18.10.15.7 (L1) Ensure 'Limit Dump Collection' is set to 'Enabled'

Information

This policy setting limits the type of memory dumps that can be collected when more information is needed to troubleshoot a problem.

The recommended state for this setting is: Enabled

Note: Memory dumps are only sent when the device has been configured to send optional diagnostic data. Diagnostic data is limited when recommendation Allow Diagnostic Data is set to Enabled: Diagnostic data off (not recommended) or Enabled: Send required diagnostic data to send only basic information.

Memory dumps can contain sensitive information. Sending this data to a third-party vendor is a security concern and should only be done on an as-needed basis.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled

Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Limit Dump Collection

Note: This Group Policy path is provided by the Group Policy template DataCollection.admx/adml that is included with the Microsoft Windows 11 Release 21H2 Administrative Templates (or newer).

Impact:

Windows Error Reporting is limited to sending kernel mini and user mode triage memory dumps, reducing the risk of sending sensitive information to Microsoft.

See Also

https://workbench.cisecurity.org/benchmarks/16514

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2

Plugin: Windows

Control ID: 8e59029285d05ae3580e86e8446f5193eedd4c813267ef8b55be3139b2e765b6