8.3.23 Set 'Allow file downloads' to 'Enabled:Disable'

Information



This policy setting allows you to manage whether file downloads are permitted from the
zone. This option is determined by the zone of the page with the link causing the download,
not the zone from which the file is delivered. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

Sites located in the Restricted Sites Zone are more likely to contain malicious payloads and
therefor downloads from this zone should be blocked.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow file
downloadsThen set the Allow file downloads option to Disable.

Impact-
If you enable this policy setting, files can be downloaded from the zone. If you disable this
policy setting, files are prevented from being downloaded from the zone. If you do not
configure this policy setting, files are prevented from being downloaded from the zone.

Default Value-Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Windows

Control ID: 7f769441cccf76aa2b4e2d0067e5794d9a51982ff09ef71633431a3eca782e5a