Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
If the following registry value doesn’t exist or is not configured as specified this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ Value Name: Security_HKLM_only Type: REG_DWORD Value: 1
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Security Zones: Use only machine settings” to “Enabled”.
If the following registry value doesn’t exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ Value Name: Security_Options_Edit Type: REG_DWORD Value: 1
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Security Zones: Do Not Allow Users to Change Policies” to “Enabled”.
If the following registry value doesn’t exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ Value Name: Security_Zones_Map_Edit Type: REG_DWORD Value: 1
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Security Zones: Do Not Allow Users to Add/Delete Sites” to “Enabled”.
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Make proxy settings per-machine (rather than per user)” to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ Criteria: If the value ProxySettingsPerUser is REG_DWORD = 1, this is not a finding.
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Make proxy settings per-machine (rather than per user)” to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ Criteria: Set the value ProxySettingsPerUser to REG_DWORD = 1.
If the following registry value doesn’t exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\ Value Name: NoJITSetup Type: REG_DWORD Value: 1
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Disable Automatic Install of Internet Explorer components” to “Enabled”.
If the following registry value doesn’t exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\ Value Name: NoUpdateCheck Type: REG_DWORD Value: 1
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Disable Periodic Check for Internet Explorer Software Updates” to “Enabled”.
If the following registry value exists and its value is not set to 1, then this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ Value Name: NoMSAppLogo5ChannelNotify Type: REG_DWORD Value: 1
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer “Disable Software Update Shell Notifications on Program Launch” to “Enabled”.
Procedure: Open Internet Explorer, Select Help, Select About. Criteria: If the version number of Internet Explorer is any version of Internet Explorer 6, this is a Finding. Note: The end of life for Internet Explorer 6 running on a Windows 2003r2 server is July 14, 2015.
Upgrade to the supported software version.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Internet Explorer\Main Criteria: If the value Start Page is about:blank or a trusted site this is not a finding.
Change Start Page value to about:blank or a trusted site.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value Currrentlevel is 0, this is not a finding.
Change the value of registry HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 to Currentlevel is 0
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value Currrentlevel is 0, this is not a finding.
Change value of registry HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 to Currentlevel is 0
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value Currrentlevel is 0, this is not a finding.
Change the value of registry HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 to Currentlevel is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value Currrentlevel is 0, this is not a finding.
Change the value of registry HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 to Currentlevel is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value Flags is less than or equal to 0x43 (hex) or 67 (Dec), this is not a finding.
Change the value of registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 to Flags is 0x43.
Procedure: From the Tools/Internet Options dialog, Select the Privacy tab and click the Advanced button. Criteria: If the Third-party Cookies are not configured to Block, this is a finding.
Under Tools/Internet Options, select the Privacy Tab and click the Advanced button. Change third party cookies to blocked.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Internet Explorer\Download Criteria: If the value CheckExeSignatures is yes, this is not a finding.
Change the value of registry key HKCU\Software\Microsoft\Internet Explorer\Download to CheckExeSignatures is yes.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings Criteria: If the value DisableCachingOfSSLPages is 1, this is not a finding. If the Do not save encrypted pages to disk is 0 enabled and the permissions of the Temporary Internet files folder are not the same as, or more restrictive than, those in the following table, this is a Finding. variable\Temporary Internet Files(The variable portion of the path name depends on the configuration setting in Internet Explorer.) Administrators ALL CREATOR OWNER ALL SYSTEM ALL [user] ALL
Change the value of registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings to DisableCachingOfSSLPages is 1
Open Internet Explorer. From the menu bar, select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the Advanced tab, from the Advanced tab window scroll down to the Security category. Verify a check mark is placed in 'Use SSL 3.0' and 'Use TLS 1.0' check boxes. Check marks can also be placed in 'Use TLS 1.1' and/or 'Use TLS 1.2'. If so, this is acceptable and not a finding. Verify there is not a check placed in the check box for 'Use SSL 2.0'. If 'Use SSL 2.0' is checked, then this is a finding.
Fix Text: Open Internet Explorer. From the menu bar, select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the Advanced tab, from the Advanced tab window scroll down to the Security category. Place a check mark in 'Use SSL 3.0' and 'Use TLS 1.0' check boxes. Check marks can also be placed in 'Use TLS 1.1' and/or 'Use TLS 1.2'. Uncheck 'Use SSL 2.0' option.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings Criteria: If the value WarnonBadCertRecving value is 1, this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings to the value WarnonBadCertRecving to 1
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings Criteria: If the value WarnonZoneCrossing value is 1, this is not a finding.
Change the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings to the value WarnonZoneCrossing is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings Criteria: If the value WarnOnPostRedirect value is 1, this is not a finding.
Change the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings to the value WarnOnPostRedirect is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel Criteria: If the value AdvancedTab is 1, this is not a finding. If the value is not 1 or the key is not present, this is a finding.
Change the registry key HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel to the value AdvancedTab is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1001 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria:Set the value 1001 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1004 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1004 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1201 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1201 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1405 is REG_DWORD = 1 (Prompt = 1), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1405 is REG_DWORD = 1 (Prompt = 1).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1604 is REG_DWORD = 1 (Prompt = 1), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1604 to REG_DWORD = 1 (Prompt = 1).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1C00 is REG_DWORD = 0 (Disabled = 0), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1C00 to REG_DWORD = 0 (Disabled = 0).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1406 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1406 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1609 is REG_DWORD = 1 (Prompt = 1), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1609 to REG_DWORD = 1 (Prompt = 1).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1A04 is REG_DWORD=3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1A04 to REG_DWORD=3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value for 1802 is REG_DWORD = 3 (Disable= 3) or the value does not exist, this is not a finding.
If a value for this zone is present and not set to 3 change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1802 to REG_DWORD = 3 (Disable= 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1800 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1800 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1804 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1804 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1607 is REG_DWORD = 1 (Prompt = 1), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1607 to REG_DWORD = 1 (Prompt = 1).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1E05 is REG_DWORD = 65536 (High Safety), this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1E05 to REG_DWORD = 65536 (High Safety).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1601 is REG_DWORD = 1 (Prompt), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1601 to REG_DWORD = 1 (Prompt).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1606 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1606 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1407 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1407 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1402 is REG_DWORD = 1 (Prompt), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1402 to REG_DWORD = 1 (Prompt).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: If the value 1A00 is REG_DWORD = 65536 (decimal), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 Criteria: Set the value 1A00 to REG_DWORD = 65536 (decimal).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1001 is REG_DWORD 1 (Prompt), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: Set the value 1001 to REG_DWORD 1 (Prompt).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1004 is REG_DWORD = 3, this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: Set the value 1004 to REG_DWORD = 3.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1201 is REG_DWORD 3, this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: Set the value 1201 to REG_DWORD 3.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1405 is REG_DWORD 1 (Prompt), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: Set the value 1405 to REG_DWORD 1 (Prompt).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1C00 is REG_DWORD = 65536, (High Safety), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: Set the value 1C00 to REG_DWORD = 65536, (High Safety).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1406 is REG_DWORD 1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1406 is REG_DWORD 1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1A04 is REG_DWORD = 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1A04 is REG_DWORD = 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1800 is REG_DWORD 1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1800 is REG_DWORD 1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1804 is REG_DWORD 1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1804 is REG_DWORD 1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1E05 is REG_DWORD = 65536 (High Safety), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1E05 is REG_DWORD = 65536 (High Safety).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1407 is REG_DWORD 1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1407 is REG_DWORD 1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1A00 is REG_DWORD = 0 (Automatically logon with current username and password), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 Criteria: If the value 1A00 is REG_DWORD = 0 (Automatically logon with current username and password).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1001 is REG_DWORD 1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1001 is REG_DWORD 1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1004 is REG_DWORD=3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1004 is REG_DWORD=3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1201 is REG_DWORD=3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1201 is REG_DWORD=3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1405 is REG_DWORD=1 (Prompt), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1405 is REG_DWORD=1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1C00 is REG_DWORD = 65536, (High Safety), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1C00 is REG_DWORD = 65536, (High Safety).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1406 is REG_DWORD=1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1406 is REG_DWORD=1 (Prompt) or 3 (Disabled),.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1A04 is REG_DWORD=3 (Disabled), this is not a finding.
Change the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 to the value 1A04 is 3.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1800 is REG_DWORD=1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1800 is REG_DWORD=1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1804 is REG_DWORD=1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1804 is REG_DWORD=1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1E05 is REG_DWORD=65536 (High Safety), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1E05 is REG_DWORD=65536 (High Safety).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1407 is REG_DWORD=1 (Prompt) or 3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1407 is REG_DWORD=1 (Prompt) or 3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1A00 is REG_DWORD=65536 (Prompt), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 Criteria: If the value 1A00 is REG_DWORD=65536 (Prompt).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1001 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1001 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1004 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1004 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1201 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1201 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1200 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1200 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1405 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1405 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1803 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1803 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1604 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1604 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1406 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1406 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1608 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1608 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1609 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1609 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1A04 is REG_DWORD=3 (Disabled), this is not a finding.
Change the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1A04 is REG_DWORD=3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1802 is REG_DWORD=3 (Disabled), this is not a finding.
Change the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1802 is REG_DWORD=3 (Disabled).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1800 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1800 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1804 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1804 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1607 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1607 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1E05 is REG_DWORD = 65536 (decimal), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1E05 is REG_DWORD = 65536 (decimal).
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security page -> Restricted Sites Zone -> "Submit non-encrypted form data" will be enabled and set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1601 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security page -> Restricted Sites Zone -> "Submit non-encrypted form data" will be enabled and set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: Set the value 1601 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1606 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1606 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1400 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1400 is REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1407 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1407 is REG_DWORD = 3 (Disabled = 3).
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security page -> Restricted Sites Zone -> "Scripting of Java Applets" will be enabled and set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1402 is REG_DWORD = 3 (Disabled = 3), this is not a finding.
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security page -> Restricted Sites Zone -> "Scripting of Java Applets" will be enabled and set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: Set the value 1402 to REG_DWORD = 3 (Disabled = 3).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1A00 is REG_DWORD = 196608 (decimal), this is not a finding.
Change the registry key HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1A00 is REG_DWORD = 196608 (decimal).
Procedure: Search for the msjava.dll file in the %System root%\System32 by using the Start menu “Search | For Files or Folders…” facility. Criteria: If the file exists, this is a finding.
Delete the file msjava.dll in the %System root%\System32 by going to the Start menu, Search | For Files or Folders.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56 Criteria: If the value Enabled is 0xffffffff, this is not a finding. The absence of the key also indicates Not a Finding.
Navigate to registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56 and change the value to Enabled is 0xffffffff.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL Criteria: If the value Enabled is 0x0, this is not a finding. The absence of the key also indicates Not a Finding.
Navigate to registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL and change the value to Enabled is 0x0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168/168 Criteria: If the value Enabled is 0xffffffff, this is not a finding. The absence of the key also indicates Not a Finding.
Navigate to the registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168/168 and change the value to Enabled is 0xffffffff.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\SHA Criteria: If the value Enabled is 0xffffffff, this is not a finding.
Navigate to the registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\SHA and change the value to Enabled is 0xffffffff.
Procedure: From IE go to the Help | About Internet Explorer dialog. The capability for 128 bit encryption is indicated by the phrase “Cipher Strength: 128 bit.” Criteria: If the phrase “Cipher Strength: 128 bit” is displayed, this is not a finding.
Install a 128 bit version of IE.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\ Software\Microsoft\Internet Explorer\Main and determine the value data for the IEWatsonEnabled value. Criteria: If the system being reviewed is running Windows XP or 2003, this is not a Finding. [This potential vulnerability is covered in the Windows Checklist.] If the value data for the IEWatsonEnabled value is not 0 (the number zero) or the key is not found, then this is a Finding.
Navigate to the registry key HKLM\Software\Microsoft\Internet Explorer\Main. Make sure that the key exists and the value data for the IEWatsonEnabled value is 0 (the number zero).
Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Internet Explorer\Main Criteria: If the value AutoSearch is 0 or 4, this is not a finding.
Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Internet Explorer\Main Ensure the value AutoSearch is 0 or 4
Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1C00 is REG_DWORD = 0 (Disabled = 0), this is not a finding.
Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 Criteria: If the value 1C00 is REG_DWORD = 0 (Disabled = 0).
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page -> Locked-Down Internet Zone -> "Download signed ActiveX controls" will be set to “Enabled” and "Disable" selected from down drop box. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 Criteria: If the value 1001 is REG_DWORD = 3, this is not a finding.
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page -> Locked-Down Internet Zone -> "Download signed ActiveX controls" will be set to “Enabled” and "Disable" selected from down drop box. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 Criteria: Set the value 1001 to REG_DWORD = 3.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing Criteria: If the value State is REG_DWORD = 65536 (decimal), this is not a finding.
Change the registry key HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\WinTrust\Trust Providers\Software Publishing to 65536.