DISA STIG Microsoft InfoPath 2013 v1r6

Audit Details

Name: DISA STIG Microsoft InfoPath 2013 v1r6

Updated: 8/21/2024

Authority: DISA STIG

Plugin: Windows

Revision: 1.0

Estimated Item Count: 25

File Details

Filename: DISA_STIG_Microsoft_InfoPath_2013_v1r6.audit

Size: 47 kB

MD5: eddbcb631b0058ea805b0b9b852e55a4
SHA256: 0fdb19dbd0ec01b2a5d82df319d4e767cfc8c5cda3aed25449f25b1d9d5fe2ca

Audit Items

DescriptionCategories
DISA_STIG_Microsoft_InfoPath_2013_v1r6.audit from DISA Microsoft InfoPath 2013 v1r6 STIG
DTOO127 - Add-ins to Office applications must be signed by a Trusted Publisher.

CONFIGURATION MANAGEMENT

DTOO131 - Trust Bar Notifications for unsigned application add-ins must be blocked.

CONFIGURATION MANAGEMENT

DTOO133 - All automatic loading from Trusted Locations must be disabled.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO156 - Offline Mode capability to cache queries for offline mode must be configured.

CONFIGURATION MANAGEMENT

DTOO157 - Redirection behavior for upgraded web sites by SharePoint must be blocked.

SYSTEM AND INFORMATION INTEGRITY

DTOO158 - Disabling the opening of solutions from the Internet Security Zone must be configured.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO159 - Disabling of Fully Trusted Solutions access to computers must be configured.

CONFIGURATION MANAGEMENT

DTOO160 - Unsafe file types must be prevented from being attached to InfoPath forms.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO164 - Beaconing UI shown for opened forms must be configured.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO165 - Beaconing of UI forms with ActiveX controls must be enforced.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO167 - Opening behavior for Email forms containing code or scripts must be controlled.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO168 - Disabling sending form templates with the email forms must be configured.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO169 - Disable dynamic caching of the form template in InfoPath eMail forms.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO170 - InfoPath 2003 forms as email forms in InfoPath 2013 must be disallowed.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO171 - Disabling email forms running in Restricted Security Level must be configured.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO172 - Disabling email forms from the Internet Security Zone must be configured.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO173 - Disabling of email forms from the Full Trust Security Zone must be configured.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO176 - Email with InfoPath forms must be configured to show UI to recipients.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO294 - InfoPath must be enforced to not use email forms from the Intranet security zone.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO295 - InfoPath email forms in Outlook must be disallowed.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO296 - Disabling opening forms with managed code from the Internet security zone must be configured.

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO297 - A form that is digitally signed must be displayed with a warning.

CONFIGURATION MANAGEMENT

DTOO309 - The InfoPath APTCA Assembly Allowable List must be enforced.

CONFIGURATION MANAGEMENT

DTOO999-InfoPath13 - The version of InfoPath running on the system must be a supported version.

SYSTEM AND INFORMATION INTEGRITY