8.9 Set 'Security Zones: Do not allow users to add/delete sites' to 'Enabled'

Information

*Description*

Enable this policy setting to disable the site management settings for security zones. (To
see the site management settings for security zones, open Internet Explorer, select Tools
and then Internet Options, click the Security tab, and then click Sites.) If this policy setting
is disabled or not configured, users will be able to add or remove Web sites in the Trusted
Sites and Restricted Sites zones, as well as alter settings in the Local Intranet zone. Note If
you enable the Disable the Security page setting (located in \User Configuration\
Administrative Templates\Windows Components\Internet Explorer\Internet Control
Panel), the Security tab is removed from the interface and the Disable setting takes
precedence over this Security Zones- setting. The recommended state for this setting is-
Enabled.

*Rationale*

If you do not configure this policy setting, users will be able to add or remove sites from the
Trusted Sites and Restricted Sites zones at will and change settings in the Local Intranet
zone. This configuration could allow sites that host malicious mobile code to be added to
these zones, which users could execute.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Zones- Do not allow users to add/delete sites

Impact-Users will not be able to change site management settings for security zones that have been
established by the administrator. When users need to add or remove sites from these
Internet Explorer security zones, an administrator will have to configure them. Intranet
zone. This may impact some business applications if users access them using a URL that
appears to be from the Internet. For example, in order to utilize all of the capabilities of
Infopath Internet Explorer needs to run the content in the Intranet or Trusted Sites zone.
However, if URL provided is an IP address or a fully qualified domain name IE will instead
run it in the Internet zone. You can overcome issues such as this by adding the URLs to the
Trusted Sites zone.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: d9070b5ac9ce09e23c60f59b6eebd1c84179af9df09d24cf1263d93d9663d3b1