Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000141

    Group
  • Scripting of Internet Explorer WebBrowser Control must be disallowed (Restricted Sites zone).

    This policy setting controls whether a page may control embedded WebBrowser Control via script. Scripted code hosted on sites located in this zone is more likely to contain malicious code. If you e...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • When uploading files to a server, the local directory path must be excluded (Restricted Sites zone).

    This policy setting controls whether or not the local path information will be sent when uploading a file via a HTML form. If the local path information is sent, some information may be unintention...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • Security Warning for unsafe files must be disallowed (Restricted Sites zone).

    This policy setting controls whether or not the 'Open File - Security Warning' message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file ...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • ActiveX controls without prompt property must be used in approved domains only (Restricted Sites zone).

    This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on websites other than the website that installed the ActiveX control. If the user were to disable ...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Cross-Site Scripting Filter property must be enforced (Restricted Sites zone).

    The Cross-Site Scripting Filter is designed to prevent users from becoming victims of unintentional information disclosure. This setting controls if the Cross-Site Scripting (XSS) Filter detects an...
    Rule Medium Severity
  • SRG-APP-000112

    Group
  • Internet Explorer Processes Restrict ActiveX Install must be enforced (Reserved).

    Users often choose to install software such as ActiveX controls that are not permitted by their organization's security policy. Such software can pose significant security and privacy risks to netw...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Status bar updates via script must be disallowed (Internet zone).

    This policy setting allows you to manage whether script is allowed to update the status bar within the zone. A script running in the zone could cause false information to be displayed on the status...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • .NET Framework-reliant components not signed with Authenticode must be disallowed to run (Internet zone).

    Unsigned components are more likely to contain malicious code and it is more difficult to determine the author of the application - therefore they should be avoided if possible. This policy setting...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • .NET Framework-reliant components signed with Authenticode must be disallowed to run (Internet zone).

    It may be possible for someone to host malicious content on a website that takes advantage of these components. This policy setting allows you to manage whether .NET Framework components that are s...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Scriptlets must be disallowed (Restricted Sites zone).

    This policy setting allows you to manage whether scriptlets can be allowed. Scriptlets hosted on sites located in this zone are more likely to contain malicious code. If you enable this policy sett...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules