4.11.7.5 (BL) Ensure 'Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later): Select the encryption method for operating system drives' is set to 'XTS-AES 128-bit (default)' or 'XTS-AES 256-bit'

Information

This policy setting determines which encryption method should be used for operating system drives.

The recommended state for this setting is: XTS-AES 128-bit (default) or XTS-AES 256-bit

Enforcing the default value of XTS-AES 128-bit (default) or higher helps ensure that a weaker cipher is not used to protect data on operating system drives.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to XTS-AES 128-bit (default) or XTS-AES 256-bit

Administrative Templates\Windows Components\BitLocker Drive Encryption\Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)\Select the encryption method for operating system drives:

Impact:

None - this setting enforces the default value or higher.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CSCv7|13.6

Plugin: Windows

Control ID: 6d1d98c6211961c6f33ef164787c50128271d4a3aed080be14e001834d2a94c1