UCF STIG Viewer Logo

Do not provide Continue Option on Encryption Warning dialog box - Outlook.


Overview

Finding ID Version Rule ID IA Controls Severity
V-17604 DTOO261 - Outlook SV-18735r1_rule ECSC-1 Medium
Description
By default, if Outlook 2007 users see an encryption-related dialog box when attempting to send a message, they can choose to dismiss the warning and send the message anyway. If users send messages after seeing an encryption error, it is likely that recipients will not be able to read them.
STIG Date
Microsoft Outlook 2007 2015-09-17

Details

Check Text ( C-18906r1_chk )
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security

Criteria: If the value DisableContinueEncryption is REG_DWORD = 0, this is not a finding.
Fix Text (F-17522r1_fix)
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”.