2.5.14.7 Ensure 'Do not automatically sign replies' is set to 'Disabled'

Information

This policy setting specifies whether replies will be automatically (digitally) signed.

The recommended state for this setting is: Disabled.

Rationale:

Disabling this setting and allowing automatic digital signatures will ensure the original sender of a signed message also receives a signed one in return. Breaking the integrity in this trust relationship may cause the other party to disregard the sender's message, causing information and trust to be lost.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Do not automatically sign replies

Default Value:

Disabled. (A signed response will be the default reply to a signed message.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1)

Plugin: Windows

Control ID: f0b58f5e254b52ed161a20b8afa61d5a507016fb359f4d87263ebbe0ad7101ad