CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
Audit:
Navigate to the UI Path articulated in the Remediation section and confirm it is set as prescribed. This group policy setting is backed by the following registry location:
HKEY_USERS\[USER SID]\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments:SaveZoneI nformation
Remediation:
To establish the recommended configuration via GP, set the following UI path to Disabled :
User Configuration\Policies\Administrative Templates\Windows Components\Attachment Manager\Do not preserve zone information in file attachments
Note: This Group Policy path is provided by the Group Policy template AttachmentManager.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.
Impact:
None - this is the default behavior.
Default Value:
Disabled. (Windows marks file attachments with their zone information.)
References:
1. CCE-34810-2
CIS Controls:
Version 6
7 Email and Web Browser Protections Email and Web Browser Protections
Version 7
7.1 Ensure Use of Only Fully Supported Browsers and Email Clients Ensure that only fully supported web browsers and email clients are allowed to execute in the organization, ideally only using the latest version of the browsers and email clients provided by the vendor.
1210 | P a g e
Made with FlippingBook - Online magazine maker