Vulnerabilities Checklists Product Dictionary Impact Metrics Data Feeds Statistics
Home ISAP/SCAP SCAP Validated Tools SCAP Events About Contact Vendor Comments
FDCC

NIST Resources

Other Resources


 

white space

white space

Federal Desktop Core Configuration
FDCC

- DOWNLOAD PAGE -

WARNING NOTICE

Do not attempt to implement any of the settings without first testing them in a non-operational environment. These recommendations should be applied only to Windows XP Professional SP2 and Vista systems and will not work on Windows 9X/ME, Windows NT, Windows 2000 or Windows Server 2003. The security policies have been tested on Windows XP Professional SP2 and Vista systems with a Windows 2003 server and will not work on Windows 9X/ME, Windows NT, Windows 2000 or Windows Server 2003.

The draft download packages contain recommended security settings; they are not meant to replace well-structured policy or sound judgment. Furthermore, these recommendations do not address site-specific configuration issues. Care must be taken when implementing these settings to address local operational and policy concerns.

These recommendations were developed at the National Institute of Standards and Technology, which collaborated with OMB, DHS, DISA, NSA, USAF, and Microsoft to produce the Windows XP and Vista FDCC baseline. Pursuant to title 17 Section 105 of the United States Code, these recommendations are not subject to copyright protection and are in the public domain. NIST assumes no responsibility whatsoever for their use by other parties, and makes no guarantees, expressed or implied, about their quality, reliability, or any other characteristic. We would appreciate acknowledgement if the recommendations are used.

 

Download Packages

2008.06.20

The updated Federal Desktop Core Configuration settings released on 20 June 2008 constitute Major Version 1.0 of FDCC. Relative to the previous version of FDCC, 40 settings have changed. Changes were derived from public comment during the April and May 2008 public comment periods, analysis of the 31 March 2008 Agency FDCC reports, and subject matter expertise.


FDCC Major Version 1.0 is based on Microsoft Windows XP Service Pack (SP) 2 and Microsoft Windows Vista SP 1. Although SCAP content has been engineered so that it will also operate on Windows XP SP3, near-term Windows XP patch checking will be oriented toward Windows XP SP2.


To coincide with the release of FDCC Major Version 1.0, new SCAP Content has also been made available. This SCAP Content is inclusive of the 40 FDCC settings changes. At this time, FDCC is comprised of 674 settings, 670 of which (99.4%) can be checked using the updated SCAP Content and an SCAP-Validated Tool. A listing of non-automated settings is available for your reference. NIST is coordinating future refinement of SCAP Content and expects to release minor versions of SCAP Content in the future as non-automated checks are automated.


New Microsoft-updated Group Policy Objects (GPO) and Virtual Hard Drive (VHD) files are also available. These files have been tested by NIST and made available through this Web page. These GPOs and VHDs are inclusive of the 40 FDCC settings changes. At this time, 625 out of 674 settings (92.7%) are embodied in GPOs and can therefore be centrally implemented via Microsoft Active Directory servers. A listing of settings that cannot be implemented via GPO is available for your reference.


Moving forward, we anticipate relatively few and infrequent changes to FDCC settings. The change control process is being actively discussed and documented as of 20 June 2008. The change control process will balance a number of factors, including but not limited to IT Provider feedback and existing SCAP Validation Program processes. The Office of Management and Budget will release more information about this process in the upcoming weeks.


2007.08.20
Please read the Download FAQs to resolve issues with downloading, logging on, and activating Windows Vista.

 

Documentation

GPOs

SCAP Content

2008.06.20
FDCC Settings major
version 1.0
- Final [xls, 456K]

SHA-1 Digest:
06D8087A0CF572F
368B4DAB5CD15B4
69029A52DC

SHA-256 Digest:
42AA5F3849D21E
54C8FF3187E46E
5D9EA7EC17E9D7
F2539FBF30D510
DE06E229

2008.06.20
FDCC 2008 Q3 GPO Release -Final [zip, ~3 MB]

SHA-1 Digest:
831F0755E3771
C4C47FC7B8847
D8AF2200DBB6AA

SHA-256 Digest:
B73D3A40CBEE922B77
3B038A8D00D839DC1A8
38A8D22109F35F80AB7
1D85FC09

Known Issues

2008.06.20
Windows XP, Vista, firewall, and IE 7. - Final [zip, ~460K]

SHA-1 Digest:
9E95E65D0623E8825A4
54EEF2FD01D9FD416
8266

SHA-256 Digest:
0511913B44E9522A693AF
0777FB37DB29C070B109EA
649D6A00B6B2423E6B87D

Known Issues


The preceding files are intended for use with "SCAP FDCC scanning capable" tools.

 

2008.06.20
FDCC Settings Changes
major version 1.0
- [xls, 25K]

SHA-1 Digest:
1B2C6FD06D78F31AA08E
29DFED887BE4E56D80F8

SHA-256 Digest:
2B8D404730A192E2B55D
44DC86773CE1D7E4B5433
FA4508AC87438F6A3FE997D

   


VHD Files

SHA-1 Digest

SHA-256 Digest

Note

Windows XP FDCC VHD Release 1.0 - Part 1 of 7 - Final [zip, ~178MB] C60D32A19D33785
7FCB72CCBC0246D
E2AC107FBE
3227AD7C4BA5B0069B
5840DC840B03399C9B
9F57AD38A76D1B3EAA
886AC8B462

2008.06.20
2008 Q3 VHD released


NOTE:
Download the six files. Use WinZip to open the archive and extract the .VHD and .VMC files.

Please read the Download FAQs.

Windows XP FDCC VHD Release 1.0 - Part 2 of 7 - Final [zip, ~648MB] 6BAC158A308DBE2E
802A4CE46D28A06A
B8D58286

D209D32EBEE50F9972
F3E2087BE1499C02B9
6E90F3B30FAD2C5F7D
448E94D147
Windows XP FDCC VHD Release 1.0 - Part 3 of 7 - Final [zip, ~648MB] 79FBBCF79078DC1397B
04FF660E435B7429A
61AA
EFFBFBE52F762B2BFEC
A957D2FB7F24F07F485
51604E7BD4A2283E9FA
C8D87CD
Windows XP FDCC VHD Release 1.0 - Part 4 of 7 - Final [zip, ~648MB] B25F1BE1FE4F103F3
72C6BB98C23ADCD123
BB8D0
12AD5620BD34D78B5
30DD9514D6C0B376E
A0191E84C73E871D4
51B509EBF7075
Windows XP FDCC VHD Release 1.0 - Part 5 of 7 - Final [zip, ~648MB] 5E57C7C5CFFCD0D80
88F3266851E7382D0
41E6B0
382EAB45586828D9CD
F9D8F46F127DEC6EAD
9EF4F7294397DB463
126D53AF4ED
Windows XP FDCC VHD Release 1.0 - Part 6 of 7 - Final [zip, ~648MB] EDF00190DF6CD57FA
0A8FF6DDE9D331F3A7
63AE3
e665593f2e12b32524b1
2E641EA8DC167774969
EE2B02A1BB51CAF6688
35EDC924C3123424F98
3B6F192
Windows XP FDCC VHD Release 1.1 - Part 7 of 7 - Final [zip, ~648MB] 70E8A589560B5AC22
AACDFC8650D27C3218
25B3D
e665593f2e12b32524b1
14329794B9ABCB544C
296DAFA9ADE615999D
17D67107454C3F7B2B
65672F247C
Windows Vista FDCC VHD Release 1.0 - Part 1 of 7 - Final [zip, ~340MB] 363677248A9FC7F3
31C16FDD504352F2
7DBF6DBA
34DE8D3793C30E778
205F934B8E2FF96D325
A8FFECC0F41A430E951
2C19C6EF5
2008.06.20
2008 Q3 VHD released -
7 files for this release



NOTE:
Download the 7 files. Use WinZip to open the archive and extract the .vhd and .vmc files.

Please read the Download FAQs.

Windows Vista FDCC VHD Release 1.0 - Part 2 of 7 - Final [zip, ~648MB] 487FDBF021ADA54220
9474E34166880AF0C
74D70
EE93C0C68EC33F2A374
8382930D29476A11B37
065FFB8DD5E38234618
A7BD843
Windows Vista FDCC VHD Release 1.0 - Part 3 of 7 - Final [zip, ~648MB] 0A154D9E74FDD4A369
2579F5314E4D60F0361
4F8
05F583431AD1F8BFCDBE8
571FB687DF4A802CD7CB
C7739382A53A5FD19A4
1246
Windows Vista FDCC VHD Release 1.0 - Part 4 of 7 - Final [zip, ~648MB] 9F635768858F87F
FDADDCCE05DD89C
B899287D78
DCC3326C6F37FB5B24D
1F839C68A4C460A9547
5243D65B66F23ED8ECE
8DABC07
Windows Vista FDCC VHD Release 1.0 - Part 5 of 7 - Final [zip, ~648MB] 53B704194FF310A662
86600DFECC73C780F
7F3AC
5255340FA42F1A7D18
44B3DF1532EE29E43F
351BFD2A09A1EBBDB9
571DB4B337
Windows Vista FDCC VHD Release 1.0 - Part 6 of 7 - Final [zip, ~648MB] 06754692ED201FB5B
6EC8DF57F0D3BE479
5EB1AC
ACB964589CF287813
D45226AC8BD9AE698
606DB25F0822ED683
1136C5BF93C85
Windows Vista FDCC VHD Release 1.0 - Part 7 of 7 - Final [zip, ~648MB] 32C6A0BAC2F2E71C2
9DA1DD7F20DD51FE5
365B97
8A8491FEEEDEFC07A70
94A9E6B5C27D2424D5D
E15923EA0E6DAF36C32
CD4715C

 

Updates History

Documentation

GPO Files

VHD Files

SCAP Content

2008.06.20
FDCC Settings major version 1.0

FDCC Settings Chananges major version 1.0
2008.06.20
2008 Q3 GPOs Released
2008.06.20
2008 Q3 VHDs Released
2008.06.20
Release 1.0 - Final

Please see the FDCC Archive for pre-final release content

 

Comments and Questions

Comments and questions may be addressed to fdcc@nist.gov.

 

 

 

 


Last updated: June, 20, 2008
Page created: July 22, 2007

Disclaimer Notice & Privacy Statement / Security Notice
Send comments or suggestions to itsec@nist.gov
NIST is an Agency of the U.S. Commerce Department's Technology Administration