1.2.4.2.3.20 Set 'Do not allow write access to devices configured in another organization' to 'True'

Information

This policy setting configures whether BitLocker protection is required for a computer to be able to write data to a removable data drive.

NOTE: Some queries in this .audit require BitLocker to be enabled in order to function properly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Make sure 'Do not allow write access to devices configured in another organization' is set to 'True'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|MP-4, 800-53|SC-28(1), CSCv6|13.2, CSCv6|13.5

Plugin: Windows

Control ID: c51be8a5b9219725c0c9457a24630ae47942bc0d7462d52e2259b513627bdb08