1. Home
  2. Security Hardening
  3. CIS Microsoft Windows 10 Enterprise Release 1909 V1.8.1 L2 Ng
  4. Ensure ‘Microsoft iSCSI Initiator Service (MSiSCSI)’ is set to ‘Disabled’

Ensure ‘Microsoft iSCSI Initiator Service (MSiSCSI)’ is set to ‘Disabled’

Details

Manages Internet SCSI (iSCSI) sessions from this computer to remote target devices.

The recommended state for this setting is: Disabled.

Rationale:

This service is critically necessary in order to directly attach to an iSCSI device. However, iSCSI itself uses a very weak authentication protocol (CHAP), which means that the passwords for iSCSI communication are easily exposed, unless all of the traffic is isolated and/or encrypted using another technology like IPsec. This service is generally more appropriate for servers in a controlled environment then on workstations requiring high security.

Solution

To establish the recommended configuration via GP, set the following UI path to: Disabled.

Computer ConfigurationPoliciesWindows SettingsSecurity SettingsSystem ServicesMicrosoft iSCSI Initiator Service

Impact:

The computer will not be able to directly login to or access iSCSI targets.

Default Value:

Manual

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Information Integrity.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles