18.6.24.1.1 Ensure 'Let Windows apps access cellular data' is set to 'Enabled: Force Deny'

Information

This policy setting specifies whether Windows apps can access cellular data.

The recommended state for this setting is: Enabled: Force Deny.

Note: In some instances, cellular data / mobile broadband is used by the EMS Gateway to transfer data in and out of the Election System. In this case, an exception to the policy Let Windows apps access cellular data that either Disables the setting, or chooses the options User is in control or Force Allow is considered in compliance with the benchmark.

Rationale:

The capability to run a cellular connection from a domain-connected computer could expose the internal network to hackers.

Note: In some instances, cellular data / mobile broadband is used by the EMS Gateway to transfer data in and out of the Election System. In this case, an exception to the policy Let Windows apps access cellular data that either Disables the setting, or chooses the options User is in control or Force Allow is considered in compliance with the benchmark.

Impact:

Users will not be able to use cellular data on the system.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Force Deny

Computer Configuration\Policies\Administrative Templates\Network\WWAN Service\Cellular Data Access\Let Windows apps access cellular data

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template wwansvc.admx/adml that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Default Value:

Disabled. (If you disable or do not configure this policy setting, employees in your organization can decide whether Windows apps can access cellular data by using Settings > Network - Internet > Cellular on the device.)

See Also

https://workbench.cisecurity.org/benchmarks/13921

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-18(3)

Plugin: Windows

Control ID: 424852b1c6a424a9a18eede7d665df8683b22372879ded4fb7948e39a95a8508