2.5.14.2.4 (L1) Ensure 'Message Formats' is set to 'Enabled: S/MIME'

Information

This policy setting controls which message encryption formats Outlook can use. Outlook supports three formats for encrypting and signing messages: S/MIME, Exchange, and Fortezza.

The recommended state for this setting is: Enabled: S/MIME

E-mail typically travels over open networks and is passed from server to server. Messages are therefore vulnerable to interception, and attackers might read or alter their content. It is therefore important to have a mechanism for signing messages and providing end-to-end encryption.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: S/MIME :

Microsoft Outlook 2016\Security\Cryptography\Message Formats

Impact:

None - This is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: b776c523f65d4576c5469e6989ab6d8d6212e21d18f839293a32384f6930f447