18.9.11.3.12 Ensure 'Configure use of smart cards on removable data drives' is set to 'Enabled'

Information

This policy setting specifies whether smart cards can be used to authenticate user access to BitLocker-protected removable data drives on a computer.

Smart cards can be used to authenticate user access to the drive. You can require smart card authentication by selecting the 'Require use of smart cards on removable data drives' check box.

Note: This setting is enforced when turning on BitLocker, not when unlocking a volume. BitLocker will allow unlocking a drive with any of the protectors available on the drive.

The recommended state for this setting is: Enabled.

Rationale:

A drive can be compromised by guessing or finding the authentication information used to access the drive. For example, a password could be guessed, or a drive set to automatically unlock could be lost or stolen with the computer it automatically unlocks with.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of smart cards on removable data drives

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template VolumeEncryption.admx/adml that is included with the Microsoft Windows 7 & Server 2008 R2 Administrative Templates (or newer).

Default Value:

Enabled. (Users are allowed to use smart cards to authenticate their access to BitLocker-protected removable data drives.)

See Also

https://workbench.cisecurity.org/files/3719

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), 800-53|IA-2(2), CSCv7|16.3

Plugin: Windows

Control ID: 8df7546ac64046249c60b6b3648c4cb121fb3b32cb0acf61f6901c57d3ab8735