II - Mission Support Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000141
Group -
Internet Explorer Processes for restricting pop-up windows must be enforced (Explorer).
Internet Explorer allows scripts to programmatically open, resize, and reposition various types of windows. Often, disreputable websites will resize windows to either hide other windows or force a ...Rule Medium Severity -
SRG-APP-000141
Group -
Internet Explorer Processes for restricting pop-up windows must be enforced (iexplore).
Internet Explorer allows scripts to programmatically open, resize, and reposition various types of windows. Often, disreputable websites will resize windows to either hide other windows or force a ...Rule Medium Severity -
SRG-APP-000516
Group -
.NET Framework-reliant components not signed with Authenticode must be disallowed to run (Restricted Sites Zone).
This policy setting allows you to manage whether .NET Framework-reliant components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed con...Rule Medium Severity -
SRG-APP-000516
Group -
.NET Framework-reliant components signed with Authenticode must be disallowed to run (Restricted Sites Zone).
This policy setting allows you to manage whether .NET Framework-reliant components that are signed with Authenticode can be executed from Internet Explorer. It may be possible for malicious content...Rule Medium Severity -
SRG-APP-000141
Group -
Scripting of Java applets must be disallowed (Restricted Sites zone).
This policy setting allows you to manage whether applets are exposed to scripts within the zone. If you enable this policy setting, scripts can access applets automatically without user interventio...Rule Medium Severity -
SRG-APP-000141
Group -
AutoComplete feature for forms must be disallowed.
This AutoComplete feature suggests possible matches when users are filling in forms. It is possible that this feature will cache sensitive data and store it in the user's profile, where it might no...Rule Medium Severity -
SRG-APP-000141
Group -
Crash Detection management must be enforced.
The 'Turn off Crash Detection' policy setting allows you to manage the crash detection feature of add-on management in Internet Explorer. A crash report could contain sensitive information from the...Rule Medium Severity -
SRG-APP-000141
Group -
Turn on the auto-complete feature for user names and passwords on forms must be disabled.
This policy setting controls automatic completion of fields in forms on web pages. It is possible that malware could be developed which would be able to extract the cached user names and passwords ...Rule Medium Severity -
SRG-APP-000206
Group -
Managing SmartScreen Filter use must be enforced.
This setting is important from a security perspective because Microsoft has extensive data illustrating the positive impact the SmartScreen filter has had on reducing the risk of malware infection ...Rule Medium Severity -
SRG-APP-000089
Group -
Browser must retain history on exit.
Delete Browsing History on exit automatically deletes specified items when the last browser window closes. Disabling this function will prevent users from deleting their browsing history, which co...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.