67.5 (L1) Ensure 'Limit Diagnostic Log Collection' is set to 'Enabled'

Information

This policy setting controls whether additional diagnostic logs are collected when more information is needed to troubleshoot a problem on the device.

The recommended state for this setting is: Enabled

Note: Diagnostic logs are only sent when the device has been configured to send optional diagnostic data. Diagnostic data is limited when recommendation Allow Diagnostic Data is set to Enabled: Diagnostic data off (not recommended) or Enabled: Send required diagnostic data to send only basic information.

Sending data to a third-party vendor is a security concern and should only be done on an as-needed basis.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

System\Limit Diagnostic Log Collection

Impact:

Diagnostic logs and information such as crash dumps will not be collected for transmission to Microsoft.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 8caf53c25222a6b0ac91efef09c4e4125f9fa712271e7635b710075611f6b2d2