1.1.1.2.1.12 Set 'Recovery console: Allow floppy copy and access to all drives and all folders' to 'Disabled'

Information

This policy setting makes the Recovery Console SET command available, which allows you to set the following recovery console environment variables: . AllowWildCards. Enables wildcard support for some commands (such as the DEL command). . AllowAllPaths. Allows access to all files and folders on the computer. . AllowRemovableMedia. Allows files to be copied to removable media, such as a floppy disk. . NoCopyPrompt. Does not prompt when overwriting an existing file. An attacker who can cause the system to restart into the Recovery Console could steal sensitive data and leave no audit or access trail.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 0.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Recovery console- Allow floppy copy and access to all drives and all folders

Impact- Users who have started a server through the Recovery Console and logged in with the built-in Administrator account will not be able to copy files and folders to a floppy disk.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CCE|CCE-3676-4, CSCv6|3.1

Plugin: Windows

Control ID: 036cfcbb4a62caa99c3a0d29447edd01634aa8505bc0d217ae63e992770f1115