Microsoft InfoPath 2013 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- DTOO127
- Vuln IDs
-
- V-242480
- V-17758
- Rule IDs
-
- SV-242480r960954_rule
- SV-53335
Checks: C-45755r713114_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Require that application add-ins are signed by Trusted Publisher" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value RequireAddinSig is REG_DWORD = 1, this is not a finding.
Fix: F-45712r713115_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Require that application add-ins are signed by Trusted Publisher" to "Enabled".
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- DTOO131
- Vuln IDs
-
- V-242481
- V-26697
- Rule IDs
-
- SV-242481r960954_rule
- SV-53452
Checks: C-45756r713117_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable Trust Bar Notification for unsigned application add-ins" must be "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Fix: F-45713r713118_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable Trust Bar Notification for unsigned application add-ins" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO133
- Vuln IDs
-
- V-242482
- V-17471
- Rule IDs
-
- SV-242482r961092_rule
- SV-53333
Checks: C-45757r713120_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable all trusted locations" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security\trusted locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-45714r713121_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> Trust Center "Disable all trusted locations" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO156
- Vuln IDs
-
- V-242483
- V-17611
- Rule IDs
-
- SV-242483r961863_rule
- SV-53384
Checks: C-45758r713123_chk
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath Options -> Advanced -> Offline "Offline Mode status" is set to "Enabled (Enabled, InfoPath not in Offline Mode)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\editor\offline Criteria: If the value CachedModeStatus is REG_DWORD = 2, this is not a finding.
Fix: F-45715r713124_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath Options -> Advanced -> Offline "Offline Mode status" to "Enabled (Enabled, InfoPath not in Offline Mode)".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTOO157
- Vuln IDs
-
- V-242484
- V-17654
- Rule IDs
-
- SV-242484r961194_rule
- SV-53378
Checks: C-45759r713126_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Control behavior for Microsoft SharePoint Foundation gradual upgrade" must be set to "Enabled (Block all redirections)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value GradualUpgradeRedirection is REG_DWORD = 2, this is not a finding.
Fix: F-45716r713127_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Control behavior for Microsoft SharePoint Foundation gradual upgrade" to "Enabled (Block all redirections)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO158
- Vuln IDs
-
- V-242485
- V-17655
- Rule IDs
-
- SV-242485r961092_rule
- SV-53383
Checks: C-45760r713129_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable opening of solutions from the Internet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value AllowInternetSolutions is REG_DWORD = 0, this is not a finding.
Fix: F-45717r713130_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable opening of solutions from the Internet security zone" to "Enabled".
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- DTOO159
- Vuln IDs
-
- V-242486
- V-17656
- Rule IDs
-
- SV-242486r960954_rule
- SV-53382
Checks: C-45761r713132_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable fully trusted solutions full access to computer" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value RunFullTrustSolutions is REG_DWORD = 0, this is not a finding.
Fix: F-45718r713133_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Disable fully trusted solutions full access to computer" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO160
- Vuln IDs
-
- V-242487
- V-17657
- Rule IDs
-
- SV-242487r961092_rule
- SV-53381
Checks: C-45762r713135_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Prevent users from allowing unsafe file types to be attached to forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value DisallowAttachmentCustomization is REG_DWORD = 1, this is not a finding.
Fix: F-45719r713136_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Prevent users from allowing unsafe file types to be attached to forms" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO164
- Vuln IDs
-
- V-242488
- V-17663
- Rule IDs
-
- SV-242488r961779_rule
- SV-53340
Checks: C-45763r713138_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath" must be set to "Enabled (Always show beaconing UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value InfoPathBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-45720r713139_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath" to "Enabled (Always show beaconing UI)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO165
- Vuln IDs
-
- V-242489
- V-17667
- Rule IDs
-
- SV-242489r961779_rule
- SV-53366
Checks: C-45764r713141_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath Filler ActiveX" must be set to "Enabled (Always show beaconing UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EditorActiveXBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-45721r713142_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security -> "Beaconing UI for forms opened in InfoPath Filler ActiveX" to "Enabled (Always show beaconing UI)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO167
- Vuln IDs
-
- V-242490
- V-17668
- Rule IDs
-
- SV-242490r961779_rule
- SV-53379
Checks: C-45765r713144_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Control behavior when opening InfoPath e-mail forms containing code or script" must be set to "Enabled (Prompt before running)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EMailFormsRunCodeAndScript is REG_DWORD = 1, this is not a finding.
Fix: F-45722r713145_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Control behavior when opening InfoPath e-mail forms containing code or script" to "Enabled (Prompt before running)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO168
- Vuln IDs
-
- V-242491
- V-17764
- Rule IDs
-
- SV-242491r961092_rule
- SV-53355
Checks: C-45766r713147_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending form template with e-mail forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\deployment Criteria: If the value MailXSNwithXML is REG_DWORD = 0, this is not a finding.
Fix: F-45723r713148_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending form template with e-mail forms" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO169
- Vuln IDs
-
- V-242492
- V-26618
- Rule IDs
-
- SV-242492r961092_rule
- SV-53385
Checks: C-45767r713150_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable dynamic caching of the form template in InfoPath e-mail forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\deployment Criteria: If the value CacheMailXSN is REG_DWORD = 0, this is not a finding.
Fix: F-45724r713151_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable dynamic caching of the form template in InfoPath e-mail forms" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO170
- Vuln IDs
-
- V-242493
- V-26619
- Rule IDs
-
- SV-242493r961092_rule
- SV-53389
Checks: C-45768r713153_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending InfoPath 2003 Forms as e-mail forms" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath Criteria: If the value DisableInfoPath2003EmailForms is REG_DWORD = 1, this is not a finding.
Fix: F-45725r713154_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable sending InfoPath 2003 Forms as e-mail forms" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO171
- Vuln IDs
-
- V-242494
- V-26620
- Rule IDs
-
- SV-242494r961092_rule
- SV-53392
Checks: C-45769r713156_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms running in restricted security level" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableRestrictedEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-45726r713157_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms running in restricted security level" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO172
- Vuln IDs
-
- V-242495
- V-17576
- Rule IDs
-
- SV-242495r961092_rule
- SV-53337
Checks: C-45770r713159_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Internet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableInternetEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-45727r713160_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Internet security zone" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO173
- Vuln IDs
-
- V-242496
- V-17187
- Rule IDs
-
- SV-242496r961092_rule
- SV-53331
Checks: C-45771r713162_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Full Trust security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableFullTrustEmailForms is REG_DWORD = 0, this is not a finding.
Fix: F-45728r713163_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Full Trust security zone" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO176
- Vuln IDs
-
- V-242497
- V-17658
- Rule IDs
-
- SV-242497r961092_rule
- SV-53353
Checks: C-45772r713165_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Miscellaneous "Email Forms Beaconing UI" must be set to "Enabled (Always show UI)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EmailFormsBeaconingUI is REG_DWORD = 1, this is not a finding.
Fix: F-45729r713166_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Miscellaneous "Email Forms Beaconing UI" to "Enabled (Always show UI)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO294
- Vuln IDs
-
- V-242498
- V-26589
- Rule IDs
-
- SV-242498r961092_rule
- SV-53328
Checks: C-45773r713168_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Intranet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value EnableIntranetEMailForms is REG_DWORD = 0, this is not a finding.
Fix: F-45730r713169_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable e-mail forms from the Intranet security zone" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO295
- Vuln IDs
-
- V-242499
- V-26621
- Rule IDs
-
- SV-242499r961092_rule
- SV-53432
Checks: C-45774r713171_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable InfoPath e-mail forms in Outlook" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\outlook\options\mail Criteria: If the value DisableInfopathForms is REG_DWORD = 1, this is not a finding.
Fix: F-45731r713172_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable InfoPath e-mail forms in Outlook" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO296
- Vuln IDs
-
- V-242500
- V-17580
- Rule IDs
-
- SV-242500r961092_rule
- SV-53362
Checks: C-45775r713174_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Disable opening forms with managed code from the Internet security zone" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value RunManagedCodeFromInternet is REG_DWORD = 1, this is not a finding.
Fix: F-45732r713175_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Disable opening forms with managed code from the Internet security zone" to "Enabled".
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- DTOO297
- Vuln IDs
-
- V-242501
- V-17745
- Rule IDs
-
- SV-242501r960954_rule
- SV-53357
Checks: C-45776r713177_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Display a warning that a form is digitally signed" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\InfoPath\security Criteria: If the value SignatureWarning is REG_DWORD = 1, this is not a finding.
Fix: F-45733r713178_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> Security "Display a warning that a form is digitally signed" to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO309
- Vuln IDs
-
- V-242502
- V-17746
- Rule IDs
-
- SV-242502r961863_rule
- SV-53359
Checks: C-45777r713180_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2013 (Machine) -> Security "InfoPath APTCA Assembly Allowable List Enforcement" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\office\15.0\InfoPath\security Criteria: If the value APTCA_AllowList is REG_DWORD = 1, this is not a finding.
Fix: F-45734r713181_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft InfoPath 2013 (Machine) -> Security "InfoPath APTCA Assembly Allowable List Enforcement" to "Enabled".
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- DTOO999-InfoPath13
- Vuln IDs
-
- V-265892
- Rule IDs
-
- SV-265892r999880_rule
Checks: C-69811r999878_chk
InfoPath 2013 is no longer supported by the vendor. If the system is running InfoPath 2013, this is a finding.
Fix: F-69715r999879_fix
Upgrade to a supported version.