Check: DTOO346
Microsoft Project 2016 STIG:
DTOO346
(in version v1 r1)
Title
Untrusted intranet zone access to Project servers must not be allowed. (Cat II impact)
Discussion
Allows users to access Project Server Web sites and Workspaces that have not been added to their trusted internet zones. If you enable this setting, users can access Project Server and Microsoft SharePoint Foundation sites that are not in their trusted internet zones. If this setting is disabled or not configured, users are required to add the Project Server and Microsoft SharePoint Foundation sites to their trusted internet site zones.
Check Content
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Project 2016 -> Project Options -> Security "Enable untrusted intranet zone access to Project server" is set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\16.0\ms project\security Criteria: If the value TrustWSS is REG_DWORD = 0, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Project 2016 -> Project Options -> Security "Enable untrusted intranet zone access to Project server" to "Disabled".
Additional Identifiers
Rule ID: SV-85351r1_rule
Vulnerability ID: V-70727
Group Title: SRG-APP-000210
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001170 |
The information system prevents the automatic execution of mobile code in organization-defined software applications. |
Controls
Number | Title |
---|---|
SC-18 (4) |
Prevent Automatic Execution |