[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Disable new DMA devices when this computer is locked

ID: oval:org.secpod.oval:def:79789Date: (C)2022-05-07   (M)2023-07-04
Class: COMPLIANCEFamily: windows




This policy setting allows you to block direct memory access (DMA) for all hot pluggable PCI downstream ports until a user logs into Windows. The recommended state for this setting is: Enabled. Note: Some PCs may not be compatible with this policy if the system firmware enables DMA for newly attached Thunderbolt devices before exposing the new devices to Windows. Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Disable new DMA devices when this computer is locked (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\FVE!DisableExternalDMAUnderLock

Platform:
Microsoft Windows 11
Reference:
CCE-97043-4
CPE    1
cpe:/o:microsoft:windows_11:21h2::x64
CCE    1
CCE-97043-4
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_11

© SecPod Technologies