Check: DTOO226 - Outlook
Microsoft Outlook 2010 STIG:
DTOO226 - Outlook
(in versions v1 r13 through v1 r12)
Title
Dial-up and Hang up Options for Outlook must be configured. (Cat II impact)
Discussion
By default, users can connect to their e-mail servers using dial-up networking if their accounts are configured appropriately. Dial-up connections are often used by mobile users who need to connect to the Internet from remote locations. Remote connections are generally not subject to the same restrictions as enterprise network environments, which can make them more vulnerable to attack.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Outlook Options -> Mail Setup “Dial–up options” must be set to “Enabled” and Hang up when finished sending, receiving, or updating is selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\outlook\options\mail Criteria: If the value Hangup after Spool is REG_DWORD = 1, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2010 -> Outlook Options -> Mail Setup “Dial–up options” to “Enabled” and Hang up when finished sending, receiving, or updating is selected.
Additional Identifiers
Rule ID: SV-33506r1_rule
Vulnerability ID: V-17585
Group Title: DTOO226 - Dial-up Options
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001150 |
The information system prohibits remote activation of collaborative computing devices, excluding the organization-defined exceptions where remote activation is to be allowed. |
Controls
Number | Title |
---|---|
SC-15 |
Collaborative Computing Devices |