Microsoft InfoPath 2010
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates No substantive changes
Comparison against the immediately-prior release (V1R9). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
No substantive changes detected against the previous release. 25 rules matched cleanly.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO131 - InfoPath
- Vuln IDs
-
- V-17187
- Rule IDs
-
- SV-33670r1_rule
Checks: C-34129r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” must be “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infoPath\security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Fix: F-29811r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO133 - InfoPath
- Vuln IDs
-
- V-17471
- Rule IDs
-
- SV-33860r2_rule
Checks: C-34218r3_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable all trusted locations” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security\trusted locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-29909r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Disable all trusted locations” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO157 - InfoPath
- Vuln IDs
-
- V-17576
- Rule IDs
-
- SV-33657r1_rule
Checks: C-34118r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Control behavior for Microsoft SharePoint Foundation gradual upgrade” must be set to “Enabled (Block all redirections)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infoPath\security Criteria: If the value GradualUpgradeRedirection is REG_DWORD = 2, this is not a finding.
Fix: F-29798r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Control behavior for Microsoft SharePoint Foundation gradual upgrade” to “Enabled (Block all redirections)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO167 - InfoPath
- Vuln IDs
-
- V-17580
- Rule IDs
-
- SV-33627r1_rule
Checks: C-34091r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Control behavior when opening InfoPath e-mail forms containing code or script” must be set to “Enabled (Prompt before running)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infoPath\security Criteria: If the value EMailFormsRunCodeAndScript is REG_DWORD = 1, this is not a finding.
Fix: F-29770r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Control behavior when opening InfoPath e-mail forms containing code or script” to “Enabled (Prompt before running)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO176 - InfoPath
- Vuln IDs
-
- V-17611
- Rule IDs
-
- SV-33651r1_rule
Checks: C-34111r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Miscellaneous “Email Forms Beaconing UI” must be set to “Enabled (Always show UI)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EmailFormsBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-29791r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Miscellaneous “Email Forms Beaconing UI” to “Enabled (Always show UI)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO169 - InfoPath
- Vuln IDs
-
- V-17654
- Rule IDs
-
- SV-33629r1_rule
Checks: C-34093r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable dynamic caching of the form template in InfoPath e-mail forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\deployment Criteria: If the value CacheMailXSN is REG_DWORD = 0, this is not a finding.
Fix: F-29772r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable dynamic caching of the form template in InfoPath e-mail forms” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO173 - InfoPath
- Vuln IDs
-
- V-17655
- Rule IDs
-
- SV-33631r1_rule
Checks: C-34095r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Full Trust security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableFullTrustEmailForms is REG_DWORD = 0, this is not a finding.
Fix: F-29774r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Full Trust security zone” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO172 - InfoPath
- Vuln IDs
-
- V-17656
- Rule IDs
-
- SV-33634r1_rule
Checks: C-34097r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Internet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableInternetEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-29776r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Internet security zone” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO171 - InfoPath
- Vuln IDs
-
- V-17657
- Rule IDs
-
- SV-33636r1_rule
Checks: C-34100r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms running in restricted security level” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableRestrictedEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-29779r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms running in restricted security level” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO159 - InfoPath
- Vuln IDs
-
- V-17658
- Rule IDs
-
- SV-33661r1_rule
Checks: C-34122r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable fully trusted solutions full access to computer” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value RunFullTrustSolutions is REG_DWORD = 0, this is not a finding.
Fix: F-29802r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable fully trusted solutions full access to computer” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO158 - InfoPath
- Vuln IDs
-
- V-17663
- Rule IDs
-
- SV-33665r1_rule
Checks: C-34126r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable opening of solutions from the Internet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value AllowInternetSolutions is REG_DWORD = 0, this is not a finding.
Fix: F-29807r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Disable opening of solutions from the Internet security zone” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO168 - InfoPath
- Vuln IDs
-
- V-17667
- Rule IDs
-
- SV-33639r1_rule
Checks: C-34102r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending form template with e-mail forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\deployment Criteria: If the value MailXSNwithXML is REG_DWORD = 0, this is not a finding.
Fix: F-29781r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending form template with e-mail forms” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO170 - InfoPath
- Vuln IDs
-
- V-17668
- Rule IDs
-
- SV-33646r1_rule
Checks: C-34107r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath Criteria: If the value DisableInfoPath2003EmailForms is REG_DWORD = 1, this is not a finding.
Fix: F-29787r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO164 - InfoPath
- Vuln IDs
-
- V-17745
- Rule IDs
-
- SV-33652r1_rule
Checks: C-34113r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath” must be set to “Enabled (Always show beaconing UI)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value InfoPathBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-29793r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath” to “Enabled (Always show beaconing UI)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO165 - InfoPath
- Vuln IDs
-
- V-17746
- Rule IDs
-
- SV-33655r1_rule
Checks: C-34116r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath Filler ActiveX" must be set to “Enabled (Always show beaconing UI)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EditorActiveXBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-29796r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Beaconing UI for forms opened in InfoPath Filler ActiveX" to “Enabled (Always show beaconing UI)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO156 - InfoPath
- Vuln IDs
-
- V-17758
- Rule IDs
-
- SV-33649r1_rule
Checks: C-34110r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath Options -> Advanced -> Offline “Offline Mode status” must be set to “Enabled (Enabled, InfoPath not in Offline Mode)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\editor\offline Criteria: If the value CachedModeStatus is REG_DWORD = 2, this is not a finding.
Fix: F-29790r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath Options -> Advanced -> Offline “Offline Mode status” to “Enabled (Enabled, InfoPath not in Offline Mode)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO160 - InfoPath
- Vuln IDs
-
- V-17764
- Rule IDs
-
- SV-33668r1_rule
Checks: C-34128r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Prevent users from allowing unsafe file types to be attached to forms” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value DisallowAttachmentCustomization is REG_DWORD = 1, this is not a finding.
Fix: F-29810r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> “Prevent users from allowing unsafe file types to be attached to forms” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO127 - InfoPath
- Vuln IDs
-
- V-26589
- Rule IDs
-
- SV-33851r1_rule
Checks: C-34219r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Require that application add-ins are signed by Trusted Publisher” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value RequireAddinSig is REG_DWORD = 1, this is not a finding.
Fix: F-29910r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Require that application add-ins are signed by Trusted Publisher” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO128 - InfoPath
- Vuln IDs
-
- V-26590
- Rule IDs
-
- SV-33856r1_rule
Checks: C-34220r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Turn off Data Execution Prevention” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableDEP is REG_DWORD = 1, this is not a finding.
Fix: F-29911r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security -> Trust Center “Turn off Data Execution Prevention” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO294 - InfoPath
- Vuln IDs
-
- V-26618
- Rule IDs
-
- SV-34111r1_rule
Checks: C-34214r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Intranet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value EnableIntranetEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-29905r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable e-mail forms from the Intranet security zone” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO295 - InfoPath
- Vuln IDs
-
- V-26619
- Rule IDs
-
- SV-34119r1_rule
Checks: C-34215r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\outlook\options\mail Criteria: If the value DisableInfopathForms is REG_DWORD = 1, this is not a finding.
Fix: F-29906r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO296 - InfoPath
- Vuln IDs
-
- V-26620
- Rule IDs
-
- SV-34123r1_rule
Checks: C-34216r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Disable opening forms with managed code from the Internet security zone” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value RunManagedCodeFromInternet is REG_DWORD = 1, this is not a finding.
Fix: F-29907r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Disable opening forms with managed code from the Internet security zone” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO297 - InfoPath
- Vuln IDs
-
- V-26621
- Rule IDs
-
- SV-34221r1_rule
Checks: C-34217r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Display a warning that a form is digitally signed” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infopath\security Criteria: If the value SignatureWarning is REG_DWORD = 1, this is not a finding.
Fix: F-29908r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> Security “Display a warning that a form is digitally signed” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO305 - InfoPath
- Vuln IDs
-
- V-26625
- Rule IDs
-
- SV-33810r1_rule
Checks: C-34184r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Global Options -> Customize “Disable UI extending from documents and templates” must be “Enabled" and " Disallow in InfoPath" selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\toolbars\infopath Criteria: If the value NoExtensibilityCustomizationFromDocument is REG_DWORD = 1, this is not a finding.
Fix: F-29873r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Global Options -> Customize “Disable UI extending from documents and templates” to “Enabled" and select "Disallow in InfoPath".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO309 - InfoPath
- Vuln IDs
-
- V-26697
- Rule IDs
-
- SV-34226r1_rule
Checks: C-34403r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2010 (Machine) -> Security “InfoPath APTCA Assembly Allowable List Enforcement” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\office\14.0\infopath\security Criteria: If the value APTCA_AllowList is REG_DWORD = 1, this is not a finding.
Fix: F-30013r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2010 (Machine) -> Security “InfoPath APTCA Assembly Allowable List Enforcement” to “Enabled”.