Skip to content

Microsoft Exchange 2016 Edge Transport Server Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • The Exchange Spam Evaluation filter must be enabled.

    By performing filtering at the perimeter, up to 90 percent of spam, malware, and other undesirable messages may be eliminated from the transport message stream, preventing their entry into the Exch...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • Exchange messages with a malformed From address must be rejected.

    Sender Identification (SID) is an email antispam sanitization process. Sender ID uses DNS MX record lookups to verify the Simple Mail Transfer Protocol (SMTP) sending server is authorized to send e...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • The Exchange tarpitting interval must be set.

    Tarpitting is the practice of artificially delaying server responses for specific Simple Mail Transfer Protocol (SMTP) communication patterns that indicate high volumes of spam or other unwelcome m...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • Exchange Simple Mail Transfer Protocol (SMTP) IP Allow List entries must be empty.

    Email system availability depends in part on best practice strategies for setting tuning configurations. Careful tuning reduces the risk that system or network congestion will contribute to availab...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • The Exchange Simple Mail Transfer Protocol (SMTP) Sender filter must be enabled.

    Email system availability depends in part on best practices strategies for setting tuning configurations. Careful tuning reduces the risk that system or network congestion will contribute to availa...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • SRG-APP-000261

    Group
  • Exchange must have antispam filtering enabled.

    Originators of spam messages are constantly changing their techniques in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. Sp...
    Rule Medium Severity
  • SRG-APP-000261

    Group
  • Exchange must have antispam filtering configured.

    Originators of spam messages are constantly changing their techniques in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. A ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules