Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-220738 | WN10-00-000250 | SV-220738r569187_rule | Medium |
Description |
---|
For virtual desktop implementations (VDIs) where the virtual desktop instance is deleted or refreshed upon logoff, the organization should enforce that sessions be terminated within 24 hours. This would ensure any data stored on the VM that is not encrypted or covered by Credential Guard is deleted. |
STIG | Date |
---|---|
Windows 10 Security Technical Implementation Guide | 2021-08-18 |
Check Text ( C-22453r554699_chk ) |
---|
Ensure there is a documented policy or procedure in place that non-persistent VM sessions do not exceed 24 hours. If there is no such documented policy or procedure in place, this is a finding. |
Fix Text (F-22442r554700_fix) |
---|
Set non-persistent VM sessions to not exceed 24 hours. |