3.048 - The Recovery Console SET command must be disabled.

Information

The Recovery Console SET command allows environment variables to be set in the Recovery Console. This permits access to all drives and folders and the copying of files to removable media which could expose sensitive information.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Recovery Console- Allow floppy copy and access to all drives and all folders' to 'Disabled'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-29019r2_rule, STIG-ID|3.048, Vuln-ID|V-1158

Plugin: Windows

Control ID: f7cea3ad133253fcd0aa0c6bb5492feec7bea56c2a854dc6232ea0a6180051e7