4.11.7.5 Ensure 'Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later): Select the encryption method for operating system drives' is set to 'XTS-AES 128-bit (default)' or 'XTS-AES 256-bit'

Information

This policy setting determines which encryption method should be used for operating system drives.

The recommended state for this setting is: XTS-AES 128-bit (default) or XTS-AES 256-bit

Enforcing the default value of XTS-AES 128-bit (default) or higher helps ensure that a weaker cipher is not used to protect data on operating system drives.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to XTS-AES 128-bit (default) or XTS-AES 256-bit.

Administrative Templates\Windows Components\BitLocker Drive Encryption\Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)\Select the encryption method for operating system drives:

Impact:

None - this setting enforces the default value or higher.

See Also

https://workbench.cisecurity.org/benchmarks/27291

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CSCv7|13.6

Plugin: Windows

Control ID: d9edb2a924ed6ab3f27558a142e8ec5c04e4d3173bd07c215061fd67dba3fbba