III - Administrative Classified
Rules and Groups employed by this XCCDF Profile
-
DTOO168 - Sending templates with email form
Group -
Disabling sending form templates with the email forms must be configured.
InfoPath allows users to attach form templates when sending email forms. If users are able to open form templates included with email forms, rather than using a cached version that is previously pu...Rule Medium Severity -
DTOO170 - 2003 forms as email
Group -
InfoPath 2003 forms as email forms in InfoPath 2013 must be disallowed.
An attacker might target InfoPath 2003 forms to try and compromise an organization's security. InfoPath 2003 did not write a published location for email forms, which means forms could open without...Rule Medium Severity -
DTOO164 - Beaconing UI / forms opening
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules