UCF STIG Viewer Logo

The system must not use removable media as the boot loader.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36664 WN12-00-000003 SV-51574r3_rule ECSC-1 High
Description
Malicious users with removable boot media can gain access to a system configured to use removable media as the boot loader.
STIG Date
Windows Server 2012 / 2012 R2 Member Server Security Technical Implementation Guide 2015-09-02

Details

Check Text ( C-46837r3_chk )
Verify whether the system BIOS or controller allows removable media for the boot loader. If it does, this is a finding.

If access is restricted by way of hypervisor configuration settings on virtual systems, this would not be a finding.
Fix Text (F-44703r2_fix)
Configure the system to use a boot loader installed on fixed media.

Restrictions may also be applied through hypervisor configuration settings for virtual machines.