800-53|SC-18(3)

Title

PREVENT DOWNLOADING / EXECUTION

Description

The information system prevents the download and execution of [Assignment: organization-defined unacceptable mobile code].

Reference Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

Parent Title: MOBILE CODE

Family: SYSTEM AND COMMUNICATIONS PROTECTION

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1 (L1) Ensure 'Open 'safe' files after downloading' is 'Disabled'UnixCIS MacOS Safari v2.0.0 L1
1.1.5.1 Ensure 'Automatically download attachments' is set to DisabledWindowsCIS Microsoft Office Outlook 2013 v1.1.0 Level 1
1.1.5.1 Ensure 'Automatically download attachments' is set to DisabledWindowsCIS Microsoft Office Outlook 2016 v1.1.0 Level 1
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - excel.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - exprwd.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - groove.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - msaccess.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - mse7.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - mspub.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - onent.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - outlook.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - powerpnt.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - pptview.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - spDesign.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - visio.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.2.1.14 Ensure 'Restrict ActiveX Install' is set to Enabled - winproj.exeWindowsCIS Microsoft Office 2016 v1.1.0
1.3 Enable 'Prevent users from bypassing SmartScreen Filter's application reputation warnings about files that are not commonly downloaded'WindowsCIS IE 9 v1.0.0
1.4 Set 'Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet' to 'Enabled'WindowsCIS IE 10 v1.1.0
1.4 Set 'Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet' to 'Enabled'WindowsCIS IE 11 v1.0.0
1.4.1.1.2 Ensure 'Load Pictures from Web Pages Not Created in Excel' is set to DisabledWindowsCIS Microsoft Office Excel 2013 v1.0.1
1.4.1.1.2 Ensure 'Load Pictures from Web Pages Not Created in Excel' is set to DisabledWindowsCIS Microsoft Office Excel 2016 v1.0.1
1.6.6.7 Ensure 'Unblock Automatic Download of Linked Images' is set to DisabledWindowsCIS Microsoft Office PowerPoint 2013 v1.0.1
1.6.6.7 Ensure 'Unblock Automatic Download of Linked Images' is set to DisabledWindowsCIS Microsoft Office PowerPoint 2016 v1.0.1
1.7 Set 'Automatically download attachments' to 'Disabled'WindowsCIS MS Office Outlook 2010 v1.0.0
1.8 Set 'Automatically download content for e- mail from people in Safe Senders and Safe Recipients Lists' to 'Disabled'WindowsCIS MS Office Outlook 2010 v1.0.0
1.8.1.3 Ensure 'Update Automatic Links at Open' is set to DisabledWindowsCIS Microsoft Office Word 2016 v1.1.0
1.8.1.3 Ensure 'Update Automatic Links at Open' is set to DisabledWindowsCIS Microsoft Office Word 2013 v1.1.0
1.10 Set 'Block Trusted Zones' to 'Enabled'WindowsCIS MS Office Outlook 2010 v1.0.0
1.13 Set 'Display pictures and external content in HTML e- mail' to 'Enabled'WindowsCIS MS Office Outlook 2010 v1.0.0
1.13.1.1 Ensure 'Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists' is set to DisabledWindowsCIS Microsoft Office Outlook 2013 v1.1.0 Level 1
1.13.1.1 Ensure 'Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists' is set to DisabledWindowsCIS Microsoft Office Outlook 2016 v1.1.0 Level 1
1.13.1.2 Ensure 'Block Trusted Zones' is set to EnabledWindowsCIS Microsoft Office Outlook 2013 v1.1.0 Level 1
1.13.1.2 Ensure 'Block Trusted Zones' is set to EnabledWindowsCIS Microsoft Office Outlook 2016 v1.1.0 Level 1
1.13.1.3 Ensure 'Display pictures and external content in HTML e-mail' is set to EnabledWindowsCIS Microsoft Office Outlook 2016 v1.1.0 Level 1
1.13.1.3 Ensure 'Display pictures and external content in HTML e-mail' is set to EnabledWindowsCIS Microsoft Office Outlook 2013 v1.1.0 Level 1
1.13.3.1.5 Ensure 'Remove file extensions blocked as Level 1' is set to DisabledWindowsCIS Microsoft Office Outlook 2013 v1.1.0 Level 1
1.13.3.1.5 Ensure 'Remove file extensions blocked as Level 1' is set to DisabledWindowsCIS Microsoft Office Outlook 2016 v1.1.0 Level 1
1.13.3.1.6 Ensure 'Remove file extensions blocked as Level 2' is set to DisabledWindowsCIS Microsoft Office Outlook 2016 v1.1.0 Level 1
1.13.3.1.6 Ensure 'Remove file extensions blocked as Level 2' is set to DisabledWindowsCIS Microsoft Office Outlook 2013 v1.1.0 Level 1
1.26 Set 'Remove file extensions blocked as Level 1' to 'Disabled'WindowsCIS MS Office Outlook 2010 v1.0.0
1.27 Set 'Remove file extensions blocked as Level 2' to 'Disabled'WindowsCIS MS Office Outlook 2010 v1.0.0
18.9.60.1 Ensure 'Prevent downloading of enclosures' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 v3.2.0
18.9.60.1 Ensure 'Prevent downloading of enclosures' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
19.7.42.2.1 Ensure 'Prevent Codec Download' is set to 'Enabled'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1
19.7.42.2.1 Ensure 'Prevent Codec Download' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L2
19.7.42.2.1 Ensure 'Prevent Codec Download' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + BL
19.7.42.2.1 Ensure 'Prevent Codec Download' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + NG
19.7.42.2.1 Ensure 'Prevent Codec Download' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L2 + BL
19.7.42.2.1 Ensure 'Prevent Codec Download' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + BL + NG
19.7.42.2.1 Ensure 'Prevent Codec Download' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2