7.5 Ensure TLS 1.0 is disabled

Information

The PCI Data Security Standard 3.1 recommends disabling 'early TLS' along with SSL:

SSL and early TLS are not considered strong cryptography and cannot be used as a security control after June 30, 2016.

Solution

Review the following registry locations to verify that TLS 1.0 is configured as expected.
Disabled settings - Enabled to 0.
HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server\Enabled

See Also

https://workbench.cisecurity.org/files/165

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 3aa5cdb31455c85252f505270c3e86fd163336192a9e9dd96ec09cbaa1a38f67