Windows 11 must have Secure Boot enabled.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-253272 | WN11-00-000010 | SV-253272r877393_rule | CCI-000366 | high |
| Description | ||||
| Secure Boot is a security standard that ensures systems boot using only software that is trusted. This prevents rootkits and other malware from loading during the boot process. | ||||
| STIG | Date | |||
| Microsoft Windows 11 Security Technical Implementation Guide | 2024-10-15 | |||
Details
Check Text (C-253272r877393_chk)
Some hardware may not support Secure Boot. Verify with the system vendor.
Run "System Information".
Under "System Summary", if "Secure Boot State" does not display "On", this is a finding.
Fix Text (F-56689r819638_fix)
Enable Secure Boot in the system firmware.
Refer to system documentation for configuration details.