Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000120

    Group
  • Exchange audit data must be protected against unauthorized access for deletion.

    Log files help establish a history of activities and can be useful in detecting attack attempts or determining tuning adjustments to improve availability. Audit log content must always be considere...
    Rule Medium Severity
  • SRG-APP-000125

    Group
  • Exchange audit data must be on separate partitions.

    Log files help establish a history of activities and can be useful in detecting attack attempts or determining tuning adjustments to improve availability. Audit log content must always be considere...
    Rule Medium Severity
  • SRG-APP-000131

    Group
  • The Exchange local machine policy must require signed scripts.

    Scripts, especially those downloaded from untrusted locations, often provide a way for attackers to infiltrate a system. By setting machine policy to prevent unauthorized script executions, unantic...
    Rule Medium Severity
  • SRG-APP-000213

    Group
  • Exchange Internet-facing Send connectors must specify a Smart Host.

    When identifying a "Smart Host" for the email environment, a logical Send connector is the preferred method. A Smart Host acts as an Internet-facing concentrator for other email servers. Appropria...
    Rule Medium Severity
  • SRG-APP-000219

    Group
  • Exchange Internet-facing Receive connectors must offer Transport Layer Security (TLS) before using basic authentication.

    Sending unencrypted email over the Internet increases the risk that messages can be intercepted or altered. TLS is designed to protect confidentiality and data integrity by encrypting email message...
    Rule Medium Severity
  • SRG-APP-000247

    Group
  • Exchange Outbound Connection Timeout must be 10 minutes or less.

    Email system availability depends in part on best practice strategies for setting tuning configurations. This configuration controls the number of idle minutes before the connection is dropped. It ...
    Rule Medium Severity
  • SRG-APP-000247

    Group
  • Exchange Outbound Connection Limit per Domain Count must be controlled.

    Email system availability depends in part on best practice strategies for setting tuning configurations. This configuration controls the maximum number of simultaneous outbound connections from a d...
    Rule Medium Severity
  • SRG-APP-000247

    Group
  • Exchange Global Outbound Message size must be controlled.

    Email system availability depends in part on best practice strategies for setting tuning configurations. Message size limits should be set to 10 megabytes at most but often are smaller, depending o...
    Rule Low Severity
  • SRG-APP-000247

    Group
  • Exchange Send connector connections count must be limited.

    This setting controls the maximum number of simultaneous outbound connections allowed for a given SMTP Connector and can be used to throttle the SMTP service if resource constraints warrant it. If ...
    Rule Low Severity
  • SRG-APP-000247

    Group
  • Exchange message size restrictions must be controlled on Send connectors.

    Email system availability depends in part on best practice strategies for setting tuning configurations. For message size restrictions, multiple places exist to set or override inbound or outbound ...
    Rule Low Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules