Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • DTOO211 - Restrict ActiveX Install

    Group
  • ActiveX installs must be configured for proper restrictions.

    Microsoft ActiveX controls allow unmanaged, unprotected code to run on the user computers. ActiveX controls do not run within a protected container in the browser like the other types of HTML or Mi...
    Rule Medium Severity
  • DTOO304 - VBA Macro Warning settings

    Group
  • Warning Bar settings for VBA macros must be configured.

    When users open files containing VBA Macros, applications open the files with the macros disabled and displays the Trust Bar with a warning that macros are present and have been disabled. Users may...
    Rule Medium Severity
  • DTOO104 - Disabling of user name and password

    Group
  • Disabling of user name and password syntax from being used in URLs must be enforced.

    The Uniform Resource Locator (URL) standard allows user authentication to be included in URL strings in the form http://username:password@example.com. A malicious user might use this URL syntax to ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules