[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Allow enhanced PINs for startup

ID: oval:org.secpod.oval:def:35260Date: (C)2016-06-10   (M)2023-12-13
Class: COMPLIANCEFamily: windows




This policy setting allows you to configure whether or not enhanced startup PINs are used with BitLocker. Enhanced startup PINs permit the use of characters including uppercase and lowercase letters, symbols, numbers, and spaces. This policy setting is applied when you turn on BitLocker. If you enable this policy setting, all new BitLocker startup PINs set will be enhanced PINs. Note: Not all computers may support enhanced PINs in the pre-boot environment. It is strongly recommended that users perform a system check during BitLocker setup. If you disable or do not configure this policy setting, enhanced PINs will not be used. Counter Measure: Numeric-only PINs provide much less entropy than a PIN that is alpha-numeric. Increasing the number of characters from 10 digits derived from the function keys to include at least 26 alpha characters from a typical US-ENG key board significantly increase the entropy for a PIN and increases the number of attempts required by an attacker to brute force the system dramatically. Potential Impact: Not all computers enable full keyboard support in the PreOS environment. Some keys may not be available. It is recommended this functionality be tested using the computers in your environment prior to it being deployed. Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Allow enhanced PINs for startup (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\FVE!UseEnhancedPin

Platform:
Microsoft Windows 10
Reference:
CCE-43295-5
CCE    1
CCE-43295-5
XCCDF    3
xccdf_org.secpod_benchmark_HIPAA_45CFR_164_Windows_10
xccdf_org.secpod_benchmark_PCI_3_2_Windows_10
xccdf_org.secpod_benchmark_general_Windows_10

© SecPod Technologies