18.9.81.2.1 Ensure 'Configure Default consent' is set to 'Enabled: Always ask before sending data'

Information

This setting allows you to set the default consent handling for error reports.

The recommended state for this setting is: Enabled: Always ask before sending data

Rationale:

Error reports may contain sensitive information and should not be sent to anyone automatically.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Always ask before sending data:

Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Error Reporting\Consent\Configure Default consent

Note: This Group Policy path is provided by the Group Policy template ErrorReporting.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Default Value:

Always ask before sending data. (Windows prompts users for consent to send reports.)

See Also

https://workbench.cisecurity.org/benchmarks/14249

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION

References: 800-53|CA-7, CCE|CCE-34330-1, CSCv7|13.3

Plugin: Windows

Control ID: f4e9519d562c982ca29489b1a5259161a4efd1f7f8fa2d74e9b65f2d9c666b48