18.9.81.2.1 Ensure 'Configure Default consent' is set to 'Enabled: Always ask before sending data'

Information

This setting allows you to set the default consent handling for error reports.

The recommended state for this setting is: Enabled: Always ask before sending data

Rationale:

Error reports may contain sensitive information and should not be sent to anyone automatically.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Always ask before sending data:

Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Error Reporting\Consent\Configure Default consent

Note: This Group Policy path is provided by the Group Policy template ErrorReporting.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

None - this is the default behavior.

Default Value:

Always ask before sending data. (Windows prompts users for consent to send reports.)

References:

CCE-37112-0

See Also

https://workbench.cisecurity.org/files/2746

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), CSCv6|13, CSCv7|13.3

Plugin: Windows

Control ID: c677e6d8f3225718af1ca0910b06735d728fd9d34dff8463add6cacd1695f63f