Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17762 | DTOO217 - Outlook | SV-18962r1_rule | ECSC-1 | Medium |
Description |
---|
By default, Outlook 2007 users can share their calendars with others by publishing them to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Unlike the Microsoft Office Online Calendar Sharing Service, which allows users to manage other people's access to their calendars, DAV access restrictions can only be accomplished through server and folder permissions, and might require the assistance of the server administrator to set up and maintain. If these permissions are not managed properly, unauthorized people could access sensitive information. |
STIG | Date |
---|---|
Microsoft Outlook 2007 | 2015-09-17 |
Check Text ( C-19025r1_chk ) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Prevent publishing to a DAV server” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal\ Criteria: If the value DisableDav is REG_DWORD = 1, this is not a finding. |
Fix Text (F-17661r1_fix) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service “Prevent publishing to a DAV server” will be set to “Enabled”. |