Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Adobe Reader DC must disable the ability to change the Default Handler.
<VulnDiscussion>Allowing user to make changes to an application case cause a security risk. When the Default PDF Handler is disabled, the en...Rule Low Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must enable Enhanced Security in a Standalone Application.
<VulnDiscussion>PDFs have evolved from static pages to complex documents with features such as interactive forms, multimedia content, scripti...Rule Medium Severity -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must enable Enhanced Security in a Browser.
<VulnDiscussion>PDFs have evolved from static pages to complex documents with features such as interactive forms, multimedia content, scripti...Rule Medium Severity -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must enable Protected Mode.
<VulnDiscussion>A threat to users of Adobe Reader DC is opening a PDF file that contains malicious executable content. Protected mode provid...Rule Medium Severity -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must enable Protected View.
<VulnDiscussion>A threat to users of Adobe Reader DC is opening a PDF file that contains malicious executable content. Protected view restri...Rule Medium Severity -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must Block Websites.
<VulnDiscussion>Clicking any link to the Internet poses a potential security risk. Malicious websites can transfer harmful content or silentl...Rule Medium Severity -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must block access to Unknown Websites.
<VulnDiscussion>Because Internet access is a potential security risk, clicking any unknown website link to the Internet poses a potential sec...Rule Medium Severity -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must prevent opening files other than PDF or FDF.
<VulnDiscussion>Attachments represent a potential security risk because they can contain malicious content, open other dangerous files, or la...Rule Medium Severity -
SRG-APP-000112
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must block Flash Content.
<VulnDiscussion>Flash content is commonly hosted on a web page, but it can also be embedded in PDF and other documents. Flash could be used t...Rule Medium Severity -
SRG-APP-000133
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable the Adobe Send and Track plugin for Outlook.
<VulnDiscussion>When enabled, Adobe Send and Track button appears in Outlook. When an email is composed it enables the ability to send large ...Rule Low Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable all service access to Document Cloud Services.
<VulnDiscussion>By default, Adobe online services are tightly integrated in Adobe Reader DC. With the integration of Adobe Document Cloud, di...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable Cloud Synchronization.
<VulnDiscussion>By default, Adobe online services are tightly integrated in Adobe Reader DC. When the Adobe Cloud synchronization is disabled...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable the Adobe Repair Installation.
<VulnDiscussion>When Repair Installation is disabled the user does not have the option (Help Menu) or functional to repair an Adobe Reader DC...Rule Low Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable 3rd Party Web Connectors.
<VulnDiscussion>When 3rd Party Web Connectors are disabled it prevents the configuration of Adobe Reader DC access to third party services fo...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable Acrobat Upsell.
<VulnDiscussion>Products that don't provide the full set of features by default provide the user the opportunity to upgrade. Acrobat Upsell d...Rule Low Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable Adobe Send for Signature.
<VulnDiscussion>The Adobe Document Cloud sign service allows users to send documents online for signature and sign from anywhere or any devic...Rule Low Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable access to Webmail.
<VulnDiscussion>When Webmail is disabled the user cannot configure a webmail account to send an open PDF document as an attachment. Users sho...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable Online SharePoint Access.
<VulnDiscussion>Disabling SharePoint disables or removes the user’s ability to add a SharePoint account access controls the application's abi...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable the Adobe Welcome Screen.
<VulnDiscussion>The Adobe Reader DC Welcome screen can be distracting and also has online links to the Adobe quick tips website, tutorials, b...Rule Low Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable Service Upgrades.
<VulnDiscussion>By default, Adobe online services are tightly integrated into Adobe Reader DC. Disabling Service Upgrades disables both updat...Rule Low Severity -
SRG-APP-000380
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable the ability to add Trusted Files and Folders.
<VulnDiscussion>Privileged Locations allow the user to selectively trust files, folders, and hosts to bypass some security restrictions, such...Rule Medium Severity -
SRG-APP-000380
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable the ability to elevate IE Trusts to Privileged Locations.
<VulnDiscussion>Privileged Locations allow the user to selectively trust files, folders, and hosts to bypass some security restrictions, such...Rule Medium Severity -
SRG-APP-000427
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable periodical uploading of European certificates.
<VulnDiscussion>By default, the user can update European certificates from an Adobe server through the GUI. When uploading European certific...Rule Low Severity -
SRG-APP-000427
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must disable periodical uploading of Adobe certificates.
<VulnDiscussion>By default, the user can update Adobe certificates from an Adobe server through the GUI. When uploading Adobe certificates i...Rule Low Severity -
SRG-APP-000456
<GroupDescription></GroupDescription>Group -
Adobe Reader DC must have the latest Security-related Software Updates installed.
<VulnDiscussion>Security flaws with software applications are discovered daily. Vendors are constantly updating and patching their products t...Rule High Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.