8.3.5 Set 'Allow active scripting' to 'Enabled:Disable'

Information



This policy setting allows you to manage whether script code on pages in the zone is run.
The recommended state for this setting is- Enabled-Disable.

*Rationale*

Active scripts hosted on sites located in this zone are more likely to contain malicious code.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow active
scriptingThen set the Allow active scripting option to Disable.

Impact-If you enable this policy setting, script code on pages in the zone can run automatically. If
you select Prompt in the drop-down box, users are queried to choose whether to allow
script code on pages in the zone to run. If you disable this policy setting, script code on
pages in the zone is prevented from running. If you do not configure this policy setting,
script code on pages in the zone is prevented from running.

Default Value-Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3)

Plugin: Windows

Control ID: 7378c2058df633a20ee65946ac01eb9c7288d08d95e600536e46d8e88af8c985