4.11.7.5 (BL) Ensure 'Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later): Select the encryption method for operating system drives' is set to 'XTS-AES 128-bit (default)' or 'XTS-AES 256-bit'

Information

This policy setting determines which encryption method should be used for operating system drives.

The recommended state for this setting is: XTS-AES 128-bit (default) or XTS-AES 256-bit

Enforcing the default value of XTS-AES 128-bit (default) or higher helps ensure that a weaker cipher is not used to protect data on operating system drives.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to XTS-AES 128-bit (default) or XTS-AES 256-bit

Administrative Templates\Windows Components\BitLocker Drive Encryption\Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)\Select the encryption method for operating system drives:

Impact:

None - this setting enforces the default value or higher.

See Also

https://workbench.cisecurity.org/benchmarks/21767

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CSCv7|13.6

Plugin: Windows

Control ID: ce7c67f4cf849811151557a0b69d3345e4c2efdd08dc7e6970bb2c6977251b62