3.052 - Ejection of removable NTFS media is not restricted to Administrators.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Removable hard drives can be formatted and ejected by others who are not members of the Administrators Group, if they are not properly configured. Formatting and ejecting removable NTFS media should only be done by administrators.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Devices: Allowed to Format and Eject Removable Media' to 'Administrators'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_R2_MS_V1R33_STIG.zip

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-2, CAT|II, CCI|CCI-000366, CSCv6|8.3, Rule-ID|SV-32310r1_rule, STIG-ID|3.052, Vuln-ID|V-1171

Plugin: Windows

Control ID: 1f5d4e08b85c325ccf18fbc9c0c8d0fd990aa71e585811dba6ccf201faf51718