WPAW-00-001060 - Device Guard Code Integrity Policy must be used on the Windows PAW to restrict applications that can run on the system (Device Guard User Mode Code Integrity).

Information

A main security architectural construct of a PAW is to restrict non-administrative applications and functions from the PAW workstation. Many standard user applications and functions, including email processing, Internet browsing, and using business applications, can increase the security risk to the workstation. These apps and functions are susceptible to many security vulnerabilities, including phishing attacks and embedded malware. This increased risk is not acceptable for the highly privileged activities of a PAW.

Solution

Implement a whitelist of authorized PAW applications using Device Guard. See the Device Guard Deployment Guide (https://docs.microsoft.com/en-us/windows/device-security/device-guard/device-guard-deployment-guide) for deployment information and hardware requirements and the IAD Device Guard document 'Implementing a Secure Administrative Workstation using Device Guard' at https://github.com/iadgov/Secure-Host-Baseline/tree/master/Device%20Guard.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_PAW_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-243451r991589_rule, STIG-ID|WPAW-00-001060, STIG-Legacy|SV-92869, STIG-Legacy|V-78163, Vuln-ID|V-243451

Plugin: Windows

Control ID: 46f0dbda67cade9d8805c7ff1ff3385335d7e670627a20b48cd2b66ee261c7c5