8.1.4 Set 'Turn on Cross-Site Scripting (XSS) Filter' to 'Enabled:Enable'

Information



This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and
prevent cross-site script injections into websites in this zone. If you enable this policy
setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block
cross-site script injections. If you disable this policy setting, the XSS Filter is turned off for
sites in this zone, and Internet Explorer permits cross-site script injections. The
recommended state for this setting is- Enabled-Enable.

*Rationale*

The Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into
websites in this zone

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Cross-Site
Scripting Filter
Then set the Turn on Cross-Site Scripting (XSS) Filter option to Enable.

Impact-If you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS
Filter attempts to block cross-site script injections. If you disable this policy setting, the XSS
Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script
injections.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Windows

Control ID: 62d09f2f42822cf376af426ca2789661eac8dc3e092b37de4415b7fba81fb930