5.6 Ensure 'Internet Connection Sharing (ICS) (SharedAccess) ' is set to 'Disabled'

Information

Provides network access translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.

The recommended state for this setting is: 'Disabled'.

Rationale:
Internet Connection Sharing (ICS) is a feature that allows someone to 'share' their Internet connection with other machines on the network - it was designed for home or small office environments where only one machine has Internet access - it effectively turns that machine into an Internet router.

This feature causes the bridging of networks and likely bypassing other, more secure pathways.

It should not be used on any enterprise-managed system.

Solution

To establish the recommended configuration via GP, set the following UI path to: 'Disabled'.


Computer Configuration\Policies\Windows Settings\Security Settings\System Services\Internet Connection Sharing (ICS)


Impact:
Internet Connection Sharing (ICS) will not be available.

Wireless connections using Miracast will also be prevented.

See Also

https://workbench.cisecurity.org/files/1929

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 41e6f8c9892d9d389d488555ec195ee4c8ed684a612cad8d89df5aa5870658a4