8.3.5 Set 'Allow file downloads' to 'Enabled:Disable'

Information

*Description*

This policy setting allows you to manage whether file downloads are permitted from the
zone. This option is determined by the zone of the page with the link causing the download,
not the zone from which the file is delivered. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

Sites located in the Restricted Sites Zone are more likely to contain malicious payloads and
therefor downloads from this zone should be blocked.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow file
downloads\Allow file downloads

Then set the Allow file downloads option to Disable.

Impact-If you enable this policy setting, files can be downloaded from the zone. If you disable this
policy setting, files are prevented from being downloaded from the zone. If you do not
configure this policy setting, files are prevented from being downloaded from the zone.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Windows

Control ID: a23ddee27437b13e8f454ede73777720c990f77e42f6a2f1fc23fa4448cffba1