800-53 Mappings linked
September 21, 2011 USGCB major version 1.2.x.0 Settings and Known Issues posted No changes USGCB major version 2.0.x.0-Alpha-Candidate SCAP content posted No changes