Check: DTOO225 - Outlook
Microsoft Outlook 2010 STIG:
DTOO225 - Outlook
(in version v1 r14)
Title
Outlook Dial-up options to Warn user before allowing switch in dial-up access must be configured. (Cat II impact)
Discussion
Users can connect to their e-mail servers using dial-up networking if their accounts are configured appropriately. Dial-up connections are often used by mobile users who need to connect to the Internet from remote locations. Remote connections are generally not subject to the same restrictions as enterprise network environments, which can make them more vulnerable to attack.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Outlook Options -> Mail Setup "Dial-up options" must be set to "Enabled" and Warn before switching dial-up connection is selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\outlook\options\mail Criteria: If the value Warn on Dialup is REG_DWORD = 1, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Outlook Options -> Mail Setup "Dial-up options" to "Enabled" and Warn before switching dial-up connection is selected.
Additional Identifiers
Rule ID: SV-242044r961503_rule
Vulnerability ID: V-242044
Group Title: SRG-APP-000394
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001958 |
Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection. |
Controls
Number | Title |
---|---|
IA-3 |
Device Identification and Authentication |