8.3.33 Set 'Software channel permissions' to 'Enabled:High safety'

Information



This policy setting allows you to manage software channel permissions. If you enable this
policy setting, you can choose the following options from the drop-down box- Low safety
allows a user to be notified of software updates by e-mail, software packages to be
automatically downloaded to a user's computers, and software packages to be
automatically installed on a user's computers. Medium safety allows a user to be notified of
software updates by e-mail and software packages to be automatically downloaded to (but
not installed on) a user's computers. High safety prevents a user from being notified of
software updates by e-mail, and from having software packages automatically downloaded
or automatically installed on the user's computers. If you disable this policy setting,
permissions are set to High safety. The recommended state for this setting is-
Enabled-High safety.

*Rationale*

Any setting lower than High Safety could cause a user to install software that includes
malicious code.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Software channel
permissionsThen set the Software channel permissions option to High safety.

Impact-There should be no impact since the recommended setting is also the default.

Default Value-High safety

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: 3011816e052c7d5c2b0da3b3122cfeded2202ec69622b57739d2816da8fa35f3