National Institute of Standards and Technology (NIST) - Information technology Laboratory (ITL)

The United States Government Configuration Baseline (USGCB) - Windows XP Content

Warning Notice

Do not attempt to implement any of the settings without first testing them in a non-operational environment. These recommendations have only been tested on Windows 7 Ultimate 32-bit, Windows 7 Ultimate 64-bit, Windows 7 Enterprise x86, and Windows 7 Enterprise x64. These settings may be applicable to other Windows systems and service packs; however, NIST has not tested other Windows based systems with these settings. Please see the National Checklist Program (NCP) website for configuration guides related to other Windows Based systems and applications.

The draft download packages contain recommended security settings; they are not meant to replace well-structured policy or sound judgment. Furthermore, these recommendations do not address site-specific configuration issues. Care must be taken when implementing these settings to address local operational and policy concerns.

These recommendations were developed at the National Institute of Standards and Technology, which collaborated with DoD and Microsoft to produce the Windows 7, Windows 7 Firewall, Internet Explorer 8 USGCB. Pursuant to title 17 Section 105 of the United States Code, these recommendations are not subject to copyright protection and are in the public domain. NIST assumes no responsibility whatsoever for their use by other parties, and makes no guarantees, expressed or implied, about their quality, reliability, or any other characteristic. We would appreciate acknowledgement if the recommendations are used.


Download Packages

The following table provides the downloads for the Windows XP USGCB Content. VHDs are also available to use for testing. Additional information can be found in the FAQ.

Documentation GPOs SCAP Content CCE to 800-53 Mappings
  • USGCB Major Version 1.2.x.0 Settings
    Please refer to the top-level Microsoft Content Page for the listing of all USGCB settings and associated hash values.
  • USGCB Major Version 1.2.x.0 Known Issues
    Please refer to the top-level Microsoft Content Page for the listing of all known issues relating to USGCB content and associated hash values.
  • USGCB/FDCC Comparison for Windows - 2010.11.09
    sha1
    6920E757F12E00ED58E39E27FCB2F79B35BBFF8F
    sha256
    7659F2007E3A0286EBCC344885F68540A4B93849628A0603382F28AE74110E18
  • USGCB Windows XP GPOs - 2011.11.10
    sha1
    F0563E0A1FE41BC53F4807B6EBB9B6BF3C64E612
    sha256
    111467E5A61F1DF7D69A9E3D6DB90E6D03224F1A5D48D8A59A911FEC6EEAB80D
  • SCAP 1.2 (Oval 5.10)

    Windows XP Content - 2012.11.28
    sha1
    2FA6C918553F19610B6332867C66D7FC3345EA11
    sha256
    6AC76BA2870EA02D5743482C4C97A5EEC63EAA7B8B1D8FCFF9F3C7D02690EA97
  • SCAP 1.0 (Oval 5.4)

    Windows XP Content - 2013.04.29
    sha1
    153DC49CB302213DA838B85B5609E5354194D442
    sha256
    AABB0A774FBA73B16A01A836B73C5FF210E1E2FB59043B48AE50120A7EB41714
  • SCAP 1.0 (Oval 5.3)

    Windows XP Content - 2013.04.29
    sha1
    2366CD2B82E3388FA9B6B689F7820394076420F1
    sha256
    E48DAB450F832E3C0C583562F789A84914E8C3BB9E11BCD44979A2B36D1D3FAA
  • Windows XP SCAP Patch Content - 2013.04.29
    sha1
    8BE6CD61955EE7429C9AC254C6A1CFC473AEF2CA
    sha256
    CA2B505F08529103CB4D638A0E9C4E0468C2EFAF9CD0C4E343685C55793294DE

Update History
Date Documentation GPOs SCAP Content CCE to 800-53 Mappings
April 29, 2013 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
March 21, 2013 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
February 25, 2013 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
January 22, 2013 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
December 28, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
December 05, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
November 28, 2012 No changes No changes SCAP 1.2 (Oval 5.10) content signature updated; no other change to content. No changes
October 31, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
August 17, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
July 30, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
June 15, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. No changes
May 21, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted. SCAP 1.2 (Oval 5.10) content signature updated; no change to content No changes
April 23, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
March 22, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
February 23, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
January 23, 2012 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
November 14, 2011 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
November 10, 2011 No changes USGCB GPOs posted No changes No changes
October 26, 2011 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
October 17, 2011 No changes No changes USGCB major version 2.0.x.0 SCAP content posted No changes
October 05, 2011 No changes No changes No changes National Checklist Program's Machine-readable CCE to 800-53 Mappings linked
September 21, 2011 USGCB major version 1.2.x.0 Settings and Known Issues posted No changes USGCB major version 2.0.x.0-Alpha-Candidate SCAP content posted No changes