1.2.4.2.2.9 Set 'Allow data recovery agent' to 'False'

Information

This policy setting allows you to control how BitLocker-protected operating system drives are recovered in the absence
of the required startup key information.

Solution

Make sure 'Allow data recovery agent' is set to 'False'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CP-10(6), 800-53|SC-28(1), CSCv6|10.3, CSCv6|13.2

Plugin: Windows

Control ID: a147bba54d6e1a07ac135c6c95e1f85e4c4c6a988c5c7f1bbb0a67ed9191728f