18.10.6.1 (L1) Ensure 'Turn off Inventory Collector' is set to 'Enabled'

Information

This policy setting controls the state of the Inventory Collector. The Inventory Collector inventories applications, files, devices, and drivers on the system and sends the information to Microsoft. This information is used to help diagnose compatibility problems.

The recommended state for this setting is: Enabled

Due to privacy concerns, data should never be sent to any 3rd party since this data could contain sensitive information.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Application Compatibility\Turn off Inventory Collector

Note: This Group Policy section is provided by the Group Policy template AppCompat.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates..

Impact:

The Inventory Collector will not send data such as, inventories of applications, files, devices, and drivers to Microsoft.

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Windows

Control ID: 6aa0549465fa07961b3e1f5244946558e9d1d075b26593396f471a06fb92ae3e