1.2.4.2.3.5 Set 'Recovery Password' to 'Do not allow 48-digit recovery password'

Information

This policy setting allows you to control how BitLocker-protected removable data drives are recovered in the absence of the required credentials.

NOTE: Some queries in this .audit require BitLocker to be enabled in order to function properly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Make sure 'Recovery Password' is set to 'Do not allow 48-digit recovery password'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CP-10(6), 800-53|SC-28(1), CSCv6|13.2

Plugin: Windows

Control ID: 1f11bae673f96952f8b9360011820d3d28f32fca911c04348dd71c9274c1f59a