2.5.14.2.4 Ensure 'Message Formats' is set to 'Enabled: S/MIME'

Information

This policy setting controls which message encryption formats Outlook can use. Outlook supports three formats for encrypting and signing messages: S/MIME, Exchange, and Fortezza.

The recommended state for this setting is: Enabled: S/MIME.

Rationale:

E-mail typically travels over open networks and is passed from server to server. Messages are therefore vulnerable to interception, and attackers might read or alter their content. It is therefore important to have a mechanism for signing messages and providing end-to-end encryption.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: S/MIME:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Security\Cryptography\Message Formats

Default Value:

Disabled. (S/MIME is used to encrypt and sign.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 24de872ca0c6646050e19792fc07d1f4d606c5a751861f60fc40512093348c67