Back

Configure the "Enable Native XMLHttp Support" setting.


CONTROL ID
02267
CONTROL TYPE
Configuration
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Configure Internet Browser security options according to organizational standards., CC ID: 02166

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • The "Enable Native XMLHttp Support" setting should be configured correctly. Technical Mechanisms: Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features Registry Keys:[HKLM | HKCU]\Software\Policies\Mic… (CCE-4259-8, Common Configuration Enumeration List, Combined XML: Internet Explorer 7, 5.20130214)
  • The "Enable Native XMLHttpRequest Support" current user setting should be configured correctly. Technical Mechanisms: User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Enable Native XMLHttpRequest Support HKEY_CURRENT_USER\Software\Policies\Micr… (CCE-17113-2, Common Configuration Enumeration List, Combined XML: Microsoft Internet Explorer 8, 5.20130214)
  • The "Enable Native XMLHttpRequest Support" machine setting should be configured correctly. Technical Mechanisms: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Enable Native XMLHttpRequest Support HKEY_LOCAL_MACHINE\Software\Policies\Micr… (CCE-15496-3, Common Configuration Enumeration List, Combined XML: Microsoft Internet Explorer 8, 5.20130214)
  • The "Enable Native XMLHttp Support" setting should be configured correctly. (oval:gov.nist.fdcc.ie7:def:338, FDCC Windows IE7 SCAP content using OVAL (fdcc-ie7-oval.xml, fdcc-ie7-patches.xml), Version 5.4)
  • Enable Native XMLHttp Support - Local Computer (EnableNativeXMLHttpSupport_LocalComputer, NIST SCAP Microsoft Internet Explorer Version 7 (fdcc-ie7-xccdf.xml), FDCC IE7 (1.2) SCAP Content - OVAL 5.4)