Check: DTOO261 - Outlook
Microsoft Outlook 2007:
DTOO261 - Outlook
(in versions v4 r16 through v4 r15)
Title
Do not provide Continue Option on Encryption Warning dialog box - Outlook. (Cat II impact)
Discussion
By default, if Outlook 2007 users see an encryption-related dialog box when attempting to send a message, they can choose to dismiss the warning and send the message anyway. If users send messages after seeing an encryption error, it is likely that recipients will not be able to read them.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value DisableContinueEncryption is REG_DWORD = 0, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography “Do not provide Continue option on Encryption warning dialog boxes” will be set to “Disabled”.
Additional Identifiers
Rule ID: SV-18735r1_rule
Vulnerability ID: V-17604
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |