5.12 Ensure the spoofed domains report is review weekly

Information

Use spoof intelligence in the Security Center on the Anti-spam settings page to review all senders who are spoofing either domains that are part of your organization, or spoofing external domains. Spoof intelligence is available as part of Office 365 Enterprise E5 or separately as part of Defender for Office 365 and as of October, 2018 Exchange Online Protection (EOP).

Rationale:

Bad actors spoof domains to trick users into conducting actions they normally would not or should not via phishing emails.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To review the report, use the Microsoft 365 Admin Center:

Go to Security.

Under Email & collaboration click on Policies & rules then select Threat policies.

Under Rules click on Tenant Allow / Block Lists then select Spoofing.

Review.

To verify mailbox auditing is enabled for all users, use the Exchange Online PowerShell Module:

Connect to Exchange Online using Connect-EXOPSSession.

Run the following PowerShell command:

Get-PhishFilterPolicy -Detailed -SpoofAllowBlockList -SpoofType Internal

Review.

See Also

https://workbench.cisecurity.org/files/3729

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-6, 800-53|AU-6(1), 800-53|AU-7(1), CSCv7|6.2

Plugin: microsoft_azure

Control ID: 19d4f73066c28be357f3eb1f896341986ca272e94eff89b3a3b7bc579b0aa009