CCI-001170
Prevents the automatic execution of mobile code in organization-defined software applications.
1 rule found Severity: Medium

9 rules found Severity: Medium

9 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

Disabling of user name and password syntax from being used in URLs must be enforced in PowerPoint Viewer.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

3 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

17 rules found Severity: Medium

9 rules found Severity: Medium

4 rules found Severity: Medium

Microsoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Microsoft Defender AV must be configured block Office applications from creating executable content.
1 rule found Severity: Medium

Microsoft Defender AV must be configured to block Office applications from injecting into other processes.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Microsoft Defender AV must be configured to prevent user and apps from accessing dangerous websites.
1 rule found Severity: Medium

2 rules found Severity: Medium

8 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

Disabling of user name and password syntax from being used in URLs must be enforced in PowerPoint Viewer.
1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Initialize and script ActiveX controls not marked as safe property must be disallowed (Internet zone).
1 rule found Severity: Medium

1 rule found Severity: Medium

The Initialize and script ActiveX controls not marked as safe must be disallowed (Trusted Sites Zone).
1 rule found Severity: Medium

The Initialize and script ActiveX controls not marked as safe property must be disallowed (Restricted Sites zone).
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

ActiveX controls without prompt property must be used in approved domains only (Restricted Sites zone).
1 rule found Severity: Medium

The Mainframe Product must prevent the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code run-time environments, and mobile agent systems.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Macros in all Office applications that are opened programmatically by another application must be opened based upon macro security level.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Outlook must be configured to not run scripts in forms in which the script and the layout are contained within the message.
1 rule found Severity: Medium

1 rule found Severity: Medium

If file validation fails, files must be opened in Protected view in PowerPoint with ability to edit disabled.
1 rule found Severity: Medium

In Word, macros must be blocked from running, even if Enable all macros is selected in the Macro Settings section of the Trust Center.
1 rule found Severity: Medium

The operating system must disable information system functionality that provides the capability for automatic execution of code on mobile devices without user direction.
2 rules found Severity: Medium

The system must restrict the ability of users to assume excessive privileges to members of a defined group and prevent unauthorized users from accessing administrative tools.
1 rule found Severity: Medium
