| NaN |
Version: 5.20120314 |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
| CCE ID |
CCE Description |
CCE Parameters |
CCE Technical Mechanisms |
NaN |
Old v4 CCE ID |
NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml) |
NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml |
FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml) |
FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml |
USGCB XCCDF (USGCB-Windows-ie7-xccdf) |
USGCB OVAL (USGCB-Windows-ie7-oval) |
| CCE-4017-0 |
The "Security Zones: Use Only Machine Settings" setting should be configured correctly. |
enabled/disabled |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Use_HKLM_only Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only |
NaN |
CCE-5 |
oval:org.mitre.oval:def:1277, oval:org.mitre.oval:def:2050 |
UseOnlyMachineSettings-LocalComputer, UseOnlyMachineSettings-LocalComputer-Disabled |
use_only_machine_settings_local_computer |
oval:gov.nist.fdcc.ie7:def:1277 |
NaN |
NaN |
| CCE-3924-8 |
Internet Explorer Processes (Restrict ActiveX Install) |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\(Reserved) HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\explorer.exe HKLM\Software\Policies\ Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict ActiveX Install Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\iexplore.exe |
NaN |
CCE-119 |
oval:org.mitre.oval:def:658 |
IEProcesses-RestrictActiveXInstall-LocalComputer |
IEProcesses_RestrictActiveXInstall_LocalComputer |
oval:gov.nist.fdcc.ie7:def:658 |
NaN |
NaN |
| CCE-3929-7 |
The "Security Zones: Do Not Allow Users to Add/Delete Sites" setting should be configured correctly. |
enabled/disabled |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_Zones_Map_Edit Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_zones_map_edit |
NaN |
CCE-146 |
oval:org.mitre.oval:def:1400 |
DoNotAllowUsersAddDeleteSites-LocalComputer |
DoNotAllowUsersAddDeleteSites_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1400 |
NaN |
NaN |
| CCE-3576-6 |
The "Disable Periodic Check For Internet Explorer Software Updates" setting should be configured correctly. |
enabled/disabled |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoUpdateCheck Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoUpdateCheck |
NaN |
CCE-212 |
oval:org.mitre.oval:def:1357 |
DisablePeriodicCheckForIESoftwareUpdates-LocalComputer |
DisablePeriodicCheckForIESoftwareUpdates_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1357 |
NaN |
NaN |
| CCE-4043-6 |
Internet Explorer Processes (Zone Elevation Protection) |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\(Reserved) HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\explorer.exe HKLM\Software\Policies\Microsoft\Internet Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Protection From Zone Elevation Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\iexplore.exe |
NaN |
CCE-347 |
oval:org.mitre.oval:def:620 |
NaN |
IEProcesses_ProtectionFromZoneElevation_LocalComputer |
oval:gov.nist.fdcc.ie7:def:620 |
NaN |
NaN |
| CCE-4047-7 |
The "Internet Explorer Processes (Consistent MIME Handling)" setting should be configured correctly. |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Reserved) HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\explorer.exe HKLM\Software\Policies\Microsoft\Internet E Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Binary Behavior Security Restriction Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\iexplore.exe |
NaN |
CCE-382 |
oval:org.mitre.oval:def:884 |
IEProcesses-ConsistentMimeHandling-LocalComputer |
IEProcesses_ConsistentMimeHandling_LocalComputer |
oval:gov.nist.fdcc.ie7:def:884 |
NaN |
NaN |
| CCE-3941-2 |
The "Allow Software to Run or Install Even if the Signature is Invalid" setting should be configured correctly. |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Download\RunInvalidSignatures Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Download\RunInvalidSignatures |
NaN |
CCE-449 |
oval:org.mitre.oval:def:680, oval:org.mitre.oval:def:1392 |
AllowSoftwareRunInstallSignatureInvalid-LocalComputer, AllowSoftwareToRununOrInstallEvenIfSignatureInvalid-LocalUser |
AllowSoftwareRunInstallSignatureInvalid_LocalComputer |
oval:gov.nist.fdcc.ie7:def:680 |
NaN |
NaN |
| CCE-3338-1 |
The "Internet Explorer Processes (MK Protocol)" setting should be configured correctly. |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved) HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\explorer.exe HKLM\Software\Policies\Microsoft Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/MK Protocol Security Restriction Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\iexplore.exe |
NaN |
CCE-591 |
oval:org.mitre.oval:def:617 |
IEProcesses-MKProtocolSecurityRestriction-LocalComputer |
IEProcesses_MKProtocolSecurityRestriction_LocalComputer |
oval:gov.nist.fdcc.ie7:def:617 |
NaN |
NaN |
| CCE-4118-6 |
The "Disable Software Update Shell Notifications on Program Launch" setting should be configured correctly. |
enabled/disabled |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoMSAppLogo5ChannelNotify Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict File Download Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe |
NaN |
CCE-622 |
oval:org.mitre.oval:def:1188 |
DisableSoftwareUpdateShellNotifications-LocalComputer |
DisableSoftwareUpdateShellNotifications_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1188 |
NaN |
NaN |
| CCE-4122-8 |
The "Internet Explorer Processes (Restrict File Download)" setting should be configured correctly. |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved) HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict File Download Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe |
NaN |
CCE-668 |
oval:org.mitre.oval:def:320 |
IEProcesses-RestrictFileDownload-LocalComputer |
IEProcesses_RestrictFileDownload_LocalComputer |
oval:gov.nist.fdcc.ie7:def:320 |
NaN |
NaN |
| CCE-3518-8 |
The "Disable Automatic Install of Internet Explorer Components" setting should be configured correctly. |
enabled/disabled |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoJITSetup Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoJITSetup |
NaN |
CCE-684 |
oval:org.mitre.oval:def:1198 |
DisableAutomaticInstallOfIEComponents-LocalComputer |
DisableAutomaticInstallOfIEComponents_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1198 |
NaN |
NaN |
| CCE-3201-1 |
The "Make Proxy Settings Per-Machine (Rather Then Per-User)" setting should be configured correctly. |
number of proxy settings |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser |
NaN |
CCE-693 |
oval:org.mitre.oval:def:1181 |
MakeProxySettingsPerMachine-LocalComputer |
MakeProxySettingsPerMachine_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1181 |
NaN |
NaN |
| CCE-3744-0 |
The "Do Not Allow Users to enable or Disable Add-Ons" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoExtensionManagement |
NaN |
CCE-708 |
oval:org.mitre.oval:def:1380, oval:org.mitre.oval:def:1358, oval:org.mitre.oval:def:1694 |
DoNotAllowUsersEnableDisableAddOns-LocalComputer, DoNotAllowUsersEnableDisableAddOns-LocalUser |
DoNotAllowUsersEnableDisableAddOns_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1694 |
NaN |
NaN |
| CCE-3894-3 |
The "Turn Off Crash Detection" setting should be configured correctly. |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoCrashDetection Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoCrashDetection |
NaN |
CCE-753 |
oval:org.mitre.oval:def:487 |
TurnOffCrashDetection-LocalComputer |
TurnOffCrashDetection_LocalComputer |
oval:gov.nist.fdcc.ie7:def:487 |
NaN |
NaN |
| CCE-4162-4 |
The "Internet Explorer Processes (Scripted Window Security Restrictions)" setting should be configured correctly. |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\(Reserved) HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\explorer.exe Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Scripted Window Security Restrictions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\iexplore.exe |
NaN |
CCE-827 |
oval:org.mitre.oval:def:465 |
IEProcesses-ScriptedWindowSecurityRestrictions-LocalComputer |
IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer |
oval:gov.nist.fdcc.ie7:def:465 |
NaN |
NaN |
| CCE-3933-9 |
The "Security Zones: Do Not Allow Users to Change Policies" setting should be configured correctly. |
enabled/disabled |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit |
NaN |
CCE-833 |
oval:org.mitre.oval:def:1404 |
DoNotAllowUsersChangePolicies-LocalComputer |
DoNotAllowUsersChangePolicies_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1404 |
NaN |
NaN |
| CCE-4149-1 |
The "Internet Explorer Processes (MIME Sniffing)" setting should be configured correctly. |
enabled/disabled |
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\(Reserved) HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\explorer.exe Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Mime Sniffing Safety Feature Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\(Reserved) [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\explorer.exe [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\iexplore.exe |
NaN |
CCE-985 |
oval:org.mitre.oval:def:317 |
IEProcesses-MimeSniffingSafetyFeature-LocalComputer |
IEProcesses_MimeSniffingSafetyFeature_LocalComputer |
oval:gov.nist.fdcc.ie7:def:317 |
NaN |
NaN |
| CCE-4026-1 |
The "Check for Signature on Downloaded Programs" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Download\CheckExeSignatures |
NaN |
CCE-1025 |
oval:org.mitre.oval:def:395 |
CheckSignatureDownloadedPrograms-LocalComputer |
CheckSignatureDownloadedPrograms_LocalComputer |
oval:gov.nist.fdcc.ie7:def:395 |
NaN |
NaN |
| CCE-4171-5 |
The "Do Not Allow Resetting Internet Explorer Settings" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableRIED |
NaN |
CCE-42 |
oval:org.mitre.oval:def:583 |
DoNotAllowResettingIESettings-LocalComputer |
DoNotAllowResettingIESettings_LocalComputer |
oval:gov.nist.fdcc.ie7:def:583 |
NaN |
NaN |
| CCE-4109-5 |
The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1407 |
NaN |
CCE-49 |
oval:org.mitre.oval:def:506, oval:org.mitre.oval:def:533 |
AllowCutCopyPasteOperationsFromClipboardViaScript-InternetZone-LocalComputer, AllowCutCopyPasteOperationsFromClipboardViaScript-InternetZone-LocalUser |
allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:506 |
NaN |
NaN |
| CCE-3378-7 |
The "Turn Off First- Run Opt-In" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208 |
NaN |
CCE-863 |
oval:org.mitre.oval:def:1119 |
TurnOffFirst-RunOpt-In-InternetZone-LocalComputer |
TurnOffFirstRunOptIn_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1119 |
NaN |
NaN |
| CCE-4131-9 |
The "Web Browser Applications" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2400 |
NaN |
CCE-286 |
oval:org.mitre.oval:def:242 |
WebBrowserApplications-InternetZone-LocalComputer |
WebBrowserApplications_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:242 |
NaN |
NaN |
| CCE-4013-9 |
The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1407 |
NaN |
CCE-1031 |
oval:org.mitre.oval:def:249, oval:org.mitre.oval:def:1393 |
AllowCutCopyPasteOperationsFromClipboardViaScript-RestrictedSitesZone-LocalComputer, AllowCutCopyPasteOperationsFromClipboardViaScript-RestrictedSitesZone-LocalUser |
AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:249 |
NaN |
NaN |
| CCE-4153-3 |
The "Turn Off First- Run Opt-In" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1208 |
NaN |
CCE-200 |
oval:org.mitre.oval:def:621 |
TurnOffFirst-RunOpt-In-RestrictedSitesZone-LocalComputer |
TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:621 |
NaN |
NaN |
| CCE-4052-7 |
The "Web Browser Applications" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2400 |
NaN |
CCE-51 |
oval:org.mitre.oval:def:580 |
WebBrowserApplications-RestrictedSitesZone-LocalComputer |
WebBrowserApplications_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:580 |
NaN |
NaN |
| CCE-4175-6 |
The "Intranet Sites: Include all network paths (UNCs)" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet |
NaN |
CCE-876 |
oval:org.mitre.oval:def:559, oval:org.mitre.oval:def:1370 |
IncludeAllNetworkPaths-LocalComputer, IncludeAllNetworkPaths-LocalUser |
include_all_network_paths_local_computer |
oval:gov.nist.fdcc.ie7:def:559 |
NaN |
NaN |
| CCE-3695-4 |
The "Disable the Advanced Page" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\AdvancedTab |
NaN |
CCE-810 |
oval:org.mitre.oval:def:934, oval:org.mitre.oval:def:660 |
DisableTheAdvancedPage-LocalComputer, DisableTheAdvancedPage-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3777-0 |
The "Disable the Privacy Page" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\PrivacyTab |
NaN |
CCE-811 |
oval:org.mitre.oval:def:1111 |
DisableThePrivacyPage-LocalComputer |
NaN |
NaN |
NaN |
NaN |
| CCE-3433-0 |
The "Disable the Security Page" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab |
NaN |
CCE-595 |
oval:org.mitre.oval:def:672, oval:org.mitre.oval:def:601 |
DisableTheSecurityPage-LocalComputer, DisableTheSecurityPage-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-4199-6 |
The "Prevent Ignoing Certificate Errors" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\PreventIgnoreCertErrors |
NaN |
CCE-938 |
oval:org.mitre.oval:def:655, oval:org.mitre.oval:def:1129 |
PreventIgnoingCertificateErrors-LocalComputer, PreventIgnoingCertificateErrors-LocalUser |
prevent_ignoring_certificate_errors_local_computer |
oval:gov.nist.fdcc.ie7:def:655 |
NaN |
NaN |
| CCE-3204-5 |
The "Turn Off changing the URL to be displayed for checking updates to Internet Explorer and Internet Tools" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Internet Settings/Component Updates/Periodic Check for Updates to Internet Explorer and Internet Tools Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Page |
NaN |
CCE-946 |
oval:org.mitre.oval:def:715 |
TurnOffChangingURLDisplay-LocalComputer |
TurnOffChangingURLDisplay_LocalComputer |
oval:gov.nist.fdcc.ie7:def:715 |
NaN |
NaN |
| CCE-4098-0 |
The "Turn Off Configuring the Update Check Interval (In Days)" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Internet Settings/Component Updates/Periodic Check for Updates to Internet Explorer and Internet Tools Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Interval |
NaN |
CCE-237 |
oval:org.mitre.oval:def:1187 |
TurnOffConfiguringUpdateCheckInterval-LocalComputer |
TurnOffConfiguringUpdateCheckInterval_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1187 |
NaN |
NaN |
| CCE-3741-6 |
The "Add-on List" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Add-on Management Registry Keys:[HKLM | HKCU]\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\ListBox_Support_CLSID |
NaN |
CCE-541 |
oval:org.mitre.oval:def:626 |
AddOnList-LocalComputer |
NaN |
NaN |
NaN |
NaN |
| CCE-3997-4 |
The "Deny all add-ons unless specifically allowed in the Add-on List" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Add-on Management Registry Keys:[HKLM | HKCU]\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\RestrictToList |
NaN |
CCE-911 |
oval:org.mitre.oval:def:1278 |
DenyAllAddOns-LocalComputer |
NaN |
NaN |
NaN |
NaN |
| CCE-4001-4 |
The "Disable "Configuring History"" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\History [HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep |
NaN |
CCE-66 |
oval:org.mitre.oval:def:757, oval:org.mitre.oval:def:1365 |
DisableConfiguringHistory-LocalComputer, DisableConfiguringHistory-LocalUser |
DisableConfiguringHistory_LocalComputer |
oval:gov.nist.fdcc.ie7:def:757 |
NaN |
NaN |
| CCE-4147-5 |
The "Disable Changing Automatic Configuration Settings" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Autoconfig |
NaN |
CCE-471 |
oval:org.mitre.oval:def:1285, oval:org.mitre.oval:def:613 |
DisableChangingAutomaticConfigurationSettings-LocalComputer, DisableChangingAutomaticConfigurationSettings-LocalUser |
DisableChangingAutomaticConfigurationSettings_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1285 |
NaN |
NaN |
| CCE-4059-2 |
The "Disable Changing Connection Settings" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connection Settings [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock |
NaN |
CCE-611 |
oval:org.mitre.oval:def:355, oval:org.mitre.oval:def:1128 |
DisableChangingConnectionSettings-LocalComputer, DisableChangingConnectionSettings-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3935-4 |
The "Disable Changing Proxy Settings" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Proxy |
NaN |
CCE-62 |
oval:org.mitre.oval:def:398, oval:org.mitre.oval:def:635 |
DisableChangingProxySettings-LocalComputer, DisableChangingProxySettings-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3706-9 |
The "Disable Showing the Splash Screen" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoSplash |
NaN |
CCE-556 |
oval:org.mitre.oval:def:1164 |
DisableShowingSplashScreen-LocalComputer |
DisableShowingSplashScreen_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1164 |
NaN |
NaN |
| CCE-3975-0 |
The "Prevent "Fix settings" Functionality" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings |
NaN |
CCE-948 |
oval:org.mitre.oval:def:448, oval:org.mitre.oval:def:640 |
PreventFixSettingsFunctionality-LocalComputer, PreventFixSettingsFunctionality-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3993-3 |
The "Prevent participation in the Customer Experience Improvement Programs" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\SQM\DisableCustomerImprovementProgram |
NaN |
CCE-495 |
oval:org.mitre.oval:def:1171, oval:org.mitre.oval:def:1391 |
PreventParticipationInCustomerExperienceImprovementPrograms-LocalComputer, PreventParticipationInCustomerExperienceImprovementPrograms-LocalUser |
PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1171 |
NaN |
NaN |
| CCE-3207-8 |
The "Prevent performance of First Run Customize settings" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\DisableFirstRunCustomize |
NaN |
CCE-1006 |
oval:org.mitre.oval:def:1322 |
PreventPerformanceOfFirstRunCustomizeSettings-LocalComputer |
PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1322 |
NaN |
NaN |
| CCE-4073-3 |
The "Prevent the deletation of temporary internet files and cookies" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Settings |
NaN |
CCE-909 |
oval:org.mitre.oval:def:1382, oval:org.mitre.oval:def:703 |
PerventDeletationOfTempInternetFiles-LocalComputer, PerventDeletationOfTempInternetFiles-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3615-2 |
The "Turn off "Delete Browsing History" functionality" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableDeleteBrowsingHistory |
NaN |
CCE-1010 |
oval:org.mitre.oval:def:458, oval:org.mitre.oval:def:1474 |
TurnOffDeleteBrowsingHistoryFunctionality-LocalComputer, TurnOffDeleteBrowsingHistoryFunctionality-LocalUser |
TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer |
oval:gov.nist.fdcc.ie7:def:458 |
NaN |
NaN |
| CCE-3866-1 |
The "Turn off Managing Phishing Filter" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\Enabled |
NaN |
CCE-1032 |
oval:org.mitre.oval:def:501 |
TurnOffManagingPhishingFilter-LocalComputer |
TurnOffManagingPhishingFilter_LocalComputer |
oval:gov.nist.fdcc.ie7:def:501 |
NaN |
NaN |
| CCE-3875-2 |
The "Turn off the Security Settings Check feature" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck |
NaN |
CCE-1054 |
oval:org.mitre.oval:def:916, oval:org.mitre.oval:def:1034 |
TurnOffSecuritySettingsCheckFeature-LocalComputer, TurnOffSecuritySettingsCheckFeature-LocalUser |
TurnOffSecuritySettingsCheckFeature_LocalComputer |
oval:gov.nist.fdcc.ie7:def:916 |
NaN |
NaN |
| CCE-4174-9 |
The "Allow Active Content from CD's to Run on User Machine" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCAL |
NaN |
CCE-964 |
oval:org.mitre.oval:def:400 |
AllowActiveContentFromCD-LocalComputer |
AllowActiveContentFromCD_LocalComputer |
oval:gov.nist.fdcc.ie7:def:400 |
NaN |
NaN |
| CCE-4192-1 |
The "Enable third-party browser extensions" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Enable Browser Extensions |
NaN |
CCE-598 |
oval:org.mitre.oval:def:110 |
AllowThird-PartyBrowserExtensions-LocalComputer |
AllowThird-PartyBrowserExtensions_LocalComputer |
oval:gov.nist.fdcc.ie7:def:110 |
NaN |
NaN |
| CCE-3584-0 |
The "Automatically Check for Internet Explorer Updates" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\NoUpdateCheck |
NaN |
CCE-1008 |
oval:org.mitre.oval:def:656, oval:org.mitre.oval:def:1360 |
AutomaticallyCheckIEUpdates-LocalComputer, AutomaticallyCheckForIEUpdates-LocalUser |
AutomaticallyCheckIEUpdates_LocalComputer |
oval:gov.nist.fdcc.ie7:def:656 |
NaN |
NaN |
| CCE-3976-8 |
The "Check for Server Certificate Revocation" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation |
NaN |
CCE-690 |
oval:org.mitre.oval:def:172, oval:org.mitre.oval:def:1502 |
CheckServerCertificateRevocation-LocalComputer, CheckForServerCertificateRevocation-LocalUser |
CheckServerCertificateRevocation_LocalComputer |
oval:gov.nist.fdcc.ie7:def:172 |
NaN |
NaN |
| CCE-3853-9 |
The "Access data sources across domains" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406 |
NaN |
CCE-47 |
oval:org.mitre.oval:def:674, oval:org.mitre.oval:def:650 |
AccessDataSourcesAcrossDomains-InternetZone-LocalComputer, AccessDataSourcesAcrossDomains-InternetZone-LocalUser |
access_data_sources_across_domains_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:674 |
NaN |
NaN |
| CCE-3998-2 |
The "Drag and drop or copy and paste files" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1802 |
NaN |
CCE-685 |
oval:org.mitre.oval:def:1083, oval:org.mitre.oval:def:547 |
AllowDragDropOrCopyPasteFiles-InternetZone-LocalComputer, AllowDragDropOrCopyPasteFiles-InternetZone-LocalUser |
AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1083 |
NaN |
NaN |
| CCE-3888-5 |
The "Font download" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1604 |
NaN |
CCE-491 |
oval:org.mitre.oval:def:524, oval:org.mitre.oval:def:659 |
AllowFontDownloads-InternetZone-LocalComputer, AllowFontDownloads-InternetZone-LocalUser |
AllowFontDownloads_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:524 |
NaN |
NaN |
| CCE-3906-5 |
The "Installation of desktop items" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1800 |
NaN |
CCE-355 |
oval:org.mitre.oval:def:223, oval:org.mitre.oval:def:541 |
AllowInstallationOfDesktopItems-InternetZone-LocalComputer, AllowInstallationOfDesktopItems-InternetZone-LocalUser |
AllowInstallationOfDesktopItems_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:223 |
NaN |
NaN |
| CCE-4099-8 |
The "Allow script-initiated windows without size or position constraints" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2102 |
NaN |
CCE-280 |
oval:org.mitre.oval:def:589, oval:org.mitre.oval:def:1476 |
AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-InternetZone-LocalComputer, AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-InternetZone-LocalUser |
AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:589 |
NaN |
NaN |
| CCE-3601-2 |
The "Allow Scriptlets" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1209 |
NaN |
CCE-439 |
oval:org.mitre.oval:def:1043 |
AllowScriptlets-InternetZone-LocalComputer |
allow_scriptlets_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1043 |
NaN |
NaN |
| CCE-3249-0 |
The "Allow status bar updates via script" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103 |
NaN |
CCE-914 |
oval:org.mitre.oval:def:226, oval:org.mitre.oval:def:1208 |
AllowStatusBarUpdatesViaScript-InternetZone-LocalComputer, AllowStatusBarUpdatesViaScript-InternetZone-LocalUser |
allow_status_bar_updates_via_script_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:226 |
NaN |
NaN |
| CCE-4139-2 |
The "Automatic prompting for file downloads" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2200 |
NaN |
CCE-16 |
oval:org.mitre.oval:def:1113, oval:org.mitre.oval:def:562 |
AutomaticPromptingFileDownloads-InternetZone-LocalComputer, AutomaticPromptingFileDownloads-InternetZone-LocalUser |
AutomaticPromptingFileDownloads_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1113 |
NaN |
NaN |
| CCE-3927-1 |
The "Download signed ActiveX controls" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1001 |
NaN |
CCE-1013 |
oval:org.mitre.oval:def:1199, oval:org.mitre.oval:def:546 |
DownloadSignedActiveXControls-InternetZone-LocalComputer, DownloadSignedActiveXControls-InternetZone-LocalUser |
download_signed_activex_controls_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1199 |
NaN |
NaN |
| CCE-3945-3 |
The "Download unsigned ActiveX controls" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1004 |
NaN |
CCE-176 |
oval:org.mitre.oval:def:391, oval:org.mitre.oval:def:1200 |
DownloadUnsignedActiveXControls-InternetZone-LocalComputer, DownloadUnsignedActiveXControls-InternetZone-LocalUser |
DownloadUnsignedActiveXControls_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:391 |
NaN |
NaN |
| CCE-4068-3 |
The "Initialize and script ActiveX controls not marked as safe for scripting" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1201 |
NaN |
CCE-586 |
oval:org.mitre.oval:def:1040, oval:org.mitre.oval:def:739 |
InitializeScriptActiveXControlsNotMarkedAsSafe-InternetZone-LocalComputer, JavaPermissions-InternetZone-LocalComputer, InitializeScriptActiveXControlsNotMarkedAsSafe-InternetZone-LocalUser |
InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1040 |
NaN |
NaN |
| CCE-3963-6 |
The "Java permissions" setting should be configured correctly for the Internet Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1C00 |
NaN |
CCE-132 |
oval:org.mitre.oval:def:1174, oval:org.mitre.oval:def:725 |
JavaPermissions-InternetZone-LocalUser |
java_permissions_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1174 |
NaN |
NaN |
| CCE-4104-6 |
The "Launching programs and files in an IFRAME" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1804 |
NaN |
CCE-689 |
oval:org.mitre.oval:def:611, oval:org.mitre.oval:def:1487 |
LaunchingApplicationsAndFilesInIFRAME-InternetZone-LocalComputer, LaunchingApplicationsAndFilesInIFRAME-InternetZone-LocalUser |
LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:611 |
NaN |
NaN |
| CCE-3623-6 |
The "Logon" setting should be configured correctly for the Internet Zone. |
Anonymous logon/Automatic logon only in Intranet zone/Automatic logon with current user name and password/Prompt for user name and password |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00 |
NaN |
CCE-720 |
oval:org.mitre.oval:def:691, oval:org.mitre.oval:def:1123 |
LogonOptions-InternetZone-LocalComputer, LogonOptions-InternetZone-LocalUser |
LogonOptions_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:691 |
NaN |
NaN |
| CCE-3751-5 |
The "Loose XAML" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2402 |
NaN |
CCE-126 |
oval:org.mitre.oval:def:240 |
LooseXAMLFiles-InternetZone-LocalComputer |
LooseXAMLFiles_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:240 |
NaN |
NaN |
| CCE-4143-4 |
The "Navigate sub-frames across different domains" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1607 |
NaN |
CCE-245 |
oval:org.mitre.oval:def:612, oval:org.mitre.oval:def:1394 |
NavigateSub-framesAcrossDifferentDomains-InternetZone-LocalComputer, NavigateSub-framesAcrossDifferentDomains-InternetZone-LocalUser |
navigate_sub_frames_across_different_domains_Internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:612 |
NaN |
NaN |
| CCE-4161-6 |
The "Open files based on content, not file extension" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2100 |
NaN |
CCE-910 |
oval:org.mitre.oval:def:953, oval:org.mitre.oval:def:1300 |
OpenFilesBasedOnContent-InternetZone-LocalComputer, OpenFilesBasedOnContent-InternetZone-LocalUser |
OpenFilesBasedOnContent_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:953 |
NaN |
NaN |
| CCE-3553-5 |
The "Software channel permissions" setting should be configured correctly for the Internet Zone. |
High safety/low safety/medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1E05 |
NaN |
CCE-359 |
oval:org.mitre.oval:def:302, oval:org.mitre.oval:def:1398 |
SoftwareChannelPermissions-InternetZone-LocalComputer, SoftwareChannelPermissions-InternetZone-LocalUser |
SoftwareChannelPermissions_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:302 |
NaN |
NaN |
| CCE-3619-4 |
The "Use Pop-up Blocker" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1809 |
NaN |
CCE-1002 |
oval:org.mitre.oval:def:1179, oval:org.mitre.oval:def:558 |
UsePop-upBlocker-InternetZone-LocalComputer, UsePop-upBlocker-InternetZone-LocalUser |
UsePop-upBlocker_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1179 |
NaN |
NaN |
| CCE-3914-9 |
The "Userdata persistence" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1606 |
NaN |
CCE-425 |
oval:org.mitre.oval:def:1108 |
UserdataPersistence-InternetZone-LocalComputer |
UserdataPersistence_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1108 |
NaN |
NaN |
| CCE-3570-9 |
The "Web sites in less privileged Web content zones can navigate into this zone" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2101 |
NaN |
CCE-724 |
oval:org.mitre.oval:def:265, oval:org.mitre.oval:def:1432 |
WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-InternetZone-LocalComputer, WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-InternetZone-LocalUser |
WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:265 |
NaN |
NaN |
| CCE-3843-0 |
The "XPS documents" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2401 |
NaN |
CCE-1015 |
oval:org.mitre.oval:def:628 |
XPSFiles-InternetZone-LocalComputer |
NaN |
NaN |
NaN |
NaN |
| CCE-3984-2 |
The "Display mixed content" setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1609 |
NaN |
CCE-878 |
oval:org.mitre.oval:def:245 |
DisplayMixedContent-LockedDownInternetZone-LocalComputer |
display_mixed_content_locked_down_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:245 |
NaN |
NaN |
| CCE-3989-1 |
The "Display mixed content" setting should be configured correctly for the Intranet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1609 |
NaN |
CCE-288 |
oval:org.mitre.oval:def:1166 |
DisplayMixedContent-IntranetZone-LocalComputer |
display_mixed_content_intranet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1166 |
NaN |
NaN |
| CCE-4121-0 |
The "Display mixed content" setting should be configured correctly for the Locked Down Intranet Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Intranet Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\1609 |
NaN |
CCE-552 |
oval:org.mitre.oval:def:247 |
DisplayMixedContent-LockedDownIntranetZone-LocalComputer |
display_mixed_content-LockedDownintranet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:247 |
NaN |
NaN |
| CCE-4138-4 |
The "Display mixed content" setting should be configured correctly for the Local Machine Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Local Machine Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1609 |
NaN |
CCE-473 |
oval:org.mitre.oval:def:383 |
DisplayMixedContent-LocalMachineZone-LocalComputer |
display_mixed_content-local_machine_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:383 |
NaN |
NaN |
| CCE-4028-7 |
The "Display mixed content" setting should be configured correctly for the Locked Down Local Machine Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Local Machine Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\1609 |
NaN |
CCE-239 |
oval:org.mitre.oval:def:418 |
DisplayMixedContent-LockedDownLocalMachineZone-LocalComputer |
display_mixed_content-LockedDownlocal_machine_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:418 |
NaN |
NaN |
| CCE-3905-7 |
The "Access data sources across domains" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1406 |
NaN |
CCE-636 |
oval:org.mitre.oval:def:652, oval:org.mitre.oval:def:750 |
AccessDataSourcesAcrossDomains-RestrictedSitesZone-LocalComputer, AccessDataSourcesAcrossDomains-RestrictedSitesZone-LocalUser |
AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:652 |
NaN |
NaN |
| CCE-4050-1 |
The "Active scripting" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1400 |
NaN |
CCE-292 |
oval:org.mitre.oval:def:293, oval:org.mitre.oval:def:561 |
AllowActiveScripting-RestrictedSitesZone-LocalComputer, AllowActiveScripting-RestrictedSitesZone-LocalUser |
AllowActiveScripting_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:293 |
NaN |
NaN |
| CCE-4196-2 |
The "Binary and script behaviors" setting should be configured correctly for the Restricted Sites Zone. |
Administrator approved/enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2000 |
NaN |
CCE-178 |
oval:org.mitre.oval:def:365, oval:org.mitre.oval:def:1314 |
AllowBinaryAndScriptBehaviors-RestrictedSitesZone-LocalComputer, AllowBinaryAndScriptBehaviors-RestrictedSitesZone-LocalUser |
AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:365 |
NaN |
NaN |
| CCE-3337-3 |
The "Drag and drop or copy and paste files" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1802 |
NaN |
CCE-41 |
oval:org.mitre.oval:def:498, oval:org.mitre.oval:def:1465 |
AllowDragDropOrCopyPasteFiles-RestrictedSitesZone-LocalComputer, AllowDragDropOrCopyPasteFiles-RestrictedSitesZone-LocalUser |
AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:498 |
NaN |
NaN |
| CCE-4150-9 |
The "File download" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1803 |
NaN |
CCE-970 |
oval:org.mitre.oval:def:1184, oval:org.mitre.oval:def:1318 |
AllowFileDownloads-RestrictedSitesZone-LocalComputer, AllowFileDownloads-RestrictedSitesZone-LocalUser |
AllowFileDownloads_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1184 |
NaN |
NaN |
| CCE-4062-6 |
The "Font download" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1604 |
NaN |
CCE-882 |
oval:org.mitre.oval:def:1109, oval:org.mitre.oval:def:1410 |
AllowFontDownloads-RestrictedSitesZone-LocalComputer, AllowFontDownloads-RestrictedSitesZone-LocalUser |
AllowFontDownloads_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1109 |
NaN |
NaN |
| CCE-4079-0 |
The "Installation of desktop items" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1800 |
NaN |
CCE-763 |
oval:org.mitre.oval:def:251, oval:org.mitre.oval:def:1257 |
AllowInstallationOfDesktopItems-RestrictedSitesZone-LocalComputer, AllowInstallationOfDesktopItems-RestrictedSitesZone-LocalUser |
AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:251 |
NaN |
NaN |
| CCE-4084-0 |
The "Allow META REFRESH" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1608 |
NaN |
CCE-680 |
oval:org.mitre.oval:def:1218, oval:org.mitre.oval:def:1270 |
AllowMETAREFRESH-RestrictedSitesZone-LocalComputer, AllowMETAREFRESH-RestrictedSitesZone-LocalUser |
AllowMETAREFRESH_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1218 |
NaN |
NaN |
| CCE-4119-4 |
The "Allow script-initiated windows without size or position constraints" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2102 |
NaN |
CCE-208 |
oval:org.mitre.oval:def:1234, oval:org.mitre.oval:def:574 |
AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-RestrictedSitesZone-LocalComputer, AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-RestrictedSitesZone-LocalUser |
AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1234 |
NaN |
NaN |
| CCE-3639-2 |
The "Allow Scriptlets" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1209 |
NaN |
CCE-838 |
oval:org.mitre.oval:def:1217 |
AllowScriptlets-RestrictedSitesZone-LocalComputer |
NaN |
NaN |
NaN |
NaN |
| CCE-4031-1 |
The "Allow status bar updates via script" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1001 |
NaN |
CCE-129 |
oval:org.mitre.oval:def:378, oval:org.mitre.oval:def:1320 |
AllowStatusBarUpdatesViaScript-RestrictedSitesZone-LocalComputer, AllowStatusBarUpdatesViaScript-RestrictedSitesZone-LocalUser |
AllowStatusBarUpdatesViaScript_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:378 |
NaN |
NaN |
| CCE-4053-5 |
The "Automatic prompting for file downloads" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2200 |
NaN |
CCE-175 |
oval:org.mitre.oval:def:252, oval:org.mitre.oval:def:1312 |
AutomaticPromptingFileDownloads-RestrictedSitesZone-LocalComputer, AutomaticPromptingFileDownloads-RestrictedSitesZone-LocalUser |
AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:252 |
NaN |
NaN |
| CCE-4057-6 |
The "Download signed ActiveX controls" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1001 |
NaN |
CCE-52 |
oval:org.mitre.oval:def:1019, oval:org.mitre.oval:def:1389 |
DownloadSignedActiveXControls-RestrictedSitesZone-LocalComputer, DownloadSignedActiveXControls-RestrictedSitesZone-LocalUser |
download_signed_activex_controls_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1019 |
NaN |
NaN |
| CCE-3564-2 |
The "Download unsigned ActiveX controls" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1004 |
NaN |
CCE-1012 |
oval:org.mitre.oval:def:949, oval:org.mitre.oval:def:579 |
DownloadUnsignedActiveXControls-RestrictedSitesZone-LocalComputer, DownloadUnsignedActiveXControls-RestrictedSitesZone-LocalUser |
DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:949 |
NaN |
NaN |
| CCE-4101-2 |
The "Initialize and script ActiveX controls not marked as safe for scripting" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1201 |
NaN |
CCE-26 |
oval:org.mitre.oval:def:273, oval:org.mitre.oval:def:1342 |
InitializeScriptActiveXControlsNotMarkedAsSafe-RestrictedSitesZone-LocalComputer, InitializeScriptActiveXControlsNotMarkedAsSafe-RestrictedSitesZone-LocalUser |
InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:273 |
NaN |
NaN |
| CCE-3996-6 |
The "Java permissions" setting should be configured correctly for the Restricted Sites Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1C00 |
NaN |
CCE-925 |
oval:org.mitre.oval:def:824, oval:org.mitre.oval:def:732 |
JavaPermissions-RestrictedSitesZone-LocalComputer, JavaPermissions-RestrictedSitesZone-LocalUser |
java_permissions_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:824 |
NaN |
NaN |
| CCE-4066-7 |
The "Launching programs and files in an IFRAME" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1804 |
NaN |
CCE-339 |
oval:org.mitre.oval:def:274, oval:org.mitre.oval:def:1223 |
LaunchingApplicationsAndFilesInIFRAME-RestrictedSitesZone-LocalComputer, LaunchingApplicationsAndFilesInIFRAME-RestrictedSitesZone-LocalUser |
LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:274 |
NaN |
NaN |
| CCE-3696-2 |
The "Logon" setting should be configured correctly for the Restricted Sites Zone. |
Anonymous logon/Automatic logon only in Intranet zone/Automatic logon with current user name and password/Prompt for user name and password |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1A00 |
NaN |
CCE-128 |
oval:org.mitre.oval:def:326, oval:org.mitre.oval:def:1378 |
LogonOptions-RestrictedSitesZone-LocalComputer, LogonOptions-RestrictedSitesZone-LocalUser |
LogonOptions_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:326 |
NaN |
NaN |
| CCE-3590-7 |
The "Loose XAML" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2402 |
NaN |
CCE-639 |
oval:org.mitre.oval:def:275 |
LooseXAMLFiles-RestrictedSitesZone-LocalComputer |
LooseXAMLFiles_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:275 |
NaN |
NaN |
| CCE-4110-3 |
The "Navigate sub-frames across different domains" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1607 |
NaN |
CCE-995 |
oval:org.mitre.oval:def:1229, oval:org.mitre.oval:def:1292 |
NavigateSub-framesAcrossDifferentDomains-RestrictedSitesZone-LocalComputer, NavigateSub-framesAcrossDifferentDomains-RestrictedSitesZone-LocalUser |
NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1229 |
NaN |
NaN |
| CCE-4132-7 |
The "Open files based on content, not file extension" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2100 |
NaN |
CCE-409 |
oval:org.mitre.oval:def:706, oval:org.mitre.oval:def:1421 |
OpenFilesBasedOnContent-RestrictedSitesZone-LocalComputer, OpenFilesBasedOnContent-RestrictedSitesZone-LocalUser |
OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:706 |
NaN |
NaN |
| CCE-3400-9 |
The "Run components not signed with Authenticode" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2004 |
NaN |
CCE-678 |
oval:org.mitre.oval:def:329, oval:org.mitre.oval:def:599 |
RunNETFrameworkReliantComponentsNotSignedWithAuthenticode-RestrictedSitesZone-LocalComputer, RunNETFrameworkReliantComponentsNotSignedWithAuthenticode-RestrictedSitesZone-LocalUser |
RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:329 |
NaN |
NaN |
| CCE-4158-2 |
The "Run components signed with Authenticode" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2001 |
NaN |
CCE-563 |
oval:org.mitre.oval:def:276, oval:org.mitre.oval:def:1428 |
RunNETFrameworkReliantComponentsSignedWithAuthenticode-RestrictedSitesZone-LocalComputer, RunNETFrameworkReliantComponentsSignedWithAuthenticode-RestrictedSitesZone-LocalUser |
RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:276 |
NaN |
NaN |
| CCE-4163-2 |
The "Run ActiveX controls and plugins" setting should be configured correctly for the Restricted Sites Zone. |
Administrator approved/enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1200 |
NaN |
CCE-841 |
oval:org.mitre.oval:def:571, oval:org.mitre.oval:def:1594 |
RunActiveXControlsAndPlugins-RestrictedSitesZone-LocalComputer, RunActiveXControlsAndPlugins-RestrictedSitesZone-LocalUser |
RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:571 |
NaN |
NaN |
| CCE-4202-8 |
The "Script ActiveX controls marked safe for scripting" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1405 |
NaN |
CCE-973 |
oval:org.mitre.oval:def:602, oval:org.mitre.oval:def:1274 |
ScriptActiveXControlsMarkedSafeForScripting-RestrictedSitesZone-LocalComputer, ScriptActiveXControlsMarkedSafeForScripting-RestrictedSitesZone-LocalUser |
ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:602 |
NaN |
NaN |
| CCE-3216-9 |
The "Scripting of Java applets" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1402 |
NaN |
CCE-1000 |
oval:org.mitre.oval:def:280, oval:org.mitre.oval:def:641 |
ScriptingOfJavaApplets-RestrictedSitesZone-LocalComputer, ScriptingOfJavaApplets-RestrictedSitesZone-LocalUser |
ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:280 |
NaN |
NaN |
| CCE-3855-4 |
The "Software channel permissions" setting should be configured correctly for the Restricted Sites Zone. |
High safety/low safety/medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1E05 |
NaN |
CCE-520 |
oval:org.mitre.oval:def:290, oval:org.mitre.oval:def:1214 |
SoftwareChannelPermissions-RestrictedSitesZone-LocalComputer, SoftwareChannelPermissions-RestrictedSitesZone-LocalUser |
SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:290 |
NaN |
NaN |
| CCE-4018-8 |
The "Use Pop-up Blocker" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1809 |
NaN |
CCE-660 |
oval:org.mitre.oval:def:1100, oval:org.mitre.oval:def:1286 |
UsePop-upBlocker-RestrictedSitesZone-LocalComputer, UsePop-upBlocker-RestrictedSitesZone-LocalUser |
UsePop-upBlocker_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1100 |
NaN |
NaN |
| CCE-4040-2 |
The "Userdata persistence" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1606 |
NaN |
CCE-28 |
oval:org.mitre.oval:def:300 |
UserdataPersistence-RestrictedSitesZone-LocalComputer |
UserdataPersistence_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:300 |
NaN |
NaN |
| CCE-4215-0 |
The "Web sites in less privileged Web content zones can navigate into this zone" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2101 |
NaN |
CCE-698 |
oval:org.mitre.oval:def:1219, oval:org.mitre.oval:def:1243 |
WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-RestrictedSitesZone-LocalComputer, WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-RestrictedSitesZone-LocalUser |
WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1219 |
NaN |
NaN |
| CCE-3991-7 |
The "XPS documents" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2401 |
NaN |
CCE-460 |
oval:org.mitre.oval:def:1176 |
XPSFiles-RestrictedSitesZone-LocalComputer |
NaN |
NaN |
NaN |
NaN |
| CCE-3264-9 |
The "Display mixed content" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\1609 |
NaN |
CCE-30 |
oval:org.mitre.oval:def:314 |
DisplayMixedContent-LockedDownRestrictedSitesZone-LocalComputer |
display_mixed_content-LockedDownRestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:314 |
NaN |
NaN |
| CCE-4087-3 |
The "Display mixed content" setting should be configured correctly for the Trusted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Trusted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1609 |
NaN |
CCE-31 |
oval:org.mitre.oval:def:1153 |
DisplayMixedContent-TrustedSitesZone-LocalComputer |
display_mixed_content_trusted_sites_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1153 |
NaN |
NaN |
| CCE-4232-5 |
The "Display mixed content" setting should be configured correctly for the Locked Down Trusted Sites Zone. |
enabled/disabled/prompt |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Trusted Sites Zone Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\1609 |
NaN |
CCE-666 |
oval:org.mitre.oval:def:1183 |
DisplayMixedContent-LockedDownTrustedSitesZone-LocalComputer |
display_mixed_content_LockedDowntrusted_sites_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1183 |
NaN |
NaN |
| CCE-4259-8 |
The "Enable Native XMLHttp Support" setting should be configured correctly. |
enabled/disabled |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\XMLHTTP |
NaN |
CCE-528 |
oval:org.mitre.oval:def:338 |
EnableNativeXMLHttpSupport-LocalComputer |
EnableNativeXMLHttpSupport_LocalComputer |
oval:gov.nist.fdcc.ie7:def:338 |
NaN |
NaN |
| CCE-3647-5 |
The "Turn on the auto-complete feature for user names and passwords on form" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FormSuggest Passwords HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\FormSuggest Passwords |
NaN |
CCE-721 |
oval:org.mitre.oval:def:645 |
DisableSaveThisProgramToDiskOption-LocalUser |
TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser |
oval:gov.nist.fdcc.ie7:def:645 |
NaN |
NaN |
| CCE-3677-2 |
The "Allow Install On Demand (Internet Explorer)" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Main\NoJITSetup |
NaN |
CCE-69 |
oval:org.mitre.oval:def:523 |
AllowInstallOnDemandIE-LocalUser |
allow_install_on_demand_ie_local_computer |
oval:gov.nist.fdcc.ie7:def:9999 |
NaN |
NaN |
| CCE-4056-8 |
The "Turn off page transitions" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Main\Page_Transitions |
NaN |
CCE-71 |
oval:org.mitre.oval:def:1206 |
TurnOffPageTransitions-LocalUser |
TurnOffPageTransitions_LocalUser |
oval:gov.nist.fdcc.ie7:def:1206 |
NaN |
NaN |
| CCE-4246-5 |
The "Disable AutoComplete for forms" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Main\Use FormSuggest HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\FormSuggest |
NaN |
CCE-478 |
oval:org.mitre.oval:def:1516 |
DisableAutoCompleteForForms-LocalUser |
DisableAutoCompleteForForms_LocalUser |
oval:gov.nist.fdcc.ie7:def:1516 |
NaN |
NaN |
| CCE-4214-3 |
The "Disable Save this program to disk option" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoSelectDownloadDir |
NaN |
CCE-412 |
oval:org.mitre.oval:def:505 |
AllowInstallOnDemandIE-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3606-1 |
The "Disable changing certificate settings" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Certificates |
NaN |
CCE-1037 |
oval:org.mitre.oval:def:1362 |
DisableChangingCertificateSettings-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-4237-4 |
The "Disable external branding of Internet Explorer" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoExternalBranding |
NaN |
CCE-1051 |
oval:org.mitre.oval:def:1384 |
DisableExternalBrandingOfIE-LocalUser |
DisableExternalBrandingOfIE_LocalUser |
oval:gov.nist.fdcc.ie7:def:1384 |
NaN |
NaN |
| CCE-3275-5 |
The "Configure Outlook Express" setting should be configured correctly |
enabled/disabled |
HKCU\Software\Microsoft\Outlook Express\BlockExeAttachments |
NaN |
CCE-963 |
oval:org.mitre.oval:def:1238 |
ConfigureOutlookExpress-LocalUser |
configure_outlook_express_local_user |
oval:gov.nist.fdcc.ie7:def:1238 |
NaN |
NaN |
| CCE-4036-0 |
The "Turn on the Internet Connection Wizard Auto Detect" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Connection Wizard\DisableICW |
NaN |
CCE-258 |
oval:org.mitre.oval:def:604 |
InternetConnectionWizardSettings-LocalUser |
TurnOnInternetConnectionWizardAutoDetect_LocalUser |
oval:gov.nist.fdcc.ie7:def:604 |
NaN |
NaN |
| CCE-3825-7 |
The "Disable Internet Connection wizard" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock |
NaN |
CCE-769 |
oval:org.mitre.oval:def:1355 |
DisableInternetConnectionWizard-LocalUser |
DisableInternetConnectionWizard_LocalUser |
oval:gov.nist.fdcc.ie7:def:1355 |
NaN |
NaN |
| CCE-4226-7 |
The "Disable the Reset Web Settings feature" should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ResetWebSettings |
NaN |
CCE-625 |
oval:org.mitre.oval:def:1437 |
DisableResetWebSettingsFeature-LocalUser |
DisableResetWebSettingsFeature_LocalUser |
oval:gov.nist.fdcc.ie7:def:1437 |
NaN |
NaN |
| CCE-4120-2 |
The "Disable Downloading Of Site Subscription Content" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoSubscriptionContent |
NaN |
CCE-74 |
oval:org.mitre.oval:def:1080 |
DisableDownloadingOfSiteSubscriptionContent-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-4248-1 |
The "Disable Adding Schedules For Offline Pages" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoAddingSubscriptions |
NaN |
CCE-122 |
oval:org.mitre.oval:def:1293 |
DisableAddingSchedulesForOfflinePages-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3389-4 |
The "Disable Adding Channels" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoAddingChannels |
NaN |
CCE-716 |
oval:org.mitre.oval:def:1383 |
DisableAddingChannels-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3645-9 |
The "Disable Editing And Creating Of Schedule Groups" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoEditingScheduleGroups |
NaN |
CCE-610 |
oval:org.mitre.oval:def:1397 |
DisableEditingAndCreatingOfScheduleGroups-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3940-4 |
The "Disable All Scheduled Offline Pages" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoScheduledUpdates |
NaN |
CCE-619 |
oval:org.mitre.oval:def:1501 |
DisableAllScheduledOfflinePages-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3821-6 |
The "Disable Editing Schedules For Offline Pages" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoEditingSubscriptions |
NaN |
CCE-373 |
oval:org.mitre.oval:def:1565 |
DisableEditingSchedulesForOfflinePages-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3742-4 |
The "Disable Channel User Interface Completely" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoChannelUI |
NaN |
CCE-298 |
oval:org.mitre.oval:def:1782 |
DisableChannelUserInterfaceCompletely-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-4261-4 |
The "Disable Removing Channels" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoRemovingChannels |
NaN |
CCE-1069 |
oval:org.mitre.oval:def:1801 |
DisableRemovingChannels-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-4190-5 |
The "Disable Removing Schedules For Offline Pages" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoRemovingSubscriptions |
NaN |
CCE-615 |
oval:org.mitre.oval:def:1954 |
DisableRemovingSchedulesForOfflinePages-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-4208-5 |
The "Disable Offline Page Hit Logging" setting should be configured correctly. |
enabled/disabled |
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoChannelLogging |
NaN |
CCE-1003 |
oval:org.mitre.oval:def:2026 |
DisableOfflinePageHitLogging-LocalUser |
NaN |
NaN |
NaN |
NaN |
| CCE-3754-9 |
The "Java permissions" setting should be configured correctly for the Locked Down Intranet Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Intranet Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\1C00 |
NaN |
CCE-320 |
oval:org.mitre.oval:def:2039 |
JavaPermissions-LockedDownIntranetZone-LocalComputer |
java_permissions_LockedDownintranet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:2039 |
NaN |
NaN |
| CCE-3891-9 |
The "Java permissions" setting should be configured correctly for the Local Machine Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Local Machine Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1C00 |
NaN |
CCE-138 |
oval:org.mitre.oval:def:1422 |
JavaPermissions-LocalMachineZone-LocalComputer |
java_permissions_local_machine_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1422 |
NaN |
NaN |
| CCE-4160-8 |
The "Java permissions" setting should be configured correctly for the Locked Down Local Machine Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Local Machine Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\1C00 |
NaN |
CCE-1045 |
oval:org.mitre.oval:def:1986 |
JavaPermissions-LockedDownLocalMachineZone-LocalComputer |
java_permissions_LockedDownlocal_machine_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1986 |
NaN |
NaN |
| CCE-4763-9 |
Computer-wide, rather than per-user, assignment of sites to zones for Internet Explorer should be enabled or disabled as appropriate. |
enabled, disabled, or not configured |
GPO Setting: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Site to Zone Assignment List |
NaN |
CCE-1005 |
NaN |
NaN |
site_to_zone_assignment_list_local_computer |
oval:gov.nist.fdcc.ie7:def:9998 |
NaN |
NaN |
| CCE-4643-3 |
The "Turn on Protected Mode" setting should be configured correctly for the Internet Zone. |
enabled/disabled |
GPO Setting: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Protected Mode |
NaN |
CCE-281 |
NaN |
NaN |
TurnOnProtectedMode_InternetZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:111999 |
NaN |
NaN |
| CCE-4652-4 |
The "Java permissions" setting should be configured correctly for the Intranet Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1C00 |
NaN |
CCE-218 |
NaN |
NaN |
java_permissions_intranet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1883 |
NaN |
NaN |
| CCE-4793-6 |
The "Download signed ActiveX controls" setting should be configured correctly for the Locked-Down Internet Zone. |
enabled/disabled/prompt |
GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone\Download signed ActiveX controls |
NaN |
CCE-308 |
NaN |
NaN |
download_signed_activex_controls_locked_down_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:24599 |
NaN |
NaN |
| CCE-4692-0 |
The "Java permissions" setting should be configured correctly for the Locked Down Internet Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\1C00 |
NaN |
CCE-781 |
NaN |
NaN |
java_permissions_locked_down_internet_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1419 |
NaN |
NaN |
| CCE-3902-4 |
The "Java permissions" setting should be configured correctly for the Locked Down Restricted Sites Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\1C00 |
NaN |
CCE-1088 |
NaN |
NaN |
java_permissions_LockedDownRestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:1753 |
NaN |
NaN |
| CCE-4546-8 |
The "Allow status bar updates via script" setting should be configured correctly for the Locked-Down Trusted Sites Zone. |
enabled/disabled |
GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Trusted Sites Zone\Allow status bar updates via script |
NaN |
CCE-1147 |
NaN |
NaN |
AllowStatusBarUpdatesViaScript_LockedDowntrusted_sites_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:118399 |
NaN |
NaN |
| CCE-4564-1 |
The "Java permissions" setting should be configured correctly for the Locked Down Trusted Sites Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Trusted Sites Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\1C00 |
NaN |
CCE-140 |
NaN |
NaN |
java_permissions_LockedDowntrusted_sites_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1699 |
NaN |
NaN |
| CCE-3909-9 |
The "Turn on Protected Mode" setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled |
GPO Setting: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn on Protected Mode Registry Keys:[HKLM|HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500 |
NaN |
CCE-1211 |
NaN |
NaN |
TurnOnProtectedMode_RestrictedSitesZone_LocalComputer |
oval:gov.nist.fdcc.ie7:def:62199 |
NaN |
NaN |
| CCE-4845-4 |
The "Java permissions" setting should be configured correctly for the Trusted Sites Zone. |
Custom/Disable Java/High safety/Low safety/Medium safety |
Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Trusted Sites Zone/Java permissions Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1C00 |
NaN |
CCE-675 |
NaN |
NaN |
java_permissions_trusted_sites_zone_local_computer |
oval:gov.nist.fdcc.ie7:def:1379 |
NaN |
NaN |
| CCE-18394-7 |
The 'Allow scripting of Internet Explorer web browser control' setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1206 (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow scripting of Internet Explorer web browser control |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
AllowScriptingOfInternetExplorerWebBrowserControl_InternetZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31098 |
| CCE-18552-0 |
The 'Include local directory path when uploading files to a server' setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\160A (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Include local directory path when uploading files to a server |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
IncludeLocalDirectoryPathWhenUploadingFilesToAServer_InternetZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31099 |
| CCE-18467-1 |
The 'Launching programs and unsafe files' setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1806 (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Launching programs and unsafe files |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
LaunchingProgramsAndUnsafeFiles_InternetZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31100 |
| CCE-18731-0 |
The 'Run .NET Framework-reliant components not signed with Authenticode' setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2004 (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components not signed with Authenticode |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_InternetZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31035 |
| CCE-18230-3 |
The 'Run .NET Framework-reliant components signed with Authenticode' setting should be configured correctly for the Internet Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2001 (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components signed with Authenticode |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
RunNETFrameworkReliantComponentsSignedWithAuthenticode_InternetZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31036 |
| CCE-18912-6 |
The 'Allow scripting of Internet Explorer web browser control' setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1206 (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow scripting of Internet Explorer web browser control |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
AllowScriptingOfInternetExplorerWebBrowserControl_RestrictedSitesZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31103 |
| CCE-18738-5 |
The 'Include local directory path when uploading files to a server' setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\160A (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Include local directory path when uploading files to a server |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
IncludeLocalDirectoryPathWhenUploadingFilesToAServer_RestrictedSitesZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31104 |
| CCE-18137-0 |
The 'Launching programs and unsafe files' setting should be configured correctly for the Restricted Sites Zone. |
enabled/disabled/prompt |
(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1806 (2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Launching programs and unsafe files |
NaN |
NaN |
NaN |
NaN |
NaN |
NaN |
LaunchingProgramsAndUnsafeFiles_RestrictedSitesZone_LocalComputer |
oval:gov.nist.USGCB.ie7:def:31105 |