DTOO314 - The default message format must be set to use Plain Text.

Information

Outlook uses HTML as the default email format. HTML format poses a security risk by embedding information into the email itself, which could allow for release of sensitive information. If a user attempted to insert an HTML link into an email message, the link itself may direct to a malicious website. By sending emails in HTML format, the recipient could be subject to becoming infected by the malicious website.

Solution

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Outlook 2016 >> Outlook Options >> Mail Format >> Internet Formatting >> Message Format 'Set message format' to 'Enabled: Plain Text'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Outlook_2016_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-251866r811197_rule, STIG-ID|DTOO314, STIG-Legacy|SV-57685, STIG-Legacy|V-44851, Vuln-ID|V-251866

Plugin: Windows

Control ID: bb7dc00ba5caf7d192b3133900272b7f68f34d413b984083351be295e655b85a