DTOO314 - Default message format must be set to use Plain Text.

Information

Outlook uses HTML as the default email format. HTML format poses a security risk by embedding information into the email itself, which could allow for release of sensitive information. If a user attempted to insert an HTML link into an email message, the link itself may direct to a malicious website. By sending in that format, the recipient would be subject to becoming infected by the malicious website.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2013 -> Outlook Options -> Mail Format -> Internet Formatting -> Message Format 'Set message format' to 'Enabled: Plain Text'.

See Also

https://iasecontent.disa.mil/stigs/zip/U_MS_Outlook_2013_V1R13_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-54062r1_rule, STIG-ID|DTOO314, Vuln-ID|V-26634

Plugin: Windows

Control ID: 490be6b3aac7c2bc00b89f1c8628eceec19b6f065f2b846fc5e25a177cdcc7fe