18.9.11.4 Ensure 'Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)

Information

18.9.11.4 Ensure 'Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)' is set to 'Enabled: AES 256-bit with Diffuser'

This policy setting allows you to configure the algorithm and cipher strength used by BitLocker Drive Encryption.

This policy setting is applied when you turn on BitLocker.

Changing the encryption method has no effect if the drive is already encrypted or if encryption is in progress.

Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about the encryption methods available.

This policy is only applicable to computers running Windows Vista or Windows 7.

The recommended state for this setting is: 'Enabled: AES 256-bit with Diffuser'.

Rationale:
The use of the AES 128-bit encryption method is likely to be strong enough for the majority of applications, but those requiring the highest level of security may find this setting suboptimal.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled: AES 256-bit with Diffuser':


Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)


Note: This Group Policy path may not exist by default.

It is provided by the Group Policy template 'VolumeEncryption.admx/adml' that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Impact:
Using AES 256-bit with Diffuser will not significantly impact initial encryption speed and overall computer performance in most cases.

See Also

https://workbench.cisecurity.org/files/1929

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, 800-53|SC-28(1), CSCv6|13.2

Plugin: Windows

Control ID: 9aaa19a4ad52f34d32bdbde836a73687cfbaad912d95a88ff74483eb2411527c