EX13-CA-000085 – Exchange must have Audit data on separate partitions. Details Log files help establish a history of activities, and can be useful in detecting attack attempts or determining tuning...
EX13-CA-000090 – Exchange Local machine policy must require signed scripts. Details Scripts often provide a way for attackers to infiltrate a system, especially those downloaded from untrusted locations. By setting...
EX13-CA-000095 – Exchange IMAP4 service must be disabled. Details The IMAP4 protocol is not approved for use within the DoD. It uses a clear text-based user name and...
EX13-CA-000100 – Exchange POP3 service must be disabled. Details The POP3 protocol is not approved for use within the DoD. It uses a clear text based user name...
EX13-CA-000105 – Exchange must have the Public Folder virtual directory removed if not in use by the site. Details To reduce the vectors through which a server can be attacked, unneeded application components should be disabled or removed....
EX13-CA-000110 – Exchange must have the Microsoft Active Sync directory removed. Details To reduce the vectors through which a server can be attacked, unneeded application components should be disabled or removed....
EX13-CA-000115 – Exchange application directory must be protected from unauthorized access. Details Default product installations may provide more generous access permissions than are necessary to run the application. By examining and...
EX13-CA-000120 – Exchange software baseline copy must exist. Details Exchange software, as with other application software installed on a host system, must be included in a system baseline...
EX13-CA-000155 – Exchange OWA must have S/MIME Certificates enabled. Details Without protection of the transmitted information, confidentiality and integrity may be compromised since unprotected communications can be intercepted and...
EX13-CA-000160 – Exchange must have the most current, approved service pack installed. Details Failure to install the most current Exchange service pack leaves a system vulnerable to exploitation. Current service packs correct...