Read signed email as plain text must be enforced.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-251865DTOO215SV-251865r811186_ruleCCI-000366medium
Description
Outlook can display email messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. By default, Outlook displays digitally signed email messages in the format which they were received.
STIGDate
Microsoft Outlook 2016 Security Technical Implementation Guide2022-03-11

Details

Check Text (C-251865r811186_chk)

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Outlook 2016 >> Outlook Options >> Preferences >> E-mail Options "Read signed e-mail as plain text" is set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\16.0\outlook\options\mail Criteria: If the value ReadSignedAsPlain is REG_DWORD = 1, this is not a finding.

Fix Text (F-55279r811185_fix)

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Outlook 2016 >> Outlook Options >> Preferences >> E-mail Options "Read signed e-mail as plain text" to "Enabled".