800-53|SC-7(4)

Title

EXTERNAL TELECOMMUNICATIONS SERVICES

Description

The organization:

Reference Item Details

Related: SC-8

Category: SYSTEM AND COMMUNICATIONS PROTECTION

Parent Title: BOUNDARY PROTECTION

Family: SYSTEM AND COMMUNICATIONS PROTECTION

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.4.1.8 Ensure 'Navigate URL' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.1.4.1.13 Ensure 'Saved from URL' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.2.1 Ensure 'Configure the list of domains on which Safe Browsing will not trigger warnings' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
1.2.2 Ensure 'Safe Browsing Protection Level' is set to 'Enabled: Safe Browsing is active in the standard mode.' or higherWindowsCIS Google Chrome L1 v3.0.0
1.3.3 Ensure 'Control use of insecure content exceptions' is set to 'Enabled: Do not allow any site to load mixed content'WindowsCIS Microsoft Edge L1 v2.0.0
1.3.10 Ensure 'Password Profiles' do not existPalo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.4.2 Verify that the scheduler API service is protected by RBACOpenShiftCIS RedHat OpenShift Container Platform 4 v1.5.0 L1
1.8 Ensure 'Control SafeSites adult content filtering' is set to 'Enabled: Filter top level sites (but not embedded iframes) for adult content'WindowsCIS Google Chrome L2 v3.0.0
1.25 Ensure 'List of names that will bypass the HSTS policy check' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
1.27 Ensure 'Suppress lookalike domain warnings on domains' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
2.2.1 Ensure 'Control use of insecure content exceptions' is set to 'Enabled: Do not allow any site to load mixed content'WindowsCIS Google Chrome L1 v3.0.0
2.12 Ensure 'Allow proceeding from the SSL warning page' is set to 'Disabled'WindowsCIS Google Chrome L2 v3.0.0
2.13 Ensure 'Disable proceeding from the Safe Browsing warning page' is set to 'Enabled'WindowsCIS Google Chrome L1 v3.0.0
2.15 Ensure 'Force Google SafeSearch' is set to 'Enabled'WindowsCIS Google Chrome L2 v3.0.0
3.1 Disable Network PrefetchUnixCIS Mozilla Firefox 102 ESR Linux L1 v1.0.0
3.1 Disable Network PrefetchWindowsCIS Mozilla Firefox 102 ESR Windows L1 v1.0.0
4.2 Ensure 'Applications and Threats Update Schedule' is set to download and install updates at daily or shorter intervalsPalo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
4.2 Ensure 'Applications and Threats Update Schedule' is set to download and install updates at daily or shorter intervalsPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
18.9.47.5.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC
18.9.47.5.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + BL + NG
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + BL
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + NG
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + BL
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + NG
18.10.43.4.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + BL + NG
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + NG
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL + NG
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1 + BL
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2022 v2.0.0 L1 MS
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2016 MS L1 v2.0.0
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + NG
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2016 DC L1 v2.0.0
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1 + BL
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2019 MS L1 v2.0.0
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2019 DC L1 v2.0.0
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL + NG
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2022 v2.0.0 L1 DC
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2019 Standalone DC L1 vCIS Microsoft Windows Server 2019 Standalone DC L1 v1.0.0
18.10.43.6.3.1 Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' - Enabled: BlockWindowsCIS Microsoft Windows Server 2019 MS Standalone L1 v1.0.0
20.12 Ensure 'Unnecessary websites are blocked'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1