1.2.4.2.3.17 Set 'Deny write access to removable drives not protected by BitLocker' to 'Enabled'

Information

This policy setting specifies whether a password is required to unlock BitLocker-protected removable data drives.

NOTE: Some queries in this .audit require BitLocker to be enabled in order to function properly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Make sure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|MP-4, 800-53|SC-28(1), CSCv6|13.2, CSCv6|13.5

Plugin: Windows

Control ID: e86e1dc60e7e195f47f329bbe75f5f4c67ed35ccbe0e505d078cb0497946e624