1.2.4.2.2.30 Configure 'Reset platform validation data after BitLocker recovery'

Information

This policy setting controls whether a BitLocker-protected computer that is connected to a trusted wired Local Area Network (LAN) and joined to a domain can create and use Network Key Protectors on TPM-enabled computers to automatically unlock the operating system drive when the computer is started.

NOTE: Some queries in this .audit require BitLocker to be enabled in order to function properly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure this setting in a manner that is consistent with security and operational requirements of your organization.

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CSCv6|13.2

Plugin: Windows

Control ID: ed4765da6ea121323e64273e9d59416c1b68f8f09404b402a13b9ffbc29429cb