1. Home
  2. Security Hardening
  3. DISA STIG Office 2010 InfoPath V1R11
  4. DTOO295 – InfoPath – InfoPath e-mail forms in Outlook must be disallowed.

DTOO295 – InfoPath – InfoPath e-mail forms in Outlook must be disallowed.

Details

Attackers can send users InfoPath e-mail forms in an attempt to gain access to confidential information. Depending on the level of trust of the forms, it might also be possible to gain access to other data automatically. By default, Outlook 2010 uses the InfoPath e-mail forms feature to render forms in Outlook and allows users to fill them out in place.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms ‘Disable InfoPath e-mail forms in Outlook’ to ‘Enabled’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles