2.10 Ensure that the SharePoint Online Web Part Gallery component is configured with limited access

Information

For each SharePoint web application, the platform should be configured to prevent users from accessing the Online Web Part Gallery.
Rationale:
Web parts are reusable components that render sections of a SharePoint Web page. The available web parts are displayed in the Web Parts Gallery, which is a collection of web parts located on the internet. The Online Gallery could contain Web Parts from unknown third parties, which could increase the risk of a malicious code execution attack. Preventing users from accessing the Online Web Part Gallery decreases the system's attack surface.

Solution

Login to Central Administration.
Navigate to Security > Manage Web Part Security
For each web application in the web application section, perform the following:
* Select the correct web application in the web application section.
* Select the 'Prevents users from accessing the Online Web Part Gallery, and helps to
improve security and performance' option in the Online Web Part Gallery section.

See Also

https://workbench.cisecurity.org/files/2031

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CSCv6|14

Plugin: Windows

Control ID: 340432e5f9bb8c7fa3767f7834ed0daa6e52a66a8b55d5d2b65a8d663c24cf77