Skip to content

MS Exchange 2013 Edge Transport Server Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Exchange Receive connectors must control the number of recipients per message.

    Email system availability depends in part on best practice strategies for setting tuning configurations. This configuration controls the maximum number of recipients who will receive a copy of a ...
    Rule Medium Severity
  • The Exchange Sender filter must block unaccepted domains.

    Spam origination sites and other sources of suspected email-borne malware have the ability to corrupt, compromise, or otherwise limit availability of email servers. Limiting exposure to unfiltered ...
    Rule Medium Severity
  • Exchange Attachment filtering must remove undesirable attachments by file type.

    By performing filtering at the perimeter, up to 90 percent of spam, malware, and other undesirable messages are eliminated from the message stream rather than admitting them into the mail server en...
    Rule Medium Severity
  • The Exchange Spam Evaluation filter must be enabled.

    By performing filtering at the perimeter, up to 90 percent of spam, malware, and other undesirable messages may be eliminated from the transport message stream, preventing their entry into the Exch...
    Rule Medium Severity
  • Exchange internal Receive connectors must not allow anonymous connections.

    This control is used to limit the servers that may use this server as a relay. If a Simple Mail Transport Protocol (SMTP) sender does not have a direct connection to the Internet (for example, an a...
    Rule Medium Severity
  • Exchange must have antispam filtering enabled.

    Originators of spam messages are constantly changing their techniques in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. Sp...
    Rule Medium Severity
  • Exchange must have antispam filtering configured.

    Originators of spam messages are constantly changing their techniques in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. A ...
    Rule Medium Severity
  • Exchange services must be documented and unnecessary services must be removed or disabled.

    Unneeded but running services offer attackers an enhanced attack profile, and attackers are constantly watching to discover open ports with running services. By analyzing and disabling unneeded ser...
    Rule Medium Severity
  • The Exchange SMTP automated banner response must not reveal server details.

    Automated connection responses occur as a result of FTP or Telnet connections when connecting to those services. They report a successful connection by greeting the connecting client and stating th...
    Rule Medium Severity
  • Exchange internal Send connectors must use an authentication level.

    The Simple Mail Transfer Protocol (SMTP) connector is used by Exchange to send and receive messages from server to server. Several controls work together to provide security between internal server...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules