Back

Configure the "Site to Zone Assignment List" to organizational standards.


CONTROL ID
08650
CONTROL TYPE
Configuration
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Configure Internet Browser security options according to organizational standards., CC ID: 02166

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • The "Site to Zone Assignment List" current user setting should be configured correctly. Technical Mechanisms: User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Site to Zone Assignment List HKEY_CURRENT_USER\Software\Policies\Micros… (CCE-16259-4, Common Configuration Enumeration List, Combined XML: Microsoft Internet Explorer 8, 5.20130214)
  • Computer-wide, rather than per-user, assignment of sites to zones for Internet Explorer should be enabled or disabled as appropriate. (xccdf_gov.nist_rule_site_to_zone_assignment_list_local_computer, oval:gov.nist.USGCB.ie7:def:9998, oval:gov.nist.USGCB.ie7:tst:9998, oval:gov.nist.USGCB.ie7:obj:9998, USGCB: Guidance for Securing Microsoft Internet Explorer 7, v1.2.3.1)