2.5.14.3.22 (L1) Ensure 'Minimum encryption settings' is set to 'Enabled: 256'

Information

This policy setting allows the configuration of the minimum cryptographic key length for encrypting e-mail messages.

The recommended state for this setting is: Enabled: 256

Cryptographic keys are used to encrypt and decrypt messages for transmission through unsecured channels. Key sizes are measured in bits, with larger keys generally less vulnerable to attack than smaller ones. 40-bit and 56-bit keys were common in the past, but as computers have become faster and more powerful these smaller key sizes have become vulnerable to brute-force attacks in which the attacking computer rapidly runs through every possible key combination until it successfully decrypts the message. The Advanced Encryption Standard (AES) published by the United States government requires a minimum key size of 128 bits for symmetric encryption, which offers significantly more protection against brute-force attack than smaller key sizes.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: 256 :

Microsoft Outlook 2016\Security\Security Form Settings\Outlook Security Mode > Minimum encryption settings

Important: For this setting to apply, the

Outlook Security Mode

setting must be enabled in

Microsoft Outlook 2016\Security\Security Form Settings

with Use Outlook Security Group Policy selected, as set in this benchmark.

Impact:

Users who see the minimum encryption warning display can still choose to send the message with the selected key, so little to no impact is expected.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 09348f11601d5a278ab0e3d2bdc6e8072348e8421fdd6ba22948994e54122650