II - Mission Support Sensitive
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000039
Group -
Dragging of content from different domains within a window must be disallowed (Restricted Sites zone).
This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window. If you enable this policy setting, u...Rule Medium Severity -
SRG-APP-000207
Group -
Anti-Malware programs against ActiveX controls must be run for the Internet zone.
This policy setting determines whether Internet Explorer runs Anti-Malware programs against ActiveX controls, to check if they're safe to load on pages. If you enable this policy setting, Inte...Rule Medium Severity -
SRG-APP-000207
Group -
Anti-Malware programs against ActiveX controls must be run for the Restricted Sites zone.
This policy setting determines whether Internet Explorer runs Anti-Malware programs against ActiveX controls, to check if they're safe to load on pages. If you enable this policy setting, Inte...Rule Medium Severity -
SRG-APP-000278
Group -
Prevent bypassing SmartScreen Filter warnings must be enabled.
This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter prevents the user from browsing to or downloading from sites that are known to host m...Rule Medium Severity -
SRG-APP-000209
Group -
Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the internet must be enabled.
This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter warns the user about executable files that Internet Explorer users do not commonly do...Rule Medium Severity -
SRG-APP-000210
Group -
Prevent per-user installation of ActiveX controls must be enabled.
This policy setting allows you to prevent the installation of ActiveX controls on a per-user basis. If you enable this policy setting, ActiveX controls cannot be installed on a per-user basis. If y...Rule Medium Severity -
SRG-APP-000427
Group -
Prevent ignoring certificate errors option must be enabled.
This policy setting prevents the user from ignoring Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate errors that interrupt browsing (such as “expired”, “revoked”, or “name mismat...Rule Medium Severity -
SRG-APP-000278
Group -
Turn on SmartScreen Filter scan option for the Internet Zone must be enabled.
This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content. If you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious ...Rule Medium Severity -
SRG-APP-000278
Group -
Turn on SmartScreen Filter scan option for the Restricted Sites Zone must be enabled.
This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content. If you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious ...Rule Medium Severity -
SRG-APP-000210
Group -
The Initialize and script ActiveX controls not marked as safe must be disallowed (Intranet Zone).
ActiveX controls that are not marked safe for scripting should not be executed. Although this is not a complete security measure for a control to be marked safe for scripting, if a control is not m...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.