2.11 Ensure that the SharePoint Online Web Part Gallery component is configured with limited access

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

For each SharePoint web application, the platform should be configured to prevent users from accessing the Online Web Part Gallery.
Rationale:
Web parts are reusable components that render sections of a SharePoint Web page. The available web parts are displayed in the Web Parts Gallery, which is a collection of web parts located on the internet. The Online Gallery could contain Web Parts from unknown third parties, which could increase the risk of a malicious code execution attack. Preventing users from accessing the Online Web Part Gallery decreases the system's attack surface.

Solution

Login to Central Administration.
Navigate to Security > Manage Web Part Security
For each web application in the web application section, perform the following:
* Select the correct web application in the web application section.
* Select the 'Prevents users from accessing the Online Web Part Gallery, and helps to
improve security and performance' option in the Online Web Part Gallery section.

See Also

https://www.cisecurity.org/benchmark/microsoft_sharepoint/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CSCv6|14

Plugin: Windows

Control ID: 29225f3385f713c3ff9c896919050bd384dd5237e864d8355291f429f0907161