8.3.26 Set 'Software channel permissions' to 'Enabled:High safety'

Information

*Description*

This policy setting allows you to manage software channel permissions. If you enable this
policy setting, you can choose the following options from the drop-down box- Low safety
allows a user to be notified of software updates by e-mail, software packages to be
automatically downloaded to a user's computers, and software packages to be
automatically installed on a user's computers. Medium safety allows a user to be notified of
software updates by e-mail and software packages to be automatically downloaded to (but
not installed on) a user's computers. High safety prevents a user from being notified of
software updates by e-mail, and from having software packages automatically downloaded
or automatically installed on the user's computers. If you disable this policy setting,
permissions are set to High safety. The recommended state for this setting is-
Enabled-High safety.

*Rationale*

Any setting lower than High Safety could cause a user to install software that includes
malicious code.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Software channel
permissions\Software channel permissions

Then set the Software channel permissions option to High safety.


Impact-There should be no impact since the recommended setting is also the default.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: e7f345ab1faca2adb4444bcd9197d42eaf80a8fc18edcdf7fe4bc18aaff49eb3