Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • DTOO221 - Junk Mail UI

    Group
  • Junk Mail UI must be configured.

    The Junk E-mail Filter in Outlook is designed to intercept the most obvious junk email, or spam, and send it to users' Junk E-mail folders. The filter evaluates each incoming message based on sever...
    Rule Medium Severity
  • DTOO274 - Internet with Safe Zones

    Group
  • Internet with Safe Zones for Picture Download must be disabled.

    Malicious email senders can send HTML email messages with embedded Web beacons, which are pictures and other content from external servers that can be used to track whether recipients open the mess...
    Rule Medium Severity
  • DTOO275 - Incl. Intranet with Safe Zone

    Group
  • Intranet with Safe Zones for automatic picture downloads must be configured.

    Malicious email senders can send HTML email messages with embedded Web beacons, which are pictures and other content from external servers that can be used to track whether recipients open the mess...
    Rule Medium Severity
  • DTOO240 - Level 1 Attachments

    Group
  • The ability to display level 1 attachments must be disallowed.

    To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, to restrict access to files attached to email messages or other items. Po...
    Rule Medium Severity
  • DTOO270 - External Pictures & content

    Group
  • External content and pictures in HTML email must be displayed.

    Malicious email senders can send HTML email messages with embedded Web beacons, which are pictures and other content from external servers that can be used to track whether specific recipients open...
    Rule Medium Severity
  • DTOO227 - Digital Signature handling

    Group
  • The ability to add signatures to email messages must be allowed.

    Outlook users can create and use signatures in email messages. Users can add signatures to messages manually, and can also configure Outlook to automatically append signatures to new messages, to r...
    Rule Medium Severity
  • DTOO230 - No fldr home pages / non-default stores

    Group
  • Folders in non-default stores, set as folder home pages, must be disallowed.

    Outlook allows users to designate Web pages as home pages for personal or public folders. When a user clicks on a folder, Outlook displays the home page the user has assigned to it. Although this f...
    Rule Medium Severity
  • DTOO233 - OOM scripts for Public Folders

    Group
  • Outlook Object Model scripts must be disallowed to run for public folders.

    In Outlook, folders can be associated with custom forms or folder home pages that include scripts that access the Outlook object model. These scripts can add functionality to the folders and items ...
    Rule Medium Severity
  • DTOO232 - OOM scripts for Shared Folders

    Group
  • Outlook Object Model scripts must be disallowed to run for shared folders.

    In Outlook, folders can be associated with custom forms or folder home pages that include scripts that access the Outlook object model. These scripts can add functionality to the folders and items ...
    Rule Medium Severity
  • DTOO285 - Internet Calendar Integration

    Group
  • Internet calendar integration in Outlook must be disabled.

    The Internet Calendar feature in Outlook enables users to publish calendars online (using the webcal:// protocol) and subscribe to calendars that others have published. When users subscribe to an I...
    Rule Medium Severity
  • DTOO269 - Attachments to Secure Temporary Folder

    Group
  • Attachments using generated name for secure temporary folders must be configured.

    The Secure Temporary Files folder is used to store attachments when they are opened in email. By default, Outlook generates a random name for the Secure Temporary Files folder and saves it in the T...
    Rule Medium Severity
  • DTOO280 - Authentication w/Exchange Svr

    Group
  • Outlook must be configured to force authentication when connecting to an Exchange server.

    Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and...
    Rule Medium Severity
  • DTOO284 - Auto download attachments Internet Cal

    Group
  • Automatic download of Internet Calendar appointment attachments must be disallowed.

    Files attached to Internet Calendar appointments could contain malicious code that could be used to compromise a computer. By default, Outlook does not download attachments when retrieving Internet...
    Rule Medium Severity
  • DTOO271 - Auto Download from Safe lists

    Group
  • Automatic download content for email in Safe Senders list must be disallowed.

    Malicious email senders can send HTML email messages with embedded Web beacons, or pictures and other content from external servers that can be used to track whether specific recipients have opened...
    Rule Medium Severity
  • DTOO229 - Make Outlook the default program

    Group
  • Outlook must be enforced as the default email, calendar, and contacts program.

    Outlook is made the default program for email, contacts, and calendar services when it is installed, although users can designate other programs as the default programs for these services. If anoth...
    Rule Medium Severity
  • DTOO260 - SMime message formats

    Group
  • Message formats must be set to use SMime.

    Email typically travels over open networks and is passed from server to server. Messages are therefore vulnerable to interception, and attackers might read or alter their contents. It is therefore ...
    Rule Medium Severity
  • DTOO268 - Missing Root Certificates

    Group
  • Missing Root Certificates warning must be enforced.

    When Outlook accesses a certificate, it validates that it can trust the certificate by examining the root certificate of the issuing CA. If the root certificate can be trusted, then certificates is...
    Rule Medium Severity
  • DTOO239 - Outlook Security Mode

    Group
  • Outlook Security Mode must be configured to use Group Policy settings.

    If users can configure security themselves, they might choose levels of security that leave their computers vulnerable to attack. By default, Outlook users can configure security for themselves, an...
    Rule Medium Severity
  • DTOO228 - Plain Text Options

    Group
  • Plain Text Options for outbound email must be configured.

    If outgoing mail is formatted in certain ways, for example, if attachments are encoded in UUENCODE format, attackers might manipulate the messages for their own purposes. If UUENCODE formatting is ...
    Rule Medium Severity
  • DTOO217 - Prevent publishing to DAV Servers

    Group
  • Publishing to a Web Distributed and Authoring (DAV) server must be prevented.

    Outlook users can share their calendars with others by publishing them to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Unlike the Microsoft Offi...
    Rule Medium Severity
  • DTOO216 - Publishing to Office Online

    Group
  • Publishing calendars to Office Online must be prevented.

    Outlook users can share their calendars with selected others by publishing them to the Microsoft Office Outlook Calendar Sharing Service. Users can control who can view their calendar and at what l...
    Rule Medium Severity
  • DTOO238 - Prev't users customizing security set

    Group
  • Users customizing attachment security settings must be prevented.

    All installed trusted COM addins can be trusted. Exchange settings for the addins still override if present and this option is selected.
    Rule Medium Severity
  • DTOO214 - Read EMail as plain text

    Group
  • Read EMail as plain text must be enforced.

    Outlook can display email messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. By default, Outlook displays email messages in whatever format they were received in.
    Rule Medium Severity
  • DTOO215 - Read signed EMail as plain text

    Group
  • Read signed email as plain text must be enforced.

    Outlook can display email messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. By default, Outlook displays digitally signed email messages in the format they we...
    Rule Medium Severity
  • DTOO244 - Lvl 1 File extensions

    Group
  • Level 1 file extensions must be blocked and not removed.

    Malicious code is often spread through e-mail. Some viruses have the ability to send copies of themselves to other people in the victim's Address Book or Contacts list, and such potentially harmful...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules