CIS Mozilla Firefox ESR GPO v1.0.0 L1

Audit Details

Name: CIS Mozilla Firefox ESR GPO v1.0.0 L1

Updated: 1/6/2025

Authority: CIS

Plugin: Windows

Revision: 1.0

Estimated Item Count: 52

File Details

Filename: CIS_Mozilla_Firefox_ESR_GPO_v1.0.0_L1.audit

Size: 99.2 kB

MD5: de3f3d55fe35383abcee28de07ed4777
SHA256: 36b4d4c1b71673be8784c67eb8001b393730eb391152f7f94a576cb5d6825002

Audit Items

DescriptionCategories
1.1.1.1 (L1) Ensure 'Allow add-on installs from websites' is set to 'Disabled'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.2.1 (L1) Ensure 'NTLM' is set to 'Disabled'

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.5.1 (L1) Ensure 'Active Logins' is set to 'Disabled'

CONFIGURATION MANAGEMENT

1.1.5.2 (L1) Ensure 'Browsing History' is set to 'Disabled'

CONFIGURATION MANAGEMENT

1.1.5.3 (L1) Ensure 'Download History' is set to 'Disabled'

CONFIGURATION MANAGEMENT

1.1.5.4 (L1) Ensure 'Form & Search History' is set to 'Disabled'

CONFIGURATION MANAGEMENT

1.1.5.5 (L1) Ensure 'Locked' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.6.1 (L1) Ensure 'Cookie Behavior' is set to 'Enabled: Reject cookies for known trackers and partition third-party cookies'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.6.2 (L1) Ensure 'Cookie Behavior in private browsing' is set to 'Enabled: Reject cookies for known trackers and partition third-party cookies'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.7.1 (L1) Ensure 'TLS_RSA_WITH_3DES_EDE_CBC_SHA ' is set to 'Enabled'

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.9.1 (L1) Ensure 'Lock Encrypted Media Extensions' is set to 'Enabled'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.10.1 (L1) Ensure 'Extension Update' is set to 'Enabled'

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.12.1 (L1) Ensure 'Activate Flash on websites' is set to 'Disabled'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.15.3.1 (L1) Ensure 'Block new requests asking to access location' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

1.1.15.3.2 (L1) Ensure 'Do not allow preferences to be changed' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.17.1 (L1) Ensure 'Block pop-ups from websites' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

1.1.17.2 (L1) Ensure 'Do not allow preferences to be changed' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.18.1 (L1) Ensure 'browser.safebrowsing.malware.enabled' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

1.1.18.2 (L1) Ensure 'browser.safebrowsing.phishing.enabled' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

1.1.18.3 (L1) Ensure 'browser.search.update' is set to 'Enabled'

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.18.4 (L1) Ensure 'dom.allow_scripts_to_close_windows' is set to 'Disabled'

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.18.5 (L1) Ensure 'dom.disable_window_flip' is set to 'Enabled'

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.18.6 (L1) Ensure 'dom.disable_window_move_resize' is set to 'Enabled'

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.18.7 (L1) Ensure 'extensions.blocklist.enabled' is set to 'Enabled'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.18.8 (L1) Ensure 'media.peerconnection.enabled' is set to 'Disabled'

CONFIGURATION MANAGEMENT

1.1.18.10 (L1) Ensure 'security.mixed_content.block_active_content' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

1.1.19.1 (L1) Ensure 'Connection Type' is set to 'Enabled: No Proxy'

CONFIGURATION MANAGEMENT

1.1.19.2 (L1) Ensure 'Do not allow proxy settings to be changed' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.22.1 (L1) Ensure 'Cryptomining' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

1.1.22.2 (L1) Ensure 'Do not allow tracking protection preferences to be changed' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.22.3 (L1) Ensure 'Email Tracking' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

1.1.22.4 (L1) Ensure 'Enabled' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.22.5 (L1) Ensure 'Fingerprinting' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

1.1.23.1 (L1) Ensure 'Extension Recommendations' is set to 'Disabled'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.24 (L1) Ensure 'Application Autoupdate' is set to 'Enabled'

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.25 (L1) Ensure 'Background updater' is set to 'Enabled'

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.26 (L1) Ensure 'Disable Developer Tools' is set to 'Enabled'

CONFIGURATION MANAGEMENT

1.1.27 (L1) Ensure 'Disable Feedback Commands' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.28 (L1) Ensure 'Disable Firefox Accounts' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

1.1.29 (L1) Ensure 'Disable Firefox Studies' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

1.1.30 (L1) Ensure 'Disable Forget Button' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY

1.1.32 (L1) Ensure 'Disable Pocket' is set to 'Enabled'

CONFIGURATION MANAGEMENT

1.1.33 (L1) Ensure 'Disable Private Browsing' is set to 'Enabled'

CONFIGURATION MANAGEMENT

1.1.34 (L1) Ensure 'Disable System Addon Updates' is set to 'Disabled'

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.35 (L1) Ensure 'Disable Telemetry' is set to 'Enabled'

CONFIGURATION MANAGEMENT

1.1.36 (L1) Ensure 'Disable Update' is set to 'Disabled'

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.37 (L1) Ensure 'Maximum SSL version enabled' is set to 'Enabled: TLS 1.3'

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.38 (L1) Ensure 'Minimum SSL version enabled' is set to 'Enabled: TLS 1.2'

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.39 (L1) Ensure 'Network Prediction' is set to 'Disabled'

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.41 (L1) Ensure 'Offer to save logins' is set to 'Disabled'

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY