1.2.5.1.5 (L1) Ensure 'Information Bar' is set to 'Enabled'

Information

This policy setting determines whether the Information Bar is displayed for Internet Explorer processes when file or code installs are restricted. By default, the Information Bar is displayed for Internet Explorer processes.

The recommended state for this setting is: Enabled: groove.exe, excel.exe, mspub.exe, powerpnt.exe, pptview.exe, visio.exe, winproj.exe, winword.exe, outlook.exe, spDesign.exe, exprwd.exe, msaccess.exe, onent.exe, mse7.exe

The information bar can help users to understand when potentially malicious content has been blocked. Some users may be confused, however, by the appearance of the bar or unsure about how to respond.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: check all applications :

Microsoft Office 2016 (Machine)\Security Settings\IE Security\Information Bar

Impact:

The security bar will be enabled for each of the specified applications.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18

Plugin: Windows

Control ID: 2b219144ec0a548c92e061e36606acc4499b6821a8f1d1da8dd486e3e4a8910a