1.2.4.2.2.27 Set 'Allow Secure Boot for integrity validation' to 'Enabled'

Information

This policy setting allows you to configure whether Secure Boot will be allowed as the platform integrity provider for BitLocker operating system drives.

NOTE: Some queries in this .audit require BitLocker to be enabled in order to function properly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Make sure 'Allow Secure Boot for integrity validation' is set to 'Enabled'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-3, CSCv6|13.2

Plugin: Windows

Control ID: 147a2dbb148fc2bb1b4ff6c9d87731aefdc95320fad19eb8f410e4fbaa923a02