Adobe Reader DC must enable Enhanced Security in a Standalone Application. (Cat II impact)
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1 If the value for bEnhancedSecurityStandalone is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1
The information system identifies organization-defined unacceptable mobile code.
The information system prevents the download of organization-defined unacceptable mobile code.
The information system prevents the automatic execution of mobile code in organization-defined software applications.
The information system takes organization-defined corrective action when organization-defined unacceptable mobile code is identified.
The information system prevents the execution of organization-defined unacceptable mobile code.