4.11.7.4 (BL) Ensure 'Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later): Select the encryption method for fixed data drives' is set to 'XTS-AES 128-bit (default)' or 'XTS-AES 256-bit'

Information

This policy setting determines which encryption method should be used for fixed data drives.

The recommended state for this setting is: XTS-AES 128-bit (default) or XTS-AES 256-bit

Enforcing the default value of XTS-AES 128-bit (default) or higher helps ensure that a weaker cipher is not used to protect data on fixed data drives.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to XTS-AES 128-bit (default) or XTS-AES 256-bit

Administrative Templates\Windows Components\BitLocker Drive Encryption\Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)\Select the encryption method for fixed data drives

Impact:

None - this setting enforces the default value or higher.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CSCv7|13.6

Plugin: Windows

Control ID: 3f603fe2b64d75501bb0713a5b4b7261f91aea1d4f61ad9370b160a2b8e0c1b7