Skip to content

Microsoft SharePoint 2013 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000516

    Group
  • SharePoint must identify data type, specification, and usage when transferring information between different security domains so policy restrictions may be applied.

    Information flow control regulates where information is allowed to travel within an information system and between information systems (as opposed to who is allowed to access the information) and w...
    Rule Medium Severity
  • SRG-APP-000047

    Group
  • SRG-APP-000068

    Group
  • SharePoint must display an approved system use notification message or banner before granting access to the system.

    Applications are required to display an approved system use notification message or banner before granting access to the system providing privacy and security notices consistent with applicable fed...
    Rule Medium Severity
  • SRG-APP-000090

    Group
  • SRG-APP-000516

    Group
  • SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds.

    It is critical when a system is at risk of failing to process audit logs as required; actions are automatically taken to mitigate the failure or risk of failure. One method used to thwart the audi...
    Rule Medium Severity
  • SRG-APP-000112

    Group
  • SRG-APP-000156

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules