1.2.3.2.1 Configure 'Configure Automatic Updates'

Information

This policy setting specifies whether computers in your environment will receive security updates from Windows Update or WSUS. If you configure this policy setting to Enabled, the operating system will recognize when a network connection is available and then use the network connection to search Windows Update or your designated intranet site for updates that apply to them. After you configure this policy setting to Enabled, select one of the following three options in the Configure Automatic Updates Properties dialog box to specify how the service will work: . Notify before downloading any updates and notify again before installing them. . Download the updates automatically and notify when they are ready to be installed. (Default setting) . Automatically download updates and install them on the schedule specified below. If you disable this policy setting, you will need to download and manually install any available updates from Windows Update. Although each version of Windows is thoroughly tested before release, it is possible that problems will be discovered after the products are shipped. The Configure Automatic Updates setting can help you ensure that the computers in your environment will always have the most recent critical operating system updates and service packs installed.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Windows Components\Windows Update\Configure Automatic Updates

Impact- Critical operating system updates and service packs will automatically download and install at 3-00 A.M. daily.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(5), CCE|CCE-3740-8

Plugin: Windows

Control ID: 34d19ffe10478a79a675e6a03d0297a7be7fe5d47141e7a743b75d8ef409c7ee