Skip to content

No profile (default benchmark)

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Firefox must not recommend extensions as the user is using the browser.

    &lt;VulnDiscussion&gt;The Recommended Extensions program recommends extensions to users as they surf the web. The user must not be encouraged to i...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • The Firefox New Tab page must not show Top Sites, Sponsored Top Sites, Pocket Recommendations, Sponsored Pocket Stories, Searches, Highlights, or Snippets.

    &lt;VulnDiscussion&gt;The New Tab page by default shows a list of built-in top sites, as well as the top sites the user has visited. It is detrime...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Firefox must be configured so that DNS over HTTPS is disabled.

    &lt;VulnDiscussion&gt;DNS over HTTPS has generally not been adopted in the DoD. DNS is tightly controlled. It is detrimental for applications to p...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Firefox accounts must be disabled.

    &lt;VulnDiscussion&gt;Disable Firefox Accounts integration (Sync). It is detrimental for applications to provide, or install by default, function...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Firefox feedback reporting must be disabled.

    &lt;VulnDiscussion&gt;Disable the menus for reporting sites (Submit Feedback, Report Deceptive Site). It is detrimental for applications to provi...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Firefox encrypted media extensions must be disabled.

    &lt;VulnDiscussion&gt;Enable or disable Encrypted Media Extensions and optionally lock it. If "Enabled" is set to "false", Firefox does not downlo...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Firefox must be configured to not delete data upon shutdown.

    &lt;VulnDiscussion&gt;For diagnostic purposes, data must remain behind when the browser is closed. This is required to meet non-repudiation control...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Pocket must be disabled.

    &lt;VulnDiscussion&gt;Pocket, previously known as Read It Later, is a social bookmarking service for storing, sharing, and discovering web bookmark...
    Rule Medium Severity
  • SRG-APP-000141

    <GroupDescription></GroupDescription>
    Group
  • Firefox Studies must be disabled.

    &lt;VulnDiscussion&gt;Studies try out different features and ideas before they are released to all Firefox users. Testing beta software is not in t...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules