Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • DTOO226 - Dial-up Options

    <GroupDescription></GroupDescription>
    Group
  • Dial-up and Hang up Options for Outlook must be configured.

    &lt;VulnDiscussion&gt;By default, users can connect to their e-mail servers using dial-up networking if their accounts are configured appropriately...
    Rule Medium Severity
  • DTOO225 - Warn before Switching Dial-up

    <GroupDescription></GroupDescription>
    Group
  • Outlook Dial-up options to Warn user before allowing switch in dial-up access must be configured.

    &lt;VulnDiscussion&gt;Users can connect to their e-mail servers using dial-up networking if their accounts are configured appropriately. Dial-up co...
    Rule Medium Severity
  • DTOO237-Disable "remember password" on eMail Accts

    <GroupDescription></GroupDescription>
    Group
  • The "remember password" for internet e-mail accounts must be disabled.

    &lt;VulnDiscussion&gt;As a security precaution, password caching for eMail Internet protocols such as POP3 or IMAP may lead to password discovery a...
    Rule Medium Severity
  • DTOO243 - Level 1 Attachment prompt

    <GroupDescription></GroupDescription>
    Group
  • Level 1 attachment close behaviors must be configured.

    &lt;VulnDiscussion&gt;To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, t...
    Rule Medium Severity
  • DTOO242 - Level 1 Attachment Prompt on sending.

    <GroupDescription></GroupDescription>
    Group
  • Prompting behavior for Level 1 attachments on sending must be configured.

    &lt;VulnDiscussion&gt;To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, t...
    Rule Medium Severity
  • DTOO283 - Dwnld articles as HTML attachments

    <GroupDescription></GroupDescription>
    Group
  • Disabling download full text of articles as HTML must be configured.

    &lt;VulnDiscussion&gt;Many RSS feeds use messages that contain a brief summary of a larger message or an article with a link to the full content. U...
    Rule Medium Severity
  • DTOO277 - Links in Email Messages

    <GroupDescription></GroupDescription>
    Group
  • Hyperlinks in suspected phishing e-mail messages must be disallowed.

    &lt;VulnDiscussion&gt;Outlook's Junk E-mail Filter evaluates each incoming message for possible spam or phishing content. Suspicious message detect...
    Rule Medium Severity
  • DTOO279 - Enable RPC Encryption

    <GroupDescription></GroupDescription>
    Group
  • RPC encryption between Outlook and Exchange server must be enforced.

    &lt;VulnDiscussion&gt;The remote procedure call (RPC) communication channel between an Outlook client computer and an Exchange server is not encryp...
    Rule Medium Severity
  • DTOO221 - Junk Mail UI

    <GroupDescription></GroupDescription>
    Group
  • Junk Mail UI must be configured.

    &lt;VulnDiscussion&gt;The Junk E-mail Filter in Outlook is designed to intercept the most obvious junk e-mail, or spam, and send it to users' Junk ...
    Rule Medium Severity
  • DTOO274 - Internet with Safe Zones

    <GroupDescription></GroupDescription>
    Group
  • Internet with Safe Zones for Picture Download must be disabled.

    &lt;VulnDiscussion&gt;Malicious e-mail senders can send HTML e-mail messages with embedded Web beacons, which are pictures and other content from e...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules