5.30 Ensure 'Windows CardSpace (idsvc)' is set to 'Disabled' or 'Not Installed'

Information

Securely enables the creation, management, and disclosure of digital identities.

The recommended state for this setting is: Disabled or Not Installed.

Rationale:

Windows CardSpace was the client software for Microsoft's digital identity metasystem that has been discontinued. There were some security risks in the CardSpace protocol and therefore this service should simply be disabled.

Solution

To establish the recommended configuration via GP, set the following UI path to: Disabled or ensure the service is not installed.

Computer Configuration\Policies\Windows Settings\Security Settings\System Services\Windows CardSpace

Impact:

Windows CardSpace functions will not be available.

Default Value:

Manual

See Also

https://workbench.cisecurity.org/files/2700

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 0ae4b642be10a60e3b22c3767f7f4860d72ae815a245ba71e827f2c41ff2ee26