8.3.16 Set 'Java permissions' to 'Enabled:Disable Java'

Information

*Description*

This policy setting allows you to manage permissions for Java applets. The recommended
state for this setting is- Enabled-Disable Java.

*Rationale*

Java applications could contain malicious code, sites located in this security zone are more
likely to be hosted by malicious people.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Java
permissions\Java permissions

Then set the Java permissions option to Disable Java.

Impact-If you enable this policy setting, you can choose options from the drop-down box. Custom,
to control permissions settings individually. Low Safety enables applets to perform all
operations. Medium Safety enables applets to run in their sandbox (an area in memory
outside of which the program cannot make calls), plus capabilities like scratch space (a safe
and secure storage area on the client computer) and user-controlled file I/O. High Safety
enables applets to run in their sandbox. Disable Java to prevent any applets from running. If
you disable this policy setting, Java applets cannot run. If you do not configure this policy
setting, the permission is set to High Safety.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Windows

Control ID: 2258f21e9ef917cd999acdf3adb45716478328040927d385879b6beac9f8f51f