Check: DTOO314 - Outlook
Microsoft Outlook 2010 STIG:
DTOO314 - Outlook
(in versions v1 r13 through v1 r12)
Title
Default message format must be set to use Plain Text. (Cat II impact)
Discussion
Outlook uses HTML as the default e-mail format, but users can choose a format other than the default when composing messages. This setting controls the default message format in Outlook.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Outlook Options -> Mail Format -> Internet Formatting -> Message Format “Set message format” must be “Enabled: Plain Text". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\outlook\options\mail Criteria: If the value EditorPreference is REG_DWORD = 65536 (dec), this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Outlook Options -> Mail Format -> Internet Formatting -> Message Format “Set message format” to “Enabled: Plain Text".
Additional Identifiers
Rule ID: SV-34105r1_rule
Vulnerability ID: V-26634
Group Title: DTOO314 - Set message format
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |