4.11.7.2.14 (BL) Ensure 'Enforce drive encryption type on operating system drives: Select the encryption type: (Device)' is set to 'Enabled: Used Space Only encryption' or 'Enabled: Full encryption'

Information

This policy setting configures the encryption type (space only and whole) used by BitLocker Drive Encryption.

The recommended state for this setting is: Enabled: Used Space Only encryption or Enabled: Full encryption

Note: Changing the encryption type does not affect drives that are already encrypted or if encryption is in progress.

Note #2: If the option

full encryption

is selected, the entire drive be encrypted. If the option

used space only encryption

is selected, only the portion of the drive used to store data will be encrypted.

The type of encryption (used space only or full) used by BitLocker should be an organizational decision and not an end user decision.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Used Space Only encryption or Full encryption

Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Enforce drive encryption type on operating system drives: Select the encryption type: (Device)

Impact:

An organization will have to choose which method is used when BitLocker is enabled. The end user will not be able to choose the encryption type.

Note: This policy is ignored when shrinking or expanding a volume, and BitLocker uses the current encryption method. Example: When a drive uses

Space Only encryption

and is expanded, the new free space isn't wiped as it is for a drive that uses

Full encryption

.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1)

Plugin: Windows

Control ID: 4e0149ad0d942181acb25d14ecb8f58c871496475fc26d9d4788ecdf342770f7