Check: WN10-CC-000195
Microsoft Windows 10 STIG:
WN10-CC-000195
(in versions v3 r2 through v1 r15)
Title
Enhanced anti-spoofing for facial recognition must be enabled on Window 10. (Cat II impact)
Discussion
Enhanced anti-spoofing provides additional protections when using facial recognition with devices that support it.
Check Content
Windows 10 v1507 LTSB version does not include this setting; it is NA for those systems. If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Biometrics\FacialFeatures\ Value Name: EnhancedAntiSpoofing Value Type: REG_DWORD Value: 0x00000001 (1)
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Biometrics >> Facial Features >> "Configure enhanced anti-spoofing" to "Enabled". v1607: The policy name is "Use enhanced anti-spoofing when available".
Additional Identifiers
Rule ID: SV-220830r991589_rule
Vulnerability ID: V-220830
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |