Check: DTOO316 - Outlook
Microsoft Outlook 2010 STIG:
DTOO316 - Outlook
(in versions v1 r13 through v1 r12)
Title
Outlook minimum encryption key length settings must be set. (Cat II impact)
Discussion
This setting allows you to set the minimum key length for an encrypted e-mail message.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Security -> Cyrptography “Minimum encryption settings” must be set to “Enabled: 168 bits". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\outlook\security Criteria: If the value MinEncKey is REG_DWORD = 168, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Security -> Cyrptography “Minimum encryption settings” to “Enabled: 168 bits".
Additional Identifiers
Rule ID: SV-34107r1_rule
Vulnerability ID: V-26636
Group Title: DTOO316 - Minimum encryption settings
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002450 |
The information system implements organization-defined cryptographic uses and type of cryptography required for each use in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. |
Controls
Number | Title |
---|---|
SC-13 |
Cryptographic Protection |