1.1.1.2.1.11 Set 'Devices: Unsigned driver installation behavior' to 'Warn but allow installation'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting determines what happens when an attempt is made to install a device driver (by means of Setup API) that has not been approved and signed by the Windows Hardware Quality Lab (WHQL). Depending on how you configure it, this policy setting will prevent the installation of unsigned drivers or warn the administrator that an unsigned driver is about to be installed. The Devices: Unsigned driver installation behavior setting can be used to prevent the installation of drivers that have not been certified to run on Windows Server 2003 with SP1. One potential problem with this configuration is that unattended installation scripts will fail when they attempt to install unsigned drivers. This policy setting will not prevent a method that is used by some attack tools in which malicious .sys files are copied and registered to start as system services.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 01.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Devices- Unsigned driver installation behavior

Impact- Users with sufficient privileges to install device drivers will be able to install unsigned device drivers. However, this capability could result in stability problems for servers. Another potential problem with a Warn but allow installation configuration is that unattended installation scripts will fail if they attempt to install unsigned drivers.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5(3), CCE|CCE-3787-9

Plugin: Windows

Control ID: 4ce21e9d63c604d807d6bec4f1862d3da4a3d29c009859651574f7244cca42db