WN12-CC-000024 - Device driver searches using Windows Update must be prevented.

Information

Some features may communicate with the vendor, sending system information or downloading data or components for the feature. Turning off this capability will prevent potentially sensitive information from being sent outside the enterprise and uncontrolled updates to the system.
This setting will prevent the system from searching Windows Update for device drivers.

Solution

Configure the policy value for Computer Configuration -> Administrative Templates -> System -> Device Installation -> 'Specify search order for device driver source locations' to 'Enabled: Do not search Windows Update'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-11(2), CAT|III, CCI|CCI-001812, Rule-ID|SV-225334r852202_rule, STIG-ID|WN12-CC-000024, STIG-Legacy|SV-53186, STIG-Legacy|V-21965, Vuln-ID|V-225334

Plugin: Windows

Control ID: 37e5a6902d2a8b09d6d8f2ad6c9da90686089aeb27c673379a166115f6a031aa