Check: DTOO316
Microsoft Outlook 2013 STIG:
DTOO316
(in versions v1 r14 through v1 r9)
Title
Outlook minimum encryption key length settings must be set. (Cat II impact)
Discussion
This setting allows the minimum key length for an encrypted email message to be configured. Satisfies: SRG-APP-000514, SRG-APP-000555, SRG-APP-000625, SRG-APP-000630, SRG-APP-000635, SRG-APP-000416
Check Content
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Security -> Cryptography "Minimum encryption settings" is set to "Enabled: 168 bits". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\outlook\security Criteria: If the value MinEncKey is REG_DWORD = 168, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Security -> Cryptography "Minimum encryption settings" to "Enabled: 168 bits".
Additional Identifiers
Rule ID: SV-242739r961857_rule
Vulnerability ID: V-242739
Group Title: SRG-APP-000514
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002450 |
Implement organization-defined types of cryptography for each specified cryptography use. |
Controls
Number | Title |
---|---|
SC-13 |
Cryptographic Protection |