1.1.1.2.1.23 Configure 'Devices: Restrict CD-ROM access to locally logged-on user only'

Information

This policy setting determines whether a CD-ROM is accessible to both local and remote users simultaneously. If you enable this policy setting, only the interactively logged-on user is allowed to access removable CD-ROM media. When this policy setting is enabled and no one is logged on interactively, the CD-ROM is accessible over the network. A remote user could potentially access a mounted CD that contains sensitive information. This risk is small, because CD drives are not automatically made available as shared drives; administrators must deliberately choose to share the drive. However, administrators may wish to deny network users the ability to view data or run applications from removable media on the server.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Devices- Restrict CD-ROM access to locally logged-on user only

Impact- Users who connect to the server over the network will not be able to use any CD drives that are installed on the server whenever anyone is logged on to the local console of the server. System tools that require access to the CD drive will fail. For example, the Volume Shadow Copy service attempts to access all CD and floppy disk drives that are present on the computer when it initializes, and if the service cannot access one of these drives, it will fail. This condition will cause the Windows Backup tool to fail if volume shadow copies were specified for the backup job. Any non-Microsoft backup products that use volume shadow copies will also fail. This policy setting would not be suitable for a computer that serves as a CD jukebox for network users.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-2, CCE|CCE-3694-7, CSCv6|8.3

Plugin: Windows

Control ID: 4c7eae1cfbbf286de103901d4441f0bb49e977a0ba722f05cb60e8b6a76bf202