Skip to content

Mozilla Firefox STIG

Rules and Groups employed by this XCCDF Profile

  • Firefox encrypted media extensions must be disabled.

    Firefox's Encrypted Media Extensions support playback of media content that is subject to Digital Right Management. These extensions may be disable...
    Rule Medium Severity
  • Enabled Firefox Enhanced Tracking Protection

    Enhanced Tracking Protection may be enabled by setting browser.contentblocking.category to strict.
    Rule Medium Severity
  • Disabled Firefox Extension Recommendations

    Extension recommendations may be disabled by setting <code>extensions.htmlaboutaddons.recommendations.enabled</code> to <code>false</code> in the p...
    Rule Medium Severity
  • Firefox must be configured to not automatically update installed add-ons and plugins.

    Firefox has a feature to permit installed add-ons and plugins to automatically update. The check may be disabled in an administrative policy by set...
    Rule Medium Severity
  • Firefox feedback reporting must be disabled.

    Feedback reporting feature may be disabled via administrative policy by setting <code>DisableFeedbackCommands</code> under <code>policies</code> to...
    Rule Medium Severity
  • Enabled Firefox Fingerprinting Protection

    Fingerprinting protection may be enabled by setting <code>Fingerprinting</code> to <code>true</code> under <code>EnableTrackingProtection</code> in...
    Rule Medium Severity
  • Firefox must prevent the user from quickly deleting data.

    The update check may be disabled in an administrative policy by setting the <code>DisableForgetButton</code> key under <code>policies</code> to <co...
    Rule Medium Severity
  • Disable JavaScript's Raise Or Lower Windows Capability

    JavaScript can configure and make changes to the web browser's appearance by specifically raising and lowering windows. This can be disabled by set...
    Rule Medium Severity
  • Disable JavaScript's Moving Or Resizing Windows Capability

    JavaScript can configure and make changes to the web browser's appearance by specifically moving and resizing browser windows. This can be disabled...
    Rule Medium Severity
  • Disable Firefox network prediction

    Firefox has a feature where it predicts and caches DNS requests. This can be disabled by setting <code>NetworkPrediction</code> to <code>true</code...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules