4.11.7.6 (BL) Ensure 'Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later): Select the encryption method for removable data drives' is set to 'XTS-AES 128-bit' or higher

Information

This policy setting determines which encryption method should be used for operating system drives.

The recommended state for this setting is: XTS-AES 128-bit or XTS-AES 256-bit

The default value of AES-CBC 128-bit is used for backwards compatibility with other operating systems. Using the other available ciphers will increase the level of security for sensitive data, but it may impact compatibility with other operating systems.

This setting is included in the benchmark because it is automatically added when 'Choose drive encryption method and cipher strength' is enabled. System administrators should use the most secure cipher available to them whenever possible.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to: XTS-AES 128-bit or XTS-AES 256-bit

Administrative Templates\Windows Components\BitLocker Drive Encryption\Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)\Select the encryption method for removable data drives:

Impact:

Using settings beyond the default value of AES-CBC 128-bit may decrease the backwards compatibility of encrypted removable drives when used in other systems.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CSCv7|13.6

Plugin: Windows

Control ID: 36e2ba1ca35c3874310a9eecb3a40eb143e86fa10b7672c56030e6fb0b85eede