8.1.2 Set 'Allow drag and drop or copy and paste files' to 'Enabled:Disable'

Information

*Description*

This policy setting allows you to manage whether users can drag files or copy and paste
files from a source within the zone. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

Content hosted on sites located in the Restricted Sites Zone are more likely to contain
malicious payloads and therefor this feature should be blocked for this zone.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Allow drag and drop or
copy and paste files\Allow drag and drop or copy and paste files

Then set the Allow drag and drop or copy and paste files option to Disable.

Impact-If you enable this policy setting, users can drag files or copy and paste files from this zone
automatically. If you select Prompt in the drop-down box, users are queried to choose
whether to drag or copy files from this zone. If you disable this policy setting, users are
prevented from dragging files or copying and pasting files from this zone.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: 5b718a0da5db78ea56343bf2f34fd99a6691eef8d1550f70152fd62b91b92bf4