18.9.108.1.4 Ensure 'Reschedule Automatic Updates scheduled installations' is set to 'Enabled: 1 minute'

Information

This policy setting specifies the amount of time for Automatic Updates to wait, following system startup, before proceeding with a scheduled installation that was missed previously.

The recommended state for this setting is: Enabled: 1 minute.

Rationale:

Rescheduling Automatic Updates that were not installed on schedule will help ensure security patches get installed. By scheduling these missed updates to install quickly after starting up Windows, it will help to reduce the amount of productivity impact on users, as they would not likely have gotten very far into their workload.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 1 minute:

Computer Configuration\Administrative Templates\Windows Components\Windows Update\Legacy Policies\Reschedule Automatic Updates scheduled installations

Note: This Group Policy path is provided by the Group Policy template WindowsUpdate.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Default Value:

Enabled: 1 minute. (A missed scheduled installation will occur one minute after the computer is next started.)

See Also

https://workbench.cisecurity.org/files/4022

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Windows

Control ID: 067f927e8a9e8ac35a899dee94a3c881025d38fa84b13d41939f8195ab49e690