1.1.3.3.2 Ensure only allow specified file types is set to enabled

Information

Hosts and participants can send files through the in-meeting chat. And that too only the file types that are whitelisted. Provide the list of filetype that needs to be whitelisted e.g. .txt, .docx, .pdf, .xlsx

Rationale:

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Go into the Zoom Admin Dashboard on the zoom website. Account Management -> Account Settings -> Meeting -> In Meeting (Basic) -> Only allow specified file types, and ensure it is enabled (i.e. checkbox enabled).

See Also

https://workbench.cisecurity.org/files/2986

Item Details

Audit Name: CIS Zoom L2 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|5.1

Plugin: Zoom

Control ID: 6028ebb2c47492d255817297ca8bd991232d748c0415b6562bcc3b39e8fb2288