83.5 (L1) Ensure 'Scheduled Install Day' is set to 'Every day'

Information

This policy setting specifies when computers in your environment will receive security updates from Windows Update or WSUS.

The recommended state for this setting is: Every day

Note: This setting is only applicable if the option of 3 or 4 is selected in the recommendation

'Allow Auto Update'

. It will have no impact if any other option is selected.

Although each version of Windows is thoroughly tested before release, it is possible that problems will be discovered after the products are shipped. The Configure Automatic Updates setting can help you ensure that the computers in your environment will always have the most recent critical operating system updates and service packs installed.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Every day

Windows Update For Business\Scheduled Install Day

Impact:

If option 3 or 4 is selected in recommendation

'Allow Auto Update'

, critical operating system updates and service packs will automatically download every day (at 3:00 A.M., by default).

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Windows

Control ID: a902304659fb1bb7b3c467948f9c83f3587f4953528a4d06b8e29870a3b330ca