Turn on Cross-Site Scripting Filter - Internet Zone

Information

This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.
If you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.
If you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.

Solution

Policy Path: Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone
Policy Setting Name: Turn on Cross-Site Scripting Filter

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-windows-10-and-windows-server-version/ba-p/1543631

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Windows

Control ID: de168f96212293225b3ecb3e83b1665e5c1032f8140fdaa23793da142f71a3b2