[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Disable new DMA devices when this computer is locked

ID: oval:org.secpod.oval:def:80699Date: (C)2022-06-03   (M)2023-12-13
Class: COMPLIANCEFamily: windows




This policy setting allows you to block direct memory access (DMA) for all hot pluggable PCI downstream ports until a user logs into Windows. The recommended state for this setting is: Enabled. Note: Some PCs may not be compatible with this policy if the system firmware enables DMA for newly attached Thunderbolt devices before exposing the new devices to Windows. Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Disable new DMA devices when this computer is locked (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\FVE!DisableExternalDMAUnderLock

Platform:
Microsoft Windows 10
Reference:
CCE-98573-9
CPE    1
cpe:/o:microsoft:windows_10
CCE    1
CCE-98573-9
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_10

© SecPod Technologies