1.2.4.2.1.17 Configure 'Deny write access to fixed drives not protected by BitLocker'

Information

This policy setting determines whether BitLocker protection is required for fixed data drives to be writable on a computer.

NOTE: Some queries in this .audit require BitLocker to be enabled in order to function properly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure this setting in a manner that is consistent with security and operational requirements of your organization.

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CSCv6|13.2

Plugin: Windows

Control ID: bbf4e42d24bad44ee71c334b76b6186d02157cdc266ebb932fb94833d4a19186