Windows 11 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-253273WN11-00-000025SV-253273r828637_ruleCCI-001764medium
Description
Utilizing a whitelist approach allows only authorized software programs to execute. This prevents malware and unauthorized software from executing.
STIGDate
Microsoft Windows 11 Security Technical Implementation Guide2024-10-15

Details

Check Text (C-253273r828637_chk)

Verify Windows Defender Application Control (WDAC) is implemented to allow only approved applications to execute. If WDAC is not implemented, this is a finding.

Fix Text (F-56690r828636_fix)

Configure Windows 11 to use Windows Defender Application Control (WDAC) to allow only approved applications to execute. Refer to Windows Defender Application Control documentation for configuration details.