2.5.14.2.5 Ensure 'Minimum encryption settings' is set to 'Enabled: 256'

Information

This policy setting allows the configuration of the minimum cryptographic key length for encrypting e-mail messages.

The recommended state for this setting is: Enabled: 256.

Rationale:

Cryptographic keys are used to encrypt and decrypt messages for transmission through unsecured channels. Key sizes are measured in bits, with larger keys generally less vulnerable to attack than smaller ones. 40-bit and 56-bit keys were common in the past, but as computers have become faster and more powerful these smaller key sizes have become vulnerable to brute-force attacks in which the attacking computer rapidly runs through every possible key combination until it successfully decrypts the message. The Advanced Encryption Standard (AES) published by the United States government requires a minimum key size of 128 bits for symmetric encryption, which offers significantly more protection against brute-force attack than smaller key sizes.

Impact:

Users who see the minimum encryption warning display can still choose to send the message with the selected key, so little to no impact is expected.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 256:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Cryptography\Minimum encryption settings

Default Value:

Disabled. (Dialog warning will be shown to the user if the user attempts to send a message using encryption. The user can still choose to ignore the warning and send using the encryption key originally chosen.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 4aad988432ff7427fe2f96f350507b9983bc02eeeae183bb52da365f5b1a9ad8