Microsoft Outlook 2013 STIG
Rules, Groups, and Values defined within the XCCDF Benchmark
-
DTOO269 - Attachments to Secure Temporary Folder
Group -
DTOO280 - Authentication w/Exchange Svr
Group -
Outlook must be configured to force authentication when connecting to an Exchange server.
Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and...Rule Medium Severity -
DTOO284 - Auto download attachments Internet Cal
Group -
Automatic download of Internet Calendar appointment attachments must be disallowed.
Files attached to Internet Calendar appointments could contain malicious code that could be used to compromise a computer. By default, Outlook does not download attachments when retrieving Internet...Rule Medium Severity -
DTOO271 - Auto Download from Safe lists
Group -
Automatic download content for email in Safe Senders list must be disallowed.
Malicious email senders can send HTML email messages with embedded Web beacons, or pictures and other content from external servers that can be used to track whether specific recipients have opened...Rule Medium Severity -
DTOO229 - Make Outlook the default program
Group -
DTOO260 - SMime message formats
Group -
Message formats must be set to use SMime.
Email typically travels over open networks and is passed from server to server. Messages are therefore vulnerable to interception, and attackers might read or alter their contents. It is therefore ...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.