CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.1

Windows 11 Control Panel: 4 Checks

Wartiva runs 4 checks for section 18.1, Control Panel, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 4 checks on this page

Ensure Allow Online Tips Is Disabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1

Finding: Online tips retrieval for the Settings app is allowed.

Checks whether the Settings app is prevented from retrieving online tips and help content.

This rule fails when allowOnlineTips is not false.

Rationale: Contacting external content services can leak information to third parties; in high-security environments data should not be shared without explicit consent.

Impact: The Settings app will not contact Microsoft content services for tips and help.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Control Panel > Allow Online Tips and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v AllowOnlineTips /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.1.1 Personalization

Ensure Prevent Enabling Lock Screen Camera Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1.1

Finding: Lock screen camera is not prevented.

Checks whether the lock screen camera toggle is disabled so a camera cannot be invoked from the lock screen.

This rule fails when noLockScreenCamera is not true.

Rationale: Extending the lock screen protection to camera features prevents an unattended, locked device from being used to capture images.

Impact: Users can no longer enable or disable lock screen camera access, and the camera cannot be invoked on the lock screen.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent enabling lock screen camera and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" /v NoLockScreenCamera /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Prevent Enabling Lock Screen Slide Show Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1.1

Finding: Lock screen slide show is not prevented.

Checks whether the lock screen slide show is disabled so no slide show plays on the lock screen.

This rule fails when noLockScreenSlideshow is not true.

Rationale: A slide show on a locked device can display file contents to a passer-by; disabling it extends the lock screen's protection to slide show contents.

Impact: Users can no longer modify slide show settings and no slide show will start on the lock screen.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent enabling lock screen slide show and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" /v NoLockScreenSlideshow /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

18.1.2 Regional and Language Options

Ensure Online Speech Recognition Services Are Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1.2

Finding: Online speech recognition and input personalization are allowed.

Checks whether automatic learning of speech, inking, and typing (input personalization) is turned off.

This rule fails when allowInputPersonalization is not false.

Rationale: Automatic learning collects speech and handwriting patterns, typing history, contacts, and calendar data, some of which is uploaded to the cloud where it may expose sensitive information.

Impact: Automatic learning stops and users cannot re-enable it from PC Settings.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Control Panel > Regional and Language Options > Allow users to enable online speech recognition services and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\InputPersonalization" /v AllowInputPersonalization /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)