1.8.2.1 Ensure 'PST Null Data On Delete' is set to Enabled

Information

This policy setting allows you to force Outlook to fully nullify deleted data in users' Personal Folder files (.pst) at the time that the data is deleted.

If you enable this policy setting, data is immediately nullified in PST files when deleted.

If you disable or do not configure this policy setting, data remains in PST files until it is purged or overwritten by the user. The recommended state for this setting is: Enabled.

Rationale:

By default, when a users' Personal Folder files (.pst) at the time that the data is deleted, the data inside the .pst file is retained in the available storage. Attackers could potentially recover the data by using tools used to view disk block or recover deleted files.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled.

User Configuration\Administrative Templates\Microsoft Outlook 2016\Miscellaneous\PST Settings

Impact:

Users may experience a delay in deleting a .pst file as it will take some time to write nulls to every location in the .pst file when deleted.

See Also

https://workbench.cisecurity.org/files/553

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 52532e437862c6f17422eee46e51e07e600c0019b4deb56dba09888ebbdb3220