1.2.4.2.5 Set 'Select the encryption method:' to 'Enabled:AES 256-bit'

Information

This policy setting allows you to configure the algorithm and cipher strength used by BitLocker Drive Encryption.

NOTE: Some queries in this .audit require BitLocker to be enabled in order to function properly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Make sure 'Select the encryption method:' is set to 'Enabled:AES 256-bit'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CSCv6|13.2

Plugin: Windows

Control ID: 44c3a04eea6c117583642c0130cac809554e33e792bc1cbb3122ff1a43a328ac