18.6.24.1.1 (L1) Ensure 'Let Windows apps access cellular data' is set to 'Enabled: Force Deny'

Information

This policy setting specifies whether Windows apps can access cellular data.

The recommended state for this setting is: Enabled: Force Deny

Note: In some instances, cellular data / mobile broadband is used by the EMS Gateway to transfer data in and out of the Election System. In this case, an exception to the policy

Let Windows apps access cellular data

that either

Disables

the setting, or chooses the options

User is in control

or

Force Allow

is considered in compliance with the benchmark.

The capability to run a cellular connection from a domain-connected computer could expose the internal network to hackers.

Note: In some instances, cellular data / mobile broadband is used by the EMS Gateway to transfer data in and out of the Election System. In this case, an exception to the policy

Let Windows apps access cellular data

that either

Disables

the setting, or chooses the options

User is in control

or

Force Allow

is considered in compliance with the benchmark.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Force Deny

Computer Configuration\Policies\Administrative Templates\Network\WWAN Service\Cellular Data Access\Let Windows apps access cellular data

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template wwansvc.admx/adml that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Impact:

Users will not be able to use cellular data on the system.

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-18(3)

Plugin: Windows

Control ID: fce24890d30a1808973c5fb0c1bbfd53c21255e85e584d6ef98abff59f482899