SHPT-00-000240 - SharePoint must retain the notification message or banner on the screen until users take explicit actions to log on to or further access.

Information

To establish acceptance of system usage policy, a click-through banner at application logon is required. The banner shall prevent further activity on the application unless and until the user executes a positive action to agree by clicking on a box indicating 'OK' or agreement with the terms of the banner. The text of this banner should be customizable in the event of future user agreement changes.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the SharePoint Web application home page to not allow any further access until the user executes a positive action to agree.

See Also

https://iasecontent.disa.mil/stigs/zip/U_MS_SharePoint_2010_V1R9_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-8b., CAT|II, CCI|CCI-000050, Rule-ID|SV-36431r1_rule, STIG-ID|SHPT-00-000240, Vuln-ID|V-28254

Plugin: Windows

Control ID: 4d83e5d51d84a7dc075ff088c235bef51301a6e2dfc154eb9b96b03dac79400c