STIGhub
STIGs
RMF Controls
Compare
← SC-18 (3) — Mobile Code
CCI-001169
Definition
Prevent the download of organization-defined unacceptable mobile code.
Parent Control
SC-18 (3)
Mobile Code
System and Communications Protection
Linked STIG Checks (34)
V-213168
CAT II
Adobe Reader DC must enable Enhanced Security in a Standalone Application.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-213169
CAT II
Adobe Reader DC must enable Enhanced Security in a Browser.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-213170
CAT II
Adobe Reader DC must enable Protected Mode.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-213171
CAT II
Adobe Reader DC must enable Protected View.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-213172
CAT II
Adobe Reader DC must Block Websites.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-213173
CAT II
Adobe Reader DC must block access to Unknown Websites.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-213174
CAT II
Adobe Reader DC must prevent opening files other than PDF or FDF.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-213175
CAT II
Adobe Reader DC must block Flash Content.
Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
V-204977
CAT II
The ALG providing content filtering must prevent the download of prohibited mobile code.
Application Layer Gateway Security Requirements Guide
V-237383
CAT II
The CA API Gateway providing content filtering must prevent the download of prohibited mobile code.
CA API Gateway ALG Security Technical Implementation Guide
V-278393
CAT II
NGINX must identify prohibited mobile code.
F5 NGINX Security Technical Implementation Guide
V-205515
CAT II
The Mainframe Product must prevent the download of prohibited mobile code.
Mainframe Product Security Requirements Guide
V-238018
CAT II
File Downloads must be configured for proper restrictions.
Microsoft Access 2016 Security Technical Implementation Guide
V-213439
CAT II
Microsoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.
Microsoft Defender Antivirus Security Technical Implementation Guide
V-213444
CAT II
Microsoft Defender AV must be configured to scan all downloaded files and attachments.
Microsoft Defender Antivirus Security Technical Implementation Guide
V-238179
CAT II
File Downloads must be configured for proper restrictions.
Microsoft Excel 2016 Security Technical Implementation Guide
V-223017
CAT II
The Download signed ActiveX controls property must be disallowed (Internet zone).
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-223018
CAT II
The Download unsigned ActiveX controls property must be disallowed (Internet zone).
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-223040
CAT II
Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the internet must be enabled.
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-223051
CAT II
The Download signed ActiveX controls property must be disallowed (Restricted Sites zone).
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-223053
CAT II
VBScript must not be allowed to run in Internet Explorer (Internet zone).
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-223054
CAT II
The Download unsigned ActiveX controls property must be disallowed (Restricted Sites zone).
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-223055
CAT II
VBScript must not be allowed to run in Internet Explorer (Restricted Sites zone).
Microsoft Internet Explorer 11 Security Technical Implementation Guide
V-215536
CAT II
File Downloads must be configured for proper restrictions.
Microsoft OneDrive Security Technical Implementation Guide
V-238051
CAT II
File Downloads must be configured for proper restrictions.
Microsoft OneNote 2016 Security Technical Implementation Guide
V-228426
CAT II
File Downloads must be configured for proper restrictions.
Microsoft Outlook 2016 Security Technical Implementation Guide
V-228469
CAT II
Automatic download of Internet Calendar appointment attachments must be disallowed.
Microsoft Outlook 2016 Security Technical Implementation Guide
V-238066
CAT II
File Downloads must be configured for proper restrictions in PowerPoint.
Microsoft PowerPoint 2016 Security Technical Implementation Guide
V-238086
CAT II
File Downloads must be configured for proper restrictions in PowerPoint Viewer.
Microsoft PowerPoint 2016 Security Technical Implementation Guide
V-70721
CAT II
File Downloads must be configured for proper restrictions.
Microsoft Project 2016 Security Technical Implementation Guide
V-238491
CAT II
File Downloads must be configured for proper restrictions.
Microsoft Publisher 2016 Security Technical Implementation Guide
V-238117
CAT II
File Downloads must be configured for proper restrictions.
Microsoft Visio 2016 Security Technical Implementation Guide
V-238133
CAT II
File Downloads must be configured for proper restrictions.
Microsoft Word 2016 Security Technical Implementation Guide
V-228853
CAT II
The Palo Alto Networks security platform must prevent the download of prohibited mobile code.
Palo Alto Networks ALG Security Technical Implementation Guide