Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (2024)

NIST 800-171 control 3.13.11 dictates that FIPS-validated cryptography is used when protecting the confidentiality of CUI. BitLocker is FIPS-validated, but it requires a setting before encryption that ensures that the encryption meets the standards set forth by FIPS 140-2. When encrypting devices with BitLocker, please be sure to follow the steps below to ensure that the encryption used is within parameters of control 3.13.11.

Option 1: Local Security Policy

  • Open Local Security Policy as administrator
  • Navigate to Local Policies =>Security Options
  • Set System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing to be Enabled
  • Then, encrypt the machine using BitLocker

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (1)

Option 2: Domain Group Policy

  • Open Group Policy Management
  • Choose one of the following options:
    • To use an existing GPO to configure the necessary setting, link the _Campus-NIST800-171-FIPS-Compliant-BitLocker GPO to the OU where the computers in question reside.
    • Otherwise: Locate an existing GPO or create a new GPO, right click it, and then select Edit
      • When the Group Policy Management Editor opens, navigate to Policies =>Windows Settings =>Security Settings =>Local Policies =>Security Options
      • Locate System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing and open it

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (2)

      • Ensure the policy is defined and set to Enabled, and then click OK.

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (3)

  • Ensure the GPO is applied to the machine to be encrypted with BitLocker.
  • Finally, encrypt the machine with BitLocker.

Special Case: Windows 7 Machine

If the machine is a Windows 7 machine, another step will need to be completed. As recovery passwords aren’t FIPS 140-2 compliant, any recovery passwords will need to be removed. This issue was resolved in Windows 8 and above. To ensure the Windows 7 machine is compliant:

  • Open CMD as an administrator
  • Run the following command:
    • manage-bde -protectors -get c:
      • Be sure to replace “c:” with the letter of the encrypted drive.
    • In the result, locate ID: under Numerical Password: and copy the value
      • Example value: {C6DF1E74-467F-4BE8-9C59-C9A9F345B9A0}

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (4)

  • When you have the value, run the following command to delete the recovery password:
    • manage-bde -protectors -delete c: -id {########-####-####-####-############}
      • Again, be sure to replace the drive letter as necessary.

Recovery Options

To ensure the drive is recoverable, a few options are:

Additional Information

For more information, please navigate to this link: How to Make Your Existing BitLocker Encrypted Environment FIPS Compliant

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (2024)
Top Articles
Virtual Debit Card vs Physical Debit Card: How to choose?
Does Closing a Credit Card Hurt Your Credit Score? - NerdWallet
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Sen. Emmett Berge

Last Updated:

Views: 5694

Rating: 5 / 5 (60 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Sen. Emmett Berge

Birthday: 1993-06-17

Address: 787 Elvis Divide, Port Brice, OH 24507-6802

Phone: +9779049645255

Job: Senior Healthcare Specialist

Hobby: Cycling, Model building, Kitesurfing, Origami, Lapidary, Dance, Basketball

Introduction: My name is Sen. Emmett Berge, I am a funny, vast, charming, courageous, enthusiastic, jolly, famous person who loves writing and wants to share my knowledge and understanding with you.