18.9.24.3 Ensure 'Default Protections for Internet Explorer' is set to 'Enabled'

Information

This setting determines if recommended EMET mitigations are applied to Internet Explorer.

The recommended state for this setting is: Enabled.

Rationale:

Applying EMET mitigations to Internet Explorer will help reduce the reliability of exploits that target it.

Impact:

EMET mitigations will be applied to Internet Explorer.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\EMET\Default Protections for Internet Explorer

Note: This Group Policy path does not exist by default. An additional Group Policy template (EMET.admx/adml) is required - it is included with Microsoft Enhanced Mitigation Experience Toolkit (EMET).

Default Value:

User configured.

See Also

https://workbench.cisecurity.org/benchmarks/14249

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SC-39, 800-53|SI-16, CCE|CCE-35474-6, CSCv7|8.3

Plugin: Windows

Control ID: c3c8bfddf721834c0c9bfb15fa25a8de8f5a260a336db54dc5a3393db7f9419e