WN11-00-000020 - Secure Boot must be enabled on Windows 11 systems.

Information

Secure Boot is a standard that ensures systems boot only to a trusted operating system. Secure Boot is required to support additional security features in Windows 11, including virtualization-based Security and Credential Guard. If Secure Boot is turned off, these security features will not function.

Solution

Enable Secure Boot in the system firmware.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_11_V2R1_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1), CAT|II, CCI|CCI-002421, Rule-ID|SV-253257r971547_rule, STIG-ID|WN11-00-000020, Vuln-ID|V-253257

Plugin: Windows

Control ID: 226c844373318f6d54615660b146c0feca52ec1da30a179656693a0af59e79dd