Windows 11 must have Secure Boot enabled.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-253272WN11-00-000010SV-253272r877393_ruleCCI-000366high
Description
Secure Boot is a security standard that ensures systems boot using only software that is trusted. This prevents rootkits and other malware from loading during the boot process.
STIGDate
Microsoft Windows 11 Security Technical Implementation Guide2024-10-15

Details

Check Text (C-253272r877393_chk)

Some hardware may not support Secure Boot. Verify with the system vendor. Run "System Information". Under "System Summary", if "Secure Boot State" does not display "On", this is a finding.

Fix Text (F-56689r819638_fix)

Enable Secure Boot in the system firmware. Refer to system documentation for configuration details.