Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17604 | DTOO261 - Outlook | SV-18735r1_rule | ECSC-1 | Medium |
Description |
---|
By default, if Outlook 2007 users see an encryption-related dialog box when attempting to send a message, they can choose to dismiss the warning and send the message anyway. If users send messages after seeing an encryption error, it is likely that recipients will not be able to read them. |
STIG | Date |
---|---|
Microsoft Outlook 2007 | 2015-09-17 |
Check Text ( C-18906r1_chk ) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value DisableContinueEncryption is REG_DWORD = 0, this is not a finding. |
Fix Text (F-17522r1_fix) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”. |