1.1.1.2.1.19 Set 'Shutdown: Clear virtual memory pagefile' to 'Disabled'

Information

This policy setting determines whether the virtual memory pagefile is cleared when the system is shut down. When this policy setting is enabled, the system pagefile is cleared each time that the system shuts down properly. If you enable this security setting, the hibernation file (Hiberfil.sys) is zeroed out when hibernation is disabled on a portable computer system. It will take longer to shut down and restart the computer, and will be especially noticeable on computers with large paging files. Important information that is kept in real memory may be written periodically to the page file to help Windows handle multitasking functions. An attacker who has physical access to a server that has been shut down could view the contents of the paging file. The attacker could move the system volume into a different computer and then analyze the contents of the paging file. Although this process is time consuming, it could expose data that is cached from random access memory (RAM) to the paging file. Caution: An attacker who has physical access to the server could bypass this countermeasure by simply unplugging the server from its power source.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 0.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Shutdown- Clear virtual memory pagefile

Impact- It will take longer to shut down and restart the server, especially on servers with large paging files. For a server with 2 gigabytes (GB) of RAM and a 2-GB paging file, this policy setting could increase the shutdown process by 20 to 30 minutes, or more. For some organizations, this downtime violates their internal service level agreements. Therefore, use caution before you implement this countermeasure in your environment.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CCE|CCE-3593-1, CSCv6|3.1

Plugin: Windows

Control ID: 05e368c5d371efaa3b2bea19a904e8aa105d60a1a7ae2d0fd0da5e0f05544a7d