2.5.10.4.2.2 (L1) Ensure 'Plain Text Options' is set to 'Disabled'

Information

This policy setting controls how plain text messages are formatted when they are sent from Outlook.

The recommended state for this setting is: Disabled

If UUENCODE formatting is used, an attacker could manipulate the encoded attachment to bypass content filtering software. By default, Outlook automatically wraps plain text messages at 76 characters and uses the standard MIME format to encode attachments in plain text messages. However, these settings can be altered to allow e-mail to be read in plain text e-mail programs that use a non-standard line length or that cannot process MIME attachments.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Outlook 2016\Outlook Options\Mail Format\Internet Formatting\Plain text options

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 207cf9aba57715f9b7050a80682799517426ea6a8a3cb566df5273b22f6cacdd