III - Administrative Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Scripting of Internet Explorer WebBrowser Control must be disallowed (Restricted Sites zone).
<VulnDiscussion>This policy setting controls whether a page may control embedded WebBrowser Control via script. Scripted code hosted on sites...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
When uploading files to a server, the local directory path must be excluded (Restricted Sites zone).
<VulnDiscussion>This policy setting controls whether or not the local path information will be sent when uploading a file via a HTML form. If...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
Security Warning for unsafe files must be disallowed (Restricted Sites zone).
<VulnDiscussion>This policy setting controls whether or not the 'Open File - Security Warning' message appears when the user tries to open ex...Rule Medium Severity -
SRG-APP-000210
<GroupDescription></GroupDescription>Group -
ActiveX controls without prompt property must be used in approved domains only (Restricted Sites zone).
<VulnDiscussion>This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on websites other than the ...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Cross-Site Scripting Filter property must be enforced (Restricted Sites zone).
<VulnDiscussion>The Cross-Site Scripting Filter is designed to prevent users from becoming victims of unintentional information disclosure. T...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.