1.106 WN22-CC-000130

Information

Windows Server 2022 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad.

GROUP ID: V-254344
RULE ID: SV-254344r991589

Compromised boot drivers can introduce malware prior to protection mechanisms that load after initialization. The Early Launch Antimalware driver can limit allowed drivers based on classifications determined by the malware protection application. At a minimum, drivers determined to be bad must not be allowed.

Solution

The default behavior is for Early Launch Antimalware - Boot-Start Driver Initialization policy to enforce 'Good, unknown and bad but critical' (preventing 'bad').

If this needs to be corrected or a more secure setting is desired, configure the policy value for

Computer Configuration >> Administrative Templates >> System >> Early Launch Antimalware >> Boot-Start Driver Initialization Policy to 'Not Configured' or 'Enabled' with any option other than 'All' selected

See Also

https://workbench.cisecurity.org/benchmarks/22357

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-254344r991589_rule, STIG-ID|WN22-CC-000130, Vuln-ID|V-254344

Plugin: Windows

Control ID: 70dfb0e020c1ef93cf24914808aa2a0a21b96575a640d97664cfb05e1b963bc5