Check: DTOO156 - InfoPath
Microsoft InfoPath 2010 STIG:
DTOO156 - InfoPath
(in versions v1 r11 through v1 r10)
Title
Offline Mode capability to cache queries for offline mode must be configured. (Cat II impact)
Discussion
InfoPath can function in online mode or offline mode. It can also cache queries for use in offline mode. If offline mode is used and cached queries are enabled, sensitive information contained in the cache could be at risk. By default, InfoPath is in online mode, but offline mode is available to users. Users can also cache queries for use in offline mode.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath Options -> Advanced -> Offline “Offline Mode status” must be set to “Enabled (Enabled, InfoPath not in Offline Mode)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\editor\offline Criteria: If the value CachedModeStatus is REG_DWORD = 2, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath Options -> Advanced -> Offline “Offline Mode status” to “Enabled (Enabled, InfoPath not in Offline Mode)”.
Additional Identifiers
Rule ID: SV-33649r1_rule
Vulnerability ID: V-17758
Group Title: DTOO156 - Offline Mode Cache
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |