18.9.11.4 Ensure 'Choose drive encryption method and cipher strength' is set to 'Enabled: AES 256-bit'

Information

This policy setting allows you to configure the algorithm and cipher strength used by BitLocker Drive Encryption.

This policy setting is applied when you turn on BitLocker.

Changing the encryption method has no effect if the drive is already encrypted or if encryption is in progress.

Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about the encryption methods available.

This policy is only applicable to computers running Windows 8 through Windows 10 RTM (Release 1507).

The recommended state for this setting is: 'Enabled: AES 256-bit'.

Rationale:

The use of the AES 128-bit encryption method is likely to be strong enough for the majority of applications, but those requiring the highest level of security may find this setting suboptimal.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: AES 256-bit:

Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507])

See Also

https://workbench.cisecurity.org/files/1933

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, 800-53|SC-28, CCE|CCE-32952-4, CSCv6|13.2

Plugin: Windows

Control ID: e53263ba983c25955e9a23d3c10b1527705edc42d4fa36793aa5df4d78b62019