2.5.9.2.1 Ensure 'PST Null Data on Delete' is set to 'Enabled'

Information

This policy setting controls whether or not Outlook is forced to fully nullify deleted data in users' Personal Folder files (.pst) at the time that the data is deleted.

NOTE: This setting does not apply to (.ost) files generated when Outlook is connected to either Exchange or Exchange Online.

The recommended state for this setting is: Enabled.

Rationale:

When a user deletes mail or other items in Outlook, the data is retained in a portion of the PST file until it is purged or overwritten. Attackers could potentially recover the data by using PST recovery tools. Nulling the data at deletion time will impede this.

Impact:

Forensics and data recovery of objects permanently removed by a user taking action to empty their Outlook trash bin will be made more difficult. These will need to be recovered by another method such as a system backup.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Miscellaneous\PST Settings\PST Null Data on Delete

Default Value:

Disabled. (Data remains in the PST files until it is purged or overwritten by the user.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-6

Plugin: Windows

Control ID: 2e7601447f14a293ad3bf40129420492b21b95030313f137e7b0112d23f1fc22