Check: DTOO316
Microsoft Outlook 2013 STIG:
DTOO316
(in versions v1 r13 through v1 r9)
Title
Outlook minimum encryption key length settings must be set. (Cat II impact)
Discussion
This setting allows the minimum key length for an encrypted email message to be configured.
Check Content
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Security -> Cryptography "Minimum encryption settings" is set to "Enabled: 168 bits". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\outlook\security Criteria: If the value MinEncKey is REG_DWORD = 168, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Security -> Cryptography "Minimum encryption settings" to "Enabled: 168 bits".
Additional Identifiers
Rule ID: SV-54064r1_rule
Vulnerability ID: V-26636
Group Title: DTOO316 - Minimum encryption settings
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002450 |
The information system implements organization-defined cryptographic uses and type of cryptography required for each use in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. |
Controls
Number | Title |
---|---|
SC-13 |
Cryptographic Protection |