I - Mission Critical Public
Rules and Groups employed by this XCCDF Profile
-
DTOO260 - SMime message formats
Group -
Message formats must be set to use SMime.
Email typically travels over open networks and is passed from server to server. Messages are therefore vulnerable to interception, and attackers might read or alter their contents. It is therefore ...Rule Medium Severity -
DTOO268 - Missing Root Certificates
Group -
Missing Root Certificates warning must be enforced.
When Outlook accesses a certificate, it validates that it can trust the certificate by examining the root certificate of the issuing CA. If the root certificate can be trusted, then certificates is...Rule Medium Severity -
DTOO239 - Outlook Security Mode
Group -
Outlook Security Mode must be configured to use Group Policy settings.
If users can configure security themselves, they might choose levels of security that leave their computers vulnerable to attack. By default, Outlook users can configure security for themselves, an...Rule Medium Severity -
DTOO228 - Plain Text Options
Group -
Plain Text Options for outbound email must be configured.
If outgoing mail is formatted in certain ways, for example, if attachments are encoded in UUENCODE format, attackers might manipulate the messages for their own purposes. If UUENCODE formatting is ...Rule Medium Severity -
DTOO217 - Prevent publishing to DAV Servers
Group -
Publishing to a Web Distributed and Authoring (DAV) server must be prevented.
Outlook users can share their calendars with others by publishing them to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Unlike the Microsoft Offi...Rule Medium Severity -
DTOO216 - Publishing to Office Online
Group -
Publishing calendars to Office Online must be prevented.
Outlook users can share their calendars with selected others by publishing them to the Microsoft Office Outlook Calendar Sharing Service. Users can control who can view their calendar and at what l...Rule Medium Severity -
DTOO238 - Prev't users customizing security set
Group -
Users customizing attachment security settings must be prevented.
All installed trusted COM addins can be trusted. Exchange settings for the addins still override if present and this option is selected.Rule Medium Severity -
DTOO214 - Read EMail as plain text
Group -
Read EMail as plain text must be enforced.
Outlook can display email messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. By default, Outlook displays email messages in whatever format they were received in.Rule Medium Severity -
DTOO215 - Read signed EMail as plain text
Group -
Read signed email as plain text must be enforced.
Outlook can display email messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. By default, Outlook displays digitally signed email messages in the format they we...Rule Medium Severity -
DTOO244 - Lvl 1 File extensions
Group -
Level 1 file extensions must be blocked and not removed.
Malicious code is often spread through e-mail. Some viruses have the ability to send copies of themselves to other people in the victim's Address Book or Contacts list, and such potentially harmful...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.