2.5.10.4.2.2 Ensure 'Plain Text Options' is set to 'Disabled'

Information

This policy setting controls how plain text messages are formatted when they are sent from Outlook.

The recommended state for this setting is: Disabled.

Rationale:

If UUENCODE formatting is used, an attacker could manipulate the encoded attachment to bypass content filtering software. By default, Outlook automatically wraps plain text messages at 76 characters and uses the standard MIME format to encode attachments in plain text messages. However, these settings can be altered to allow e-mail to be read in plain text e-mail programs that use a non-standard line length or that cannot process MIME attachments.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Mail Format\Internet Formatting\Plain text options

Default Value:

Disabled. (Users can modify plain text options in Outlook when required by clicking Tools, clicking Options, clicking the Mail Format tab, clicking Internet Format, and changing the values under 'Plain text options'.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1)

Plugin: Windows

Control ID: 9f7030fe9edcb2955a2e7ab2bae3c1742bd655e832ca3c5d5856981cf85987b2