DISA STIGS Viewer

Automatically downloading enclosures on RSS must be disallowed.

Overview

Finding ID Version Rule ID IA Controls Severity
V-228472 DTOO313 SV-228472r508021_rule   Medium
Description
This policy setting allows you to control whether Outlook automatically downloads enclosures on RSS items. If you enable this policy setting, Outlook will automatically download enclosures on RSS items. If you disable or do not configure this policy setting, enclosures on RSS items are not downloaded by default.
STIG Date
Microsoft Outlook 2016 Security Technical Implementation Guide 2022-03-11

Details

Check Text (C-30705r497738_chk)
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2016 -> Account Settings -> RSS Feeds "Automatically download enclosures" is set to "Disabled".

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\16.0\outlook\options\rss

Criteria: If the value EnableAttachments is REG_DWORD = 0, this is not a finding.
Fix Text (F-30690r497739_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Outlook 2016 -> Account Settings -> RSS Feeds "Automatically download enclosures" to "Disabled".