Skip to content

Mozilla Firefox STIG

Rules and Groups employed by this XCCDF Profile

  • Firefox

    Firefox is an open-source web browser and developed by Mozilla. Web browsers such as Firefox are used for a number of reasons. This section provides settings for configuring Firefox policies to mee...
    Group
  • Firefox must be configured to disable the installation of extensions.

    Addon installation may be disabled in an administrative policy by setting the InstallAddonsPermission key under policies to false.
    Rule Medium Severity
  • Firefox autoplay must be disabled.

    Audio/Video autoplay may be disabled in an administrative policy by setting the Default key under Permissions, Autoplay to "block-audio-video".
    Rule Medium Severity
  • Enabled Firefox Cryptomining protection

    Cryptomining protection may be enabled by setting privacy.trackingprotection.cryptomining.enabled to true.
    Rule Medium Severity
  • Disable Firefox Development Tools

    Firefox provides development tools which identify detailed information about the browser and its configuration. These details are often also recorded into a log file, giving an attacker the abili...
    Rule Low Severity
  • Disable Firefox deprecated ciphers

    Pocket may be disabled by setting TLS_RSA_WITH_3DES_EDE_CBC_SHA to true under DisabledCiphers in the policies file.
    Rule Medium Severity
  • Firefox must be configured to disable form fill assistance.

    The update check may be disabled in an administrative policy by setting the DisableFormHistory key under policies to true.
    Rule Medium Severity
  • Disable Firefox Pocket

    Pocket may be disabled by setting DisablePocket to true in the policies file.
    Rule Medium Severity
  • Disable Firefox Studies

    Pocket may be disabled by setting DisableFirefoxStudies to true in the policies file.
    Rule Medium Severity
  • Firefox must be configured so that DNS over HTTPS is disabled.

    DNS over HTTPS feature may be disabled via administrative policy by setting Enabled under DNSOverHTTPS to false.
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules