Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • DTOO283 - Dwnld articles as HTML attachments

    <GroupDescription></GroupDescription>
    Group
  • Disabling download full text of articles as HTML must be configured.

    &lt;VulnDiscussion&gt;Many RSS feeds use messages that contain a brief summary of a larger message or an article with a link to the full content. U...
    Rule Medium Severity
  • DTOO277 - Links in Email Messages

    <GroupDescription></GroupDescription>
    Group
  • Hyperlinks in suspected phishing e-mail messages must be disallowed.

    &lt;VulnDiscussion&gt;Outlook's Junk E-mail Filter evaluates each incoming message for possible spam or phishing content. Suspicious message detect...
    Rule Medium Severity
  • DTOO279 - Enable RPC Encryption

    <GroupDescription></GroupDescription>
    Group
  • RPC encryption between Outlook and Exchange server must be enforced.

    &lt;VulnDiscussion&gt;The remote procedure call (RPC) communication channel between an Outlook client computer and an Exchange server is not encryp...
    Rule Medium Severity
  • DTOO221 - Junk Mail UI

    <GroupDescription></GroupDescription>
    Group
  • Junk Mail UI must be configured.

    &lt;VulnDiscussion&gt;The Junk E-mail Filter in Outlook is designed to intercept the most obvious junk e-mail, or spam, and send it to users' Junk ...
    Rule Medium Severity
  • DTOO274 - Internet with Safe Zones

    <GroupDescription></GroupDescription>
    Group
  • Internet with Safe Zones for Picture Download must be disabled.

    &lt;VulnDiscussion&gt;Malicious e-mail senders can send HTML e-mail messages with embedded Web beacons, which are pictures and other content from e...
    Rule Medium Severity
  • DTOO275 - Incl. Intranet with Safe Zone

    <GroupDescription></GroupDescription>
    Group
  • Intranet with Safe Zones for automatic picture downloads must be configured.

    &lt;VulnDiscussion&gt;Malicious e-mail senders can send HTML e-mail messages with embedded Web beacons, which are pictures and other content from e...
    Rule Medium Severity
  • DTOO240 - Level 1 Attachments

    <GroupDescription></GroupDescription>
    Group
  • The ability to display level 1 attachments must be disallowed.

    &lt;VulnDiscussion&gt;To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, t...
    Rule Medium Severity
  • DTOO270 - External Pictures &amp; content

    <GroupDescription></GroupDescription>
    Group
  • External content and pictures in HTML eMail must be displayed.

    &lt;VulnDiscussion&gt;Malicious email senders can send HTML email messages with embedded Web beacons, which are pictures and other content from ext...
    Rule Medium Severity
  • DTOO227 - Digital Signature handling

    <GroupDescription></GroupDescription>
    Group
  • Digital signatures must be allowed.

    &lt;VulnDiscussion&gt;Outlook users can create and use signatures in e-mail messages. Users can add signatures to messages manually, and can also c...
    Rule Medium Severity
  • DTOO230 - No fldr home pages / non-default stores

    <GroupDescription></GroupDescription>
    Group
  • Folders in non-default stores, set as folder home pages, must be disallowed.

    &lt;VulnDiscussion&gt;Outlook allows users to designate Web pages as home pages for personal or public folders. When a user clicks on a folder, Out...
    Rule Medium Severity
  • DTOO233 - OOM scripts for Public Folders

    <GroupDescription></GroupDescription>
    Group
  • Outlook Object Model scripts must be disallowed to run for public folders.

    &lt;VulnDiscussion&gt;In Outlook, folders can be associated with custom forms or folder home pages that include scripts that access the Outlook obj...
    Rule Medium Severity
  • DTOO232 - OOM scripts for Shared Folders

    <GroupDescription></GroupDescription>
    Group
  • Outlook Object Model scripts must be disallowed to run for shared folders.

    &lt;VulnDiscussion&gt;In Outlook, folders can be associated with custom forms or folder home pages that include scripts that access the Outlook obj...
    Rule Medium Severity
  • DTOO285 - Internet Calendar Integration

    <GroupDescription></GroupDescription>
    Group
  • Do not include Internet Calendar Integration in Outlook must be enforced.

    &lt;VulnDiscussion&gt;The Internet Calendar feature in Outlook enables users to publish calendars online (using the webcal:// protocol) and subscri...
    Rule Medium Severity
  • DTOO269 - Attachments to Secure Temporary Folder

    <GroupDescription></GroupDescription>
    Group
  • Attachments using generated name for secure temporary folders must be configured.

    &lt;VulnDiscussion&gt;The Secure Temporary Files folder is used to store attachments when they are opened in e-mail. By default, Outlook generates ...
    Rule Medium Severity
  • DTOO280 - Authentication w/Exchange Svr

    <GroupDescription></GroupDescription>
    Group
  • Authentication with Exchange Server must be required.

    &lt;VulnDiscussion&gt;Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more ...
    Rule Medium Severity
  • DTOO278 - Auto configure profile based on AD

    <GroupDescription></GroupDescription>
    Group
  • Automatically configure user profile based on Active Directory primary SMTP address must be enforced.

    &lt;VulnDiscussion&gt;If a user is joined to a domain in an Active Directory environment and does not have an e-mail account configured, Outlook po...
    Rule Medium Severity
  • DTOO284 - Auto download attachments Internet Cal

    <GroupDescription></GroupDescription>
    Group
  • Automatic download of Internet Calendar appointment attachments must be disallowed.

    &lt;VulnDiscussion&gt;Files attached to Internet Calendar appointments could contain malicious code that could be used to compromise a computer. By...
    Rule Medium Severity
  • DTOO271 - Auto Download from Safe lists

    <GroupDescription></GroupDescription>
    Group
  • Automatic download content for email in Safe Senders list must be disallowed.

    &lt;VulnDiscussion&gt;Malicious e-mail senders can send HTML e-mail messages with embedded Web beacons, or pictures and other content from external...
    Rule Medium Severity
  • DTOO229 - Make Outlook the default program

    <GroupDescription></GroupDescription>
    Group
  • Outlook must be enforced as the default email, calendar, and contacts program.

    &lt;VulnDiscussion&gt;Outlook is made the default program for E-mail, contacts, and calendar services when it is installed, although users can desi...
    Rule Medium Severity
  • DTOO260 - SMime message formats

    <GroupDescription></GroupDescription>
    Group
  • Message formats must be set to use SMime.

    &lt;VulnDiscussion&gt;E-mail typically travels over open networks and is passed from server to server. Messages are therefore vulnerable to interce...
    Rule Medium Severity
  • DTOO268 - Missing Root Certificates

    <GroupDescription></GroupDescription>
    Group
  • Missing Root Certificates warning must be enforced.

    &lt;VulnDiscussion&gt;When Outlook accesses a certificate, it validates that it can trust the certificate by examining the root certificate of the ...
    Rule Medium Severity
  • DTOO239 - Outlook Security Mode

    <GroupDescription></GroupDescription>
    Group
  • Outlook Security Mode must be configured to use Group Policy settings.

    &lt;VulnDiscussion&gt;If users can configure security themselves, they might choose levels of security that leave their computers vulnerable to att...
    Rule Medium Severity
  • DTOO228 - Plain Text Options

    <GroupDescription></GroupDescription>
    Group
  • Plain Text Options for outbound email must be configured.

    &lt;VulnDiscussion&gt;If outgoing mail is formatted in certain ways, for example if attachments are encoded in UUENCODE format, attackers might man...
    Rule Medium Severity
  • DTOO217 - Prevent publishing to DAV Servers

    <GroupDescription></GroupDescription>
    Group
  • Publishing to a Web Distributed and Authoring (DAV) server must be prevented.

    &lt;VulnDiscussion&gt;Outlook users can share their calendars with others by publishing them to a server that supports the World Wide Web Distribut...
    Rule Medium Severity
  • DTOO216 - Publishing to Office Online

    <GroupDescription></GroupDescription>
    Group
  • Publishing calendars to Office Online must be prevented.

    &lt;VulnDiscussion&gt;Outlook users can share their calendars with selected others by publishing them to the Microsoft Office Outlook Calendar Shar...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules