8.3.2 Set 'Allow active scripting' to 'Enabled:Disable'

Information

*Description*

This policy setting allows you to manage whether script code on pages in the zone is run.
The recommended state for this setting is- Enabled-Disable.

*Rationale*

Active scripts hosted on sites located in this zone are more likely to contain malicious code.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.
Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow active
scripting\Allow active scripting

Then set the Allow active scripting option to Disable.

Impact-If you enable this policy setting, script code on pages in the zone can run automatically. If
you select Prompt in the drop-down box, users are queried to choose whether to allow
script code on pages in the zone to run. If you disable this policy setting, script code on
pages in the zone is prevented from running. If you do not configure this policy setting,
script code on pages in the zone is prevented from running.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3)

Plugin: Windows

Control ID: ed7e62b902036a81fa9716aa9c8053458169d6e7877e5a0511c6794eddd22dce