DTOO219 - Outlook - Access restriction settings for published calendars in Outlook.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

By default, users can share their calendars with others by publishing them to the Microsoft Office Online Calendar Sharing Services and to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Office Online allows users to choose whether to restrict access to their calendars to people they invite, or allow unrestricted access to anyone who knows the URL to reach the calendar. DAV access restrictions can only be achieved through server and folder permissions, and might require the assistance of a server administrator to set up and maintain.
If a calendar is visible to anyone on Office Online or third-party DAV servers, sensitive information might be revealed contained in calendar appointments.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Calendar Options -> Microsoft Office Online Sharing Service 'Access to published calendars' will be set to 'Enabled'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-20, CAT|II, Rule-ID|SV-18641r2_rule, STIG-ID|DTOO219, Vuln-ID|V-17546

Plugin: Windows

Control ID: 4e00fac554627b8976b73fa15f98a1a6d3efd9adb0f51aa6cedc7c5333b6c1bd