<?xml version='1.0' encoding='UTF-8'?>
<ncp xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://scap.nist.gov/schema/feed/ncp/checklist/0.1" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.3" xmlns:config="http://scap.nist.gov/schema/configuration/0.1" xmlns:ncp="http://scap.nist.gov/schema/ncp/checklist/0.1" nvd_xml_version="0.1" pub_date="2009-10-12T17:22:42" xsi:schemaLocation="http://scap.nist.gov/schema/configuration/0.1 http://nvd.nist.gov/schema/configuration_0.1.xsd http://scap.nist.gov/schema/scap-core/0.3 http://nvd.nist.gov/schema/scap-core_0.3.xsd http://scap.nist.gov/schema/feed/ncp/checklist/0.1 http://nvd.nist.gov/schema/ncp-checklist-feed_0.1.xsd">
    <entry id="170" checklist-version="1.2" published-datetime="2008-06-19T04:00:00.000Z" entry-datetime="2007-11-29T05:00:00.000Z" checklist-name="FDCC IE7" last-modified-datetime="2009-10-07T15:20:59.183Z">
        <ncp:tier>4</ncp:tier>
        <ncp:review-status>FINAL</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.whitehouse.gov/omb/" name="OMB" />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Microsoft Internet Explorer 7</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:ie:7.0</ncp:cpe-name>
            <ncp:product-category>Web Browser</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>The Federal Desktop Core Configuration (FDCC) is an OMB-mandated security configuration. The FDCC currently exists for Microsoft Windows Vista and XP operating system software. While not addressed specifically as the "Federal Desktop Core Configuration," the FDCC was originally called for in a 22 March 2007 memorandum from OMB to all Federal agencies and department heads and a corresponding memorandum from OMB to all Federal agency and department Chief Information Officers (CIO).

This checklist represents the FDCC guidance for Microsoft Internet Explorer 7.</ncp:summary>
        <ncp:checklist-role>Web Browser</ncp:checklist-role>
        <ncp:target-operational-environment>FDCC</ncp:target-operational-environment>
        <ncp:change-history>08/06/2009 - OVAL 5.3 Patch Content Updated

04/08/2009 - Major Version 1.2 released

10/31/2008 - Major Version 1.1.1.0 released

06/20/2008 - Major Version 1.0 released</ncp:change-history>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://fdcc.nist.gov" />
            <ncp:description>The link to the FDCC home page.</ncp:description>
        </ncp:ncp-reference>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/fdcc_faq.cfm" />
            <ncp:description>FDCC FAQ</ncp:description>
        </ncp:ncp-reference>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/download_fdcc.cfm" />
            <ncp:description>FDCC primary download page</ncp:description>
        </ncp:ncp-reference>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/download_file_fdcc.cfm" />
            <ncp:description>FDCC individual file listings and download page</ncp:description>
        </ncp:ncp-reference>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>true</ncp:scap-expressed>
            <ncp:xccdf-expressed>true</ncp:xccdf-expressed>
            <ncp:oval-expressed>true</ncp:oval-expressed>
            <ncp:cce-expressed>true</ncp:cce-expressed>
            <ncp:cve-expressed>true</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>true</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:scap-content>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/fdcc-files-1.2.1.0/fdcc-ie7.zip" />
            <ncp:author system-id="http://www.nist.gov/" name="NIST, Computer Security Division" />
            <ncp:title>OVAL 5.3</ncp:title>
            <ncp:sha-1>9E3C08C585D0B64836FD821AA4D6410C8C9AC011</ncp:sha-1>
            <ncp:sha-256>951C03ABF54ADA35FA25162743AAF02EF519417D4B47CE9D61EC3C277DB3C058</ncp:sha-256>
            <ncp:description>The FDCC IE7 SCAP Content using OVAL version 5.3.</ncp:description>
            <ncp:type>SCAP_CONTENT</ncp:type>
        </ncp:scap-content>
        <ncp:scap-content>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/fdcc-files-1.2.0.0/fdcc-ie7.zip" />
            <ncp:author system-id="http://www.nist.gov/" name="NIST, Computer Security Division" />
            <ncp:title>OVAL 5.4</ncp:title>
            <ncp:sha-1>AE21DA41BAE747F6F21DEB62B341B6035CF46AE5</ncp:sha-1>
            <ncp:sha-256>2FDFEA8C9DFC84CBE7F3B9BE26B4A5C71EC1AE734010FB537B9F2FBE6CA1F848</ncp:sha-256>
            <ncp:description>FDCC Windows IE7 SCAP content using OVAL version 5.3.</ncp:description>
            <ncp:type>SCAP_CONTENT</ncp:type>
        </ncp:scap-content>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/fdcc-files-1.2.1.0/fdcc-ie7.zip" />
            <ncp:author system-id="http://www.nist.gov/" name="NIST, Computer Security Division" />
            <ncp:title>OVAL 5.3</ncp:title>
            <ncp:sha-1>9E3C08C585D0B64836FD821AA4D6410C8C9AC011</ncp:sha-1>
            <ncp:sha-256>951C03ABF54ADA35FA25162743AAF02EF519417D4B47CE9D61EC3C277DB3C058</ncp:sha-256>
            <ncp:description>The FDCC IE7 SCAP Content using OVAL version 5.3.</ncp:description>
            <ncp:type>SCAP Content</ncp:type>
        </ncp:supporting-resource>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/fdcc-files-1.2.0.0/fdcc-ie7.zip" />
            <ncp:author system-id="http://www.nist.gov/" name="NIST, Computer Security Division" />
            <ncp:title>OVAL 5.4</ncp:title>
            <ncp:sha-1>AE21DA41BAE747F6F21DEB62B341B6035CF46AE5</ncp:sha-1>
            <ncp:sha-256>2FDFEA8C9DFC84CBE7F3B9BE26B4A5C71EC1AE734010FB537B9F2FBE6CA1F848</ncp:sha-256>
            <ncp:description>FDCC Windows IE7 SCAP content using OVAL version 5.3.</ncp:description>
            <ncp:type>SCAP Content</ncp:type>
        </ncp:supporting-resource>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/FDCC_v1.0_Q1_2009_GPOs.zip" />
            <ncp:author system-id="http://www.nist.gov/" name="NIST, Computer Security Division" />
            <ncp:sha-1>7DD0E04CEE71F16BBAA6366C358B740C1041834C</ncp:sha-1>
            <ncp:sha-256>53664841150B753339A32B7C3A3A4EA4F7CB760D77023A6ECC0B147AE4B02F73</ncp:sha-256>
            <ncp:description>FDCC Windows Vista Firewall GPOs</ncp:description>
            <ncp:type>GPOs</ncp:type>
        </ncp:supporting-resource>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/fdcc/FDCC-Settings-major-version-1.2.x.0.xls" />
            <ncp:author system-id="http://www.nist.gov/" name="NIST, Computer Security Division" />
            <ncp:sha-1>1C4962660C0CEB4CA530DFFE7A56C81463C78F50</ncp:sha-1>
            <ncp:sha-256>37FC8ECB0A95AB31B56463A5D83E6206DC4964D6A1FA0E4AF710BBD246BEB0F6</ncp:sha-256>
            <ncp:description>This is the human readable version of the FDCC settings.</ncp:description>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
        <ncp:cce-mapping-list>
            <ncp:cce id="CCE-3201-1">
                <config:cce-id>CCE-3201-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.640Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.640Z</config:last-modified-datetime>
                <config:summary>The "Make Proxy Settings Per-Machine (Rather Then Per-User)" setting should be configured correctly.</config:summary>
            </ncp:cce>
            <ncp:cce id="CCE-3204-5">
                <config:cce-id>CCE-3204-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.797Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.797Z</config:last-modified-datetime>
                <config:summary>The "Turn Off changing the URL to be displayed for checking updates to Internet Explorer and Internet Tools" setting should be configured correctly.</config:summary>
            </ncp:cce>
            <ncp:cce id="CCE-3207-8">
                <config:cce-id>CCE-3207-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.890Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.890Z</config:last-modified-datetime>
                <config:summary>The "Prevent performance of First Run Customize settings" setting should be configured correctly.</config:summary>
            </ncp:cce>
            <ncp:cce id="CCE-3216-9">
                <config:cce-id>CCE-3216-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.360Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.360Z</config:last-modified-datetime>
                <config:summary>The "Scripting of Java applets" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
            </ncp:cce>
            <ncp:cce id="CCE-3249-0">
                <config:cce-id>CCE-3249-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.000Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.000Z</config:last-modified-datetime>
                <config:summary>The "Allow status bar updates via script" setting should be configured correctly for the Internet Zone.</config:summary>
            </ncp:cce>
            <ncp:cce id="CCE-3264-9">
                <config:cce-id>CCE-3264-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.407Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.407Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:47.670Z">
                        <scap-core:mapping published="2009-07-30T20:04:47.670Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:47.640Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3275-5">
                <config:cce-id>CCE-3275-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.500Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.500Z</config:last-modified-datetime>
                <config:summary>The "Configure Outlook Express" setting should be configured correctly</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:49.280Z">
                        <scap-core:mapping published="2009-07-30T20:04:49.280Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3337-3">
                <config:cce-id>CCE-3337-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.170Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.170Z</config:last-modified-datetime>
                <config:summary>The "Drag and drop or copy and paste files" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:23.390Z">
                        <scap-core:mapping published="2009-07-30T20:04:23.390Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3338-1">
                <config:cce-id>CCE-3338-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.610Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.610Z</config:last-modified-datetime>
                <config:summary>The "Internet Explorer Processes (MK Protocol)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:20.890Z">
                        <scap-core:mapping published="2009-07-30T20:04:20.890Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3378-7">
                <config:cce-id>CCE-3378-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.717Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.717Z</config:last-modified-datetime>
                <config:summary>The "Turn Off First- Run Opt-In" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:49.530Z">
                        <scap-core:mapping published="2009-07-30T20:04:49.530Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3400-9">
                <config:cce-id>CCE-3400-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.327Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.327Z</config:last-modified-datetime>
                <config:summary>The "Run components not signed with Authenticode" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:21.907Z">
                        <scap-core:mapping published="2009-07-30T20:04:21.907Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:21.907Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3477-7">
                <config:cce-id>CCE-3477-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:55.767Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:55.767Z</config:last-modified-datetime>
                <config:summary>The "Turn off downloading of enclosures" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:57.377Z">
                        <scap-core:mapping published="2009-07-30T20:04:57.377Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3518-8">
                <config:cce-id>CCE-3518-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.640Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.640Z</config:last-modified-datetime>
                <config:summary>The "Disable Automatic Install of Internet Explorer Components" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:36.313Z">
                        <scap-core:mapping published="2009-07-30T20:04:36.313Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:36.280Z">SI-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:36.267Z">SI-7</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:36.297Z">SI-8</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3553-5">
                <config:cce-id>CCE-3553-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.077Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.077Z</config:last-modified-datetime>
                <config:summary>The "Software channel permissions" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:34.407Z">
                        <scap-core:mapping published="2009-07-30T20:04:34.407Z">CM-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3564-2">
                <config:cce-id>CCE-3564-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.250Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.250Z</config:last-modified-datetime>
                <config:summary>The "Download unsigned ActiveX controls" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:23.093Z">
                        <scap-core:mapping published="2009-07-30T20:04:23.077Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:23.093Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3570-9">
                <config:cce-id>CCE-3570-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.110Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.110Z</config:last-modified-datetime>
                <config:summary>The "Web sites in less privileged Web content zones can navigate into this zone" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:35.920Z">
                        <scap-core:mapping published="2009-07-30T20:04:35.920Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:35.907Z">CM-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3576-6">
                <config:cce-id>CCE-3576-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.577Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.577Z</config:last-modified-datetime>
                <config:summary>The "Disable Periodic Check For Internet Explorer Software Updates" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:49.670Z">
                        <scap-core:mapping published="2009-07-30T20:04:49.670Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:49.627Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:49.640Z">SI-2</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3584-0">
                <config:cce-id>CCE-3584-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.937Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.937Z</config:last-modified-datetime>
                <config:summary>The "Automatically Check for Internet Explorer Updates" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:36.000Z">
                        <scap-core:mapping published="2009-07-30T20:04:35.983Z">CM-2</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:36.000Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3590-7">
                <config:cce-id>CCE-3590-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.297Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.297Z</config:last-modified-datetime>
                <config:summary>The "Loose XAML" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:33.140Z">
                        <scap-core:mapping published="2009-07-30T20:04:33.140Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3601-2">
                <config:cce-id>CCE-3601-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.983Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.983Z</config:last-modified-datetime>
                <config:summary>The "Allow Scriptlets" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:43.983Z">
                        <scap-core:mapping published="2009-07-30T20:04:43.983Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:43.953Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3615-2">
                <config:cce-id>CCE-3615-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.907Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.907Z</config:last-modified-datetime>
                <config:summary>The "Turn off "Delete Browsing History" functionality" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:27.170Z">
                        <scap-core:mapping published="2009-07-30T20:04:27.170Z">AU-9</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:27.157Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3619-4">
                <config:cce-id>CCE-3619-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.093Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.093Z</config:last-modified-datetime>
                <config:summary>The "Use Pop-up Blocker" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:24.093Z">
                        <scap-core:mapping published="2009-07-30T20:04:24.093Z">SI-8</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3623-6">
                <config:cce-id>CCE-3623-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.047Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.047Z</config:last-modified-datetime>
                <config:summary>The "Logon" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:35.767Z">
                        <scap-core:mapping published="2009-07-30T20:04:35.750Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:35.767Z">IA-2</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3647-5">
                <config:cce-id>CCE-3647-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.437Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.437Z</config:last-modified-datetime>
                <config:summary>The "Turn on the auto-complete feature for user names and passwords on form" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:25.890Z">
                        <scap-core:mapping published="2009-07-30T20:04:25.890Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:25.890Z">IA-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3677-2">
                <config:cce-id>CCE-3677-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.453Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.453Z</config:last-modified-datetime>
                <config:summary>The "Allow Install On Demand (Internet Explorer)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:24.267Z">
                        <scap-core:mapping published="2009-07-30T20:04:24.267Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:24.250Z">SI-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3696-2">
                <config:cce-id>CCE-3696-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.280Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.280Z</config:last-modified-datetime>
                <config:summary>The "Logon" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:40.627Z">
                        <scap-core:mapping published="2009-07-30T20:04:40.610Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:40.627Z">IA-2</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3706-9">
                <config:cce-id>CCE-3706-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.860Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.860Z</config:last-modified-datetime>
                <config:summary>The "Disable Showing the Splash Screen" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:04:50.627Z">
                        <scap-core:mapping published="2009-07-30T20:04:50.627Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:04:50.610Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3744-0">
                <config:cce-id>CCE-3744-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.657Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.657Z</config:last-modified-datetime>
                <config:summary>The "Do Not Allow Users to enable or Disable Add-Ons" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:37.890Z">
                        <scap-core:mapping published="2009-07-30T20:05:37.890Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:37.877Z">CM-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3751-5">
                <config:cce-id>CCE-3751-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.063Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.063Z</config:last-modified-datetime>
                <config:summary>The "Loose XAML" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:34.953Z">
                        <scap-core:mapping published="2009-07-30T20:05:34.953Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3754-9">
                <config:cce-id>CCE-3754-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.627Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.627Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Locked Down Intranet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:39.327Z">
                        <scap-core:mapping published="2009-07-30T20:05:39.327Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3825-7">
                <config:cce-id>CCE-3825-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.517Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.517Z</config:last-modified-datetime>
                <config:summary>The "Disable Internet Connection wizard" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:32.157Z">
                        <scap-core:mapping published="2009-07-30T20:05:32.157Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3853-9">
                <config:cce-id>CCE-3853-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.953Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.953Z</config:last-modified-datetime>
                <config:summary>The "Access data sources across domains" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:00.703Z">
                        <scap-core:mapping published="2009-07-30T20:06:00.703Z">AC-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3855-4">
                <config:cce-id>CCE-3855-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.360Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.360Z</config:last-modified-datetime>
                <config:summary>The "Software channel permissions" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:01.297Z">
                        <scap-core:mapping published="2009-07-30T20:06:01.297Z">CM-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3866-1">
                <config:cce-id>CCE-3866-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.907Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.907Z</config:last-modified-datetime>
                <config:summary>The "Turn off Managing Phishing Filter" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:37.377Z">
                        <scap-core:mapping published="2009-07-30T20:05:37.377Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:37.343Z">SI-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:37.360Z">SI-8</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3875-2">
                <config:cce-id>CCE-3875-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.920Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.920Z</config:last-modified-datetime>
                <config:summary>The "Turn off the Security Settings Check feature" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:28.217Z">
                        <scap-core:mapping published="2009-07-30T20:05:28.217Z">SI-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3888-5">
                <config:cce-id>CCE-3888-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.967Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.967Z</config:last-modified-datetime>
                <config:summary>The "Font download" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:32.313Z">
                        <scap-core:mapping published="2009-07-30T20:05:32.313Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3891-9">
                <config:cce-id>CCE-3891-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.627Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.627Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Local Machine Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:36.280Z">
                        <scap-core:mapping published="2009-07-30T20:05:36.280Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3894-3">
                <config:cce-id>CCE-3894-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.670Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.670Z</config:last-modified-datetime>
                <config:summary>The "Turn Off Crash Detection" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:59.390Z">
                        <scap-core:mapping published="2009-07-30T20:05:59.390Z">CM-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3902-4">
                <config:cce-id>CCE-3902-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.703Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.703Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Locked Down Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:40.343Z">
                        <scap-core:mapping published="2009-07-30T20:05:40.343Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3905-7">
                <config:cce-id>CCE-3905-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.157Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.157Z</config:last-modified-datetime>
                <config:summary>The "Access data sources across domains" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:52.627Z">
                        <scap-core:mapping published="2009-07-30T20:05:52.627Z">AC-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3906-5">
                <config:cce-id>CCE-3906-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.967Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.967Z</config:last-modified-datetime>
                <config:summary>The "Installation of desktop items" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:40.983Z">
                        <scap-core:mapping published="2009-07-30T20:05:40.983Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3909-9">
                <config:cce-id>CCE-3909-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.733Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.733Z</config:last-modified-datetime>
                <config:summary>The "Turn on Protected Mode" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:31.297Z">
                        <scap-core:mapping published="2009-07-30T20:05:31.297Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:31.297Z">CM-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3914-9">
                <config:cce-id>CCE-3914-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.093Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.093Z</config:last-modified-datetime>
                <config:summary>The "Userdata persistence" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:28.110Z">
                        <scap-core:mapping published="2009-07-30T20:05:28.110Z">SC-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3924-8">
                <config:cce-id>CCE-3924-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.563Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.563Z</config:last-modified-datetime>
                <config:summary>Internet Explorer Processes (Restrict ActiveX Install)</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:06.437Z">
                        <scap-core:mapping published="2009-07-30T20:06:06.437Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3927-1">
                <config:cce-id>CCE-3927-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.017Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.017Z</config:last-modified-datetime>
                <config:summary>The "Download signed ActiveX controls" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:41.640Z">
                        <scap-core:mapping published="2009-07-30T20:05:41.627Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:41.640Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3929-7">
                <config:cce-id>CCE-3929-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.577Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.577Z</config:last-modified-datetime>
                <config:summary>The "Security Zones: Do Not Allow Users to Add/Delete Sites" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:29.187Z">
                        <scap-core:mapping published="2009-07-30T20:05:29.187Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:29.187Z">AC-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:29.170Z">CM-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3933-9">
                <config:cce-id>CCE-3933-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.687Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.687Z</config:last-modified-datetime>
                <config:summary>The "Security Zones: Do Not Allow Users to Change Policies" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:25.500Z">
                        <scap-core:mapping published="2009-07-30T20:05:25.500Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:25.500Z">AC-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:25.500Z">CM-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3941-2">
                <config:cce-id>CCE-3941-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.610Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.610Z</config:last-modified-datetime>
                <config:summary>The "Allow Software to Run or Install Even if the Signature is Invalid" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:56.377Z">
                        <scap-core:mapping published="2009-07-30T20:05:56.343Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:56.377Z">SI-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3945-3">
                <config:cce-id>CCE-3945-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.017Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.017Z</config:last-modified-datetime>
                <config:summary>The "Download unsigned ActiveX controls" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:54.877Z">
                        <scap-core:mapping published="2009-07-30T20:05:54.877Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:54.843Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3963-6">
                <config:cce-id>CCE-3963-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.030Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.030Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:41.390Z">
                        <scap-core:mapping published="2009-07-30T20:05:41.390Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3976-8">
                <config:cce-id>CCE-3976-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.953Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.953Z</config:last-modified-datetime>
                <config:summary>The "Check for Server Certificate Revocation" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:29.250Z">
                        <scap-core:mapping published="2009-07-30T20:05:29.233Z">IA-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:29.250Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3984-2">
                <config:cce-id>CCE-3984-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.110Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.110Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:32.937Z">
                        <scap-core:mapping published="2009-07-30T20:05:32.937Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:32.920Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3989-1">
                <config:cce-id>CCE-3989-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.127Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.127Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Intranet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:33.813Z">
                        <scap-core:mapping published="2009-07-30T20:05:33.813Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:33.797Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3993-3">
                <config:cce-id>CCE-3993-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.877Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.877Z</config:last-modified-datetime>
                <config:summary>The "Prevent participation in the Customer Experience Improvement Programs" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:58.313Z">
                        <scap-core:mapping published="2009-07-30T20:05:58.313Z">AC-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3996-6">
                <config:cce-id>CCE-3996-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.267Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.267Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:59.500Z">
                        <scap-core:mapping published="2009-07-30T20:05:59.500Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-3998-2">
                <config:cce-id>CCE-3998-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.953Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.953Z</config:last-modified-datetime>
                <config:summary>The "Drag and drop or copy and paste files" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:58.670Z">
                        <scap-core:mapping published="2009-07-30T20:05:58.670Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4001-4">
                <config:cce-id>CCE-4001-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.843Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.843Z</config:last-modified-datetime>
                <config:summary>The "Disable "Configuring History"" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:48.577Z">
                        <scap-core:mapping published="2009-07-30T20:05:48.577Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4013-9">
                <config:cce-id>CCE-4013-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.733Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.733Z</config:last-modified-datetime>
                <config:summary>The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:25.953Z">
                        <scap-core:mapping published="2009-07-30T20:05:25.953Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4017-0">
                <config:cce-id>CCE-4017-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.563Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.563Z</config:last-modified-datetime>
                <config:summary>The "Security Zones: Use Only Machine Settings" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:27.000Z">
                        <scap-core:mapping published="2009-07-30T20:05:27.000Z">CM-2</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:27.000Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4018-8">
                <config:cce-id>CCE-4018-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.377Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.377Z</config:last-modified-datetime>
                <config:summary>The "Use Pop-up Blocker" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:31.047Z">
                        <scap-core:mapping published="2009-07-30T20:05:31.047Z">SI-8</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4026-1">
                <config:cce-id>CCE-4026-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.703Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.703Z</config:last-modified-datetime>
                <config:summary>The "Check for Signature on Downloaded Programs" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:03.233Z">
                        <scap-core:mapping published="2009-07-30T20:06:03.203Z">IA-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:06:03.233Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4028-7">
                <config:cce-id>CCE-4028-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.140Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.140Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Locked Down Local Machine Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:59.047Z">
                        <scap-core:mapping published="2009-07-30T20:05:59.047Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:59.030Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4031-1">
                <config:cce-id>CCE-4031-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.233Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.233Z</config:last-modified-datetime>
                <config:summary>The "Allow status bar updates via script" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:27.563Z">
                        <scap-core:mapping published="2009-07-30T20:05:27.563Z">SC-8</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:27.563Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4036-0">
                <config:cce-id>CCE-4036-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.517Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.517Z</config:last-modified-datetime>
                <config:summary>The "Turn on the Internet Connection Wizard Auto Detect" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:46.327Z">
                        <scap-core:mapping published="2009-07-30T20:05:46.327Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4040-2">
                <config:cce-id>CCE-4040-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.377Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.377Z</config:last-modified-datetime>
                <config:summary>The "Userdata persistence" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:39.170Z">
                        <scap-core:mapping published="2009-07-30T20:05:39.170Z">SC-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4043-6">
                <config:cce-id>CCE-4043-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.593Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.593Z</config:last-modified-datetime>
                <config:summary>Internet Explorer Processes (Zone Elevation Protection)</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:34.500Z">
                        <scap-core:mapping published="2009-07-30T20:05:34.500Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4047-7">
                <config:cce-id>CCE-4047-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.593Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.593Z</config:last-modified-datetime>
                <config:summary>The "Internet Explorer Processes (Consistent MIME Handling)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:26.327Z">
                        <scap-core:mapping published="2009-07-30T20:05:26.327Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4050-1">
                <config:cce-id>CCE-4050-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.157Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.157Z</config:last-modified-datetime>
                <config:summary>The "Active scripting" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:26.483Z">
                        <scap-core:mapping published="2009-07-30T20:05:26.483Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:26.483Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4052-7">
                <config:cce-id>CCE-4052-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.750Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.750Z</config:last-modified-datetime>
                <config:summary>The "Web Browser Applications" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:26.233Z">
                        <scap-core:mapping published="2009-07-30T20:05:26.233Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:26.233Z">CM-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4053-5">
                <config:cce-id>CCE-4053-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.233Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.233Z</config:last-modified-datetime>
                <config:summary>The "Automatic prompting for file downloads" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:36.343Z">
                        <scap-core:mapping published="2009-07-30T20:05:36.343Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:36.327Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4056-8">
                <config:cce-id>CCE-4056-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.453Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.453Z</config:last-modified-datetime>
                <config:summary>The "Turn off page transitions" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:37.517Z">
                        <scap-core:mapping published="2009-07-30T20:05:37.517Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4057-6">
                <config:cce-id>CCE-4057-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.250Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.250Z</config:last-modified-datetime>
                <config:summary>The "Download signed ActiveX controls" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:38.047Z">
                        <scap-core:mapping published="2009-07-30T20:05:38.047Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:38.030Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4062-6">
                <config:cce-id>CCE-4062-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.187Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.187Z</config:last-modified-datetime>
                <config:summary>The "Font download" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:30.187Z">
                        <scap-core:mapping published="2009-07-30T20:05:30.187Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4066-7">
                <config:cce-id>CCE-4066-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.280Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.280Z</config:last-modified-datetime>
                <config:summary>The "Launching programs and files in an IFRAME" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:45.877Z">
                        <scap-core:mapping published="2009-07-30T20:05:45.877Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:45.860Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4068-3">
                <config:cce-id>CCE-4068-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.030Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.030Z</config:last-modified-datetime>
                <config:summary>The "Initialize and script ActiveX controls not marked as safe for scripting" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:04.000Z">
                        <scap-core:mapping published="2009-07-30T20:06:04.000Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4079-0">
                <config:cce-id>CCE-4079-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.203Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.203Z</config:last-modified-datetime>
                <config:summary>The "Installation of desktop items" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:31.687Z">
                        <scap-core:mapping published="2009-07-30T20:05:31.687Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4084-0">
                <config:cce-id>CCE-4084-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.203Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.203Z</config:last-modified-datetime>
                <config:summary>The "Allow META REFRESH" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:32.983Z">
                        <scap-core:mapping published="2009-07-30T20:05:32.983Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4087-3">
                <config:cce-id>CCE-4087-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.420Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.420Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Trusted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:25.703Z">
                        <scap-core:mapping published="2009-07-30T20:05:25.703Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:25.703Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4098-0">
                <config:cce-id>CCE-4098-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.813Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.813Z</config:last-modified-datetime>
                <config:summary>The "Turn Off Configuring the Update Check Interval (In Days)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:59.767Z">
                        <scap-core:mapping published="2009-07-30T20:05:59.767Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:59.733Z">SI-2</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4099-8">
                <config:cce-id>CCE-4099-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.983Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.983Z</config:last-modified-datetime>
                <config:summary>The "Allow script-initiated windows without size or position constraints" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:49.127Z">
                        <scap-core:mapping published="2009-07-30T20:05:49.127Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:49.093Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4101-2">
                <config:cce-id>CCE-4101-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.267Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.267Z</config:last-modified-datetime>
                <config:summary>The "Initialize and script ActiveX controls not marked as safe for scripting" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:48.343Z">
                        <scap-core:mapping published="2009-07-30T20:05:48.343Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4104-6">
                <config:cce-id>CCE-4104-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.047Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.047Z</config:last-modified-datetime>
                <config:summary>The "Launching programs and files in an IFRAME" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:39.110Z">
                        <scap-core:mapping published="2009-07-30T20:05:39.110Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:39.093Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4109-5">
                <config:cce-id>CCE-4109-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.717Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.717Z</config:last-modified-datetime>
                <config:summary>The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:37.203Z">
                        <scap-core:mapping published="2009-07-30T20:05:37.203Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4110-3">
                <config:cce-id>CCE-4110-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.297Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.297Z</config:last-modified-datetime>
                <config:summary>The "Navigate sub-frames across different domains" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:41.140Z">
                        <scap-core:mapping published="2009-07-30T20:05:41.140Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4118-6">
                <config:cce-id>CCE-4118-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.627Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.627Z</config:last-modified-datetime>
                <config:summary>The "Disable Software Update Shell Notifications on Program Launch" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:42.530Z">
                        <scap-core:mapping published="2009-07-30T20:05:42.517Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:42.530Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4119-4">
                <config:cce-id>CCE-4119-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.217Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.217Z</config:last-modified-datetime>
                <config:summary>The "Allow script-initiated windows without size or position constraints" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:42.267Z">
                        <scap-core:mapping published="2009-07-30T20:05:42.267Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:42.250Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4121-0">
                <config:cce-id>CCE-4121-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.127Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.127Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Locked Down Intranet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:25.593Z">
                        <scap-core:mapping published="2009-07-30T20:05:25.593Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:25.593Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4122-8">
                <config:cce-id>CCE-4122-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.627Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.627Z</config:last-modified-datetime>
                <config:summary>The "Internet Explorer Processes (Restrict File Download)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:32.703Z">
                        <scap-core:mapping published="2009-07-30T20:05:32.703Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4131-9">
                <config:cce-id>CCE-4131-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.733Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.733Z</config:last-modified-datetime>
                <config:summary>The "Web Browser Applications" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:40.110Z">
                        <scap-core:mapping published="2009-07-30T20:05:40.110Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:40.093Z">CM-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4132-7">
                <config:cce-id>CCE-4132-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.313Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.313Z</config:last-modified-datetime>
                <config:summary>The "Open files based on content, not file extension" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:46.110Z">
                        <scap-core:mapping published="2009-07-30T20:05:46.110Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4138-4">
                <config:cce-id>CCE-4138-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.140Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.140Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Local Machine Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:44.640Z">
                        <scap-core:mapping published="2009-07-30T20:05:44.640Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:44.610Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4139-2">
                <config:cce-id>CCE-4139-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.000Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.000Z</config:last-modified-datetime>
                <config:summary>The "Automatic prompting for file downloads" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:39.577Z">
                        <scap-core:mapping published="2009-07-30T20:05:39.577Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:39.563Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4143-4">
                <config:cce-id>CCE-4143-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.063Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.063Z</config:last-modified-datetime>
                <config:summary>The "Navigate sub-frames across different domains" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:29.577Z">
                        <scap-core:mapping published="2009-07-30T20:05:29.577Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4147-5">
                <config:cce-id>CCE-4147-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.843Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.843Z</config:last-modified-datetime>
                <config:summary>The "Disable Changing Automatic Configuration Settings" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:57.627Z">
                        <scap-core:mapping published="2009-07-30T20:05:57.627Z">CM-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4149-1">
                <config:cce-id>CCE-4149-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.687Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.687Z</config:last-modified-datetime>
                <config:summary>The "Internet Explorer Processes (MIME Sniffing)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:26.297Z">
                        <scap-core:mapping published="2009-07-30T20:05:26.297Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4150-9">
                <config:cce-id>CCE-4150-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.187Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.187Z</config:last-modified-datetime>
                <config:summary>The "File download" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:25.780Z">
                        <scap-core:mapping published="2009-07-30T20:05:25.780Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4153-3">
                <config:cce-id>CCE-4153-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.733Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.733Z</config:last-modified-datetime>
                <config:summary>The "Turn Off First- Run Opt-In" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:33.140Z">
                        <scap-core:mapping published="2009-07-30T20:05:33.140Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4158-2">
                <config:cce-id>CCE-4158-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.327Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.327Z</config:last-modified-datetime>
                <config:summary>The "Run components signed with Authenticode" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:34.063Z">
                        <scap-core:mapping published="2009-07-30T20:05:34.063Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:34.047Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4160-8">
                <config:cce-id>CCE-4160-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.640Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.640Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Locked Down Local Machine Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:31.467Z">
                        <scap-core:mapping published="2009-07-30T20:05:31.467Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4161-6">
                <config:cce-id>CCE-4161-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.077Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.077Z</config:last-modified-datetime>
                <config:summary>The "Open files based on content, not file extension" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:31.640Z">
                        <scap-core:mapping published="2009-07-30T20:05:31.640Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4162-4">
                <config:cce-id>CCE-4162-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.670Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.670Z</config:last-modified-datetime>
                <config:summary>The "Internet Explorer Processes (Scripted Window Security Restrictions)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:32.267Z">
                        <scap-core:mapping published="2009-07-30T20:05:32.267Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4163-2">
                <config:cce-id>CCE-4163-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.343Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.343Z</config:last-modified-datetime>
                <config:summary>The "Run ActiveX controls and plugins" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:32.203Z">
                        <scap-core:mapping published="2009-07-30T20:05:32.203Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4171-5">
                <config:cce-id>CCE-4171-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.703Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.703Z</config:last-modified-datetime>
                <config:summary>The "Do Not Allow Resetting Internet Explorer Settings" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:04.140Z">
                        <scap-core:mapping published="2009-07-30T20:06:04.140Z">CM-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4174-9">
                <config:cce-id>CCE-4174-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.920Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.920Z</config:last-modified-datetime>
                <config:summary>The "Allow Active Content from CD's to Run on User Machine" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:46.233Z">
                        <scap-core:mapping published="2009-07-30T20:05:46.203Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:46.233Z">SI-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4175-6">
                <config:cce-id>CCE-4175-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.767Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.767Z</config:last-modified-datetime>
                <config:summary>The "Intranet Sites: Include all network paths (UNCs)" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:30.047Z">
                        <scap-core:mapping published="2009-07-30T20:05:30.047Z">AC-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4192-1">
                <config:cce-id>CCE-4192-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.937Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.937Z</config:last-modified-datetime>
                <config:summary>The "Enable third-party browser extensions" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:00.953Z">
                        <scap-core:mapping published="2009-07-30T20:06:00.953Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:06:00.920Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4196-2">
                <config:cce-id>CCE-4196-2</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.170Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.170Z</config:last-modified-datetime>
                <config:summary>The "Binary and script behaviors" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:34.327Z">
                        <scap-core:mapping published="2009-07-30T20:05:34.327Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:05:34.327Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4199-6">
                <config:cce-id>CCE-4199-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:14.797Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:14.797Z</config:last-modified-datetime>
                <config:summary>The "Prevent Ignoing Certificate Errors" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:05:43.517Z">
                        <scap-core:mapping published="2009-07-30T20:05:43.517Z">SI-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4202-8">
                <config:cce-id>CCE-4202-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.343Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.343Z</config:last-modified-datetime>
                <config:summary>The "Script ActiveX controls marked safe for scripting" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:04.610Z">
                        <scap-core:mapping published="2009-07-30T20:06:04.610Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4215-0">
                <config:cce-id>CCE-4215-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.390Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.390Z</config:last-modified-datetime>
                <config:summary>The "Web sites in less privileged Web content zones can navigate into this zone" setting should be configured correctly for the Restricted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:14:54.860Z">
                        <scap-core:mapping published="2009-08-20T16:14:54.860Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-08-20T16:14:54.860Z">CM-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4226-7">
                <config:cce-id>CCE-4226-7</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.530Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.530Z</config:last-modified-datetime>
                <config:summary>The "Disable the Reset Web Settings feature" should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:32.093Z">
                        <scap-core:mapping published="2009-07-30T20:06:32.093Z">CM-5</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:06:32.093Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4232-5">
                <config:cce-id>CCE-4232-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.420Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.420Z</config:last-modified-datetime>
                <config:summary>The "Display mixed content" setting should be configured correctly for the Locked Down Trusted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:40.110Z">
                        <scap-core:mapping published="2009-07-30T20:06:40.110Z">AC-3</scap-core:mapping>
                        <scap-core:mapping published="2009-07-30T20:06:40.110Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4237-4">
                <config:cce-id>CCE-4237-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.500Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.500Z</config:last-modified-datetime>
                <config:summary>The "Disable external branding of Internet Explorer" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:36.983Z">
                        <scap-core:mapping published="2009-07-30T20:06:36.983Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4246-5">
                <config:cce-id>CCE-4246-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.467Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.467Z</config:last-modified-datetime>
                <config:summary>The "Disable AutoComplete for forms" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:38.077Z">
                        <scap-core:mapping published="2009-07-30T20:06:38.077Z">CM-5</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4259-8">
                <config:cce-id>CCE-4259-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.437Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.437Z</config:last-modified-datetime>
                <config:summary>The "Enable Native XMLHttp Support" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:15:11.483Z">
                        <scap-core:mapping published="2009-08-20T16:15:11.483Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4546-8">
                <config:cce-id>CCE-4546-8</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.717Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.717Z</config:last-modified-datetime>
                <config:summary>The "Allow status bar updates via script" setting should be configured correctly for the Locked-Down Trusted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:32.217Z">
                        <scap-core:mapping published="2009-07-30T20:06:32.217Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4564-1">
                <config:cce-id>CCE-4564-1</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.717Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.717Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Locked Down Trusted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:40.967Z">
                        <scap-core:mapping published="2009-07-30T20:06:40.967Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4581-5">
                <config:cce-id>CCE-4581-5</config:cce-id>
                <config:published-datetime>2009-07-30T19:31:58.670Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:31:58.670Z</config:last-modified-datetime>
                <config:summary>The "Turn off downloading of enclosures" setting should be configured correctly.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:15:12.233Z">
                        <scap-core:mapping published="2009-08-20T16:15:12.233Z">CM-6</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4643-3">
                <config:cce-id>CCE-4643-3</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.657Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.657Z</config:last-modified-datetime>
                <config:summary>The "Turn on Protected Mode" setting should be configured correctly for the Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:15:04.030Z">
                        <scap-core:mapping published="2009-08-20T16:15:04.017Z">CM-6</scap-core:mapping>
                        <scap-core:mapping published="2009-08-20T16:15:04.030Z">CM-7</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4652-4">
                <config:cce-id>CCE-4652-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.670Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.670Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Intranet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-07-30T20:06:35.360Z">
                        <scap-core:mapping published="2009-07-30T20:06:35.360Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4692-0">
                <config:cce-id>CCE-4692-0</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.687Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.687Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Locked Down Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:14:51.233Z">
                        <scap-core:mapping published="2009-08-20T16:14:51.233Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4763-9">
                <config:cce-id>CCE-4763-9</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.657Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.657Z</config:last-modified-datetime>
                <config:summary>Computer-wide, rather than per-user, assignment of sites to zones for Internet Explorer should be enabled or disabled as appropriate.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:15:03.877Z">
                        <scap-core:mapping published="2009-08-20T16:15:03.877Z">AC-4</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4793-6">
                <config:cce-id>CCE-4793-6</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.670Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.670Z</config:last-modified-datetime>
                <config:summary>The "Download signed ActiveX controls" setting should be configured correctly for the Locked-Down Internet Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:15:59.967Z">
                        <scap-core:mapping published="2009-08-20T16:15:59.967Z">SC-1</scap-core:mapping>
                        <scap-core:mapping published="2009-08-20T16:15:59.967Z">SI-3</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
            <ncp:cce id="CCE-4845-4">
                <config:cce-id>CCE-4845-4</config:cce-id>
                <config:published-datetime>2009-07-30T19:30:15.733Z</config:published-datetime>
                <config:last-modified-datetime>2009-07-30T19:30:15.733Z</config:last-modified-datetime>
                <config:summary>The "Java permissions" setting should be configured correctly for the Trusted Sites Zone.</config:summary>
                <scap-core:control-mappings>
                    <scap-core:control-mapping system-id="http://csrc.nist.gov/publications/PubsSPs.html#SP-800-53-Rev.%203" source="http://nvd.nist.gov/" last-modified="2009-08-20T16:16:03.670Z">
                        <scap-core:mapping published="2009-08-20T16:16:03.670Z">SC-1</scap-core:mapping>
                    </scap-core:control-mapping>
                </scap-core:control-mappings>
            </ncp:cce>
        </ncp:cce-mapping-list>
    </entry>
    <entry id="282" checklist-version="Version 5, Release 1.19" published-datetime="2008-03-31T04:00:00.000Z" entry-datetime="2008-03-31T04:00:00.000Z" checklist-name="UNIX Security Checklist" last-modified-datetime="2009-10-07T17:09:25.937Z">
        <ncp:tier>3</ncp:tier>
        <ncp:review-status>UNDER_REVIEW</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Redhat Enterprise Linux 4.0</ncp:name>
            <ncp:cpe-name>cpe:/o:redhat:enterprise_linux:4.0</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This guide has been created to assist IT professionals, in effectively securing systems with Red Hat Enterprise Linux 4.</ncp:summary>
        <ncp:checklist-role>Operating System</ncp:checklist-role>
        <ncp:target-audience>Developed for the DOD.
This document is intended for IAOs, SAs, IAMs, NSOs, and others who are responsible for the configuration, management, or support of information systems. It assumes that the reader has knowledge of the UNIX operating system and is familiar with common computer terminology.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.</ncp:comments-warnings-miscellaneous>
        <ncp:disclaimer>Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment. NIST assumes no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic. NIST would appreciate acknowledgement if the document and template are used.</ncp:disclaimer>
        <ncp:product-support>It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.</ncp:product-support>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/stig/unix-stig-v5r1.pdf" />
            <ncp:description />
        </ncp:ncp-reference>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>true</ncp:scap-expressed>
            <ncp:xccdf-expressed>true</ncp:xccdf-expressed>
            <ncp:oval-expressed>true</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>true</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:scap-content>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/scap/content/scap-rhel4-content.zip" />
            <ncp:author system-id="http://www.irs.gov/" name="IRS" />
            <ncp:sha-1>CEDF5407C0E9C96996853B647A90461E43312A81</ncp:sha-1>
            <ncp:sha-256>7ED1A3EEE24EFE888934F3C3153B43C02760CA977D9F52050A2285460B039B2A</ncp:sha-256>
            <ncp:description>SCAP content for the checklist entitled SCAP: Guide To The Secure Configuration of Red Hat Enterprise Linux 4.</ncp:description>
            <ncp:type>SCAP_CONTENT</ncp:type>
        </ncp:scap-content>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/scap/content/scap-rhel4-content.zip" />
            <ncp:author system-id="http://www.irs.gov/" name="IRS" />
            <ncp:sha-1>CEDF5407C0E9C96996853B647A90461E43312A81</ncp:sha-1>
            <ncp:sha-256>7ED1A3EEE24EFE888934F3C3153B43C02760CA977D9F52050A2285460B039B2A</ncp:sha-256>
            <ncp:description>SCAP content for the checklist entitled SCAP: Guide To The Secure Configuration of Red Hat Enterprise Linux 4.</ncp:description>
            <ncp:type>SCAP Content</ncp:type>
        </ncp:supporting-resource>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/unix_checklist_v5r1-19_20090815.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>CFC60D835D75538A8DC56C62B9DC48A5ADB83DAA</ncp:sha-1>
            <ncp:sha-256>A84319C8F2495F6E8784A7845AC50DF892E8356B7842EC24189A36100997E1E9</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="283" checklist-version="Version 5, Release 1.19" published-datetime="2008-03-31T04:00:00.000Z" entry-datetime="2008-03-31T04:00:00.000Z" checklist-name="UNIX Security Checklist" last-modified-datetime="2009-10-07T15:22:20.603Z">
        <ncp:tier>3</ncp:tier>
        <ncp:review-status>UNDER_REVIEW</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Sun Solaris 9</ncp:name>
            <ncp:cpe-name>cpe:/o:sun:solaris:9</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This guide has been created to assist IT professionals, in effectively securing systems with Sun Microsystems Solaris 9.</ncp:summary>
        <ncp:checklist-role>Operating System</ncp:checklist-role>
        <ncp:target-audience>Developed for the DOD.

This guide has been created to assist IT professionals, in effectively securing systems with Sun Microsystems Solaris 9.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.</ncp:comments-warnings-miscellaneous>
        <ncp:disclaimer>This guide has been created to assist IT professionals, in effectively securing systems with Sun Microsystems Solaris 9.</ncp:disclaimer>
        <ncp:product-support>It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.</ncp:product-support>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/stig/unix-stig-v5r1.pdf" />
            <ncp:description />
        </ncp:ncp-reference>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>true</ncp:scap-expressed>
            <ncp:xccdf-expressed>true</ncp:xccdf-expressed>
            <ncp:oval-expressed>true</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>true</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:scap-content>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/scap/content/scap-sol9-content.zip" />
            <ncp:author system-id="http://www.irs.gov/" name="IRS" />
            <ncp:sha-1>CBFF22750ADEA3CCD14E34C422B76CCC232C8B5A</ncp:sha-1>
            <ncp:sha-256>0EF8545AA5C2D12DAE5C8A4111A1102085F8CE52ABA6A2C1975404241ABBEA50</ncp:sha-256>
            <ncp:description>SCAP content for checklist entitled SCAP: Guide To The Secure Configuration of Sun Solaris 9.</ncp:description>
            <ncp:type>SCAP_CONTENT</ncp:type>
        </ncp:scap-content>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/scap/content/scap-sol9-content.zip" />
            <ncp:author system-id="http://www.irs.gov/" name="IRS" />
            <ncp:sha-1>CBFF22750ADEA3CCD14E34C422B76CCC232C8B5A</ncp:sha-1>
            <ncp:sha-256>0EF8545AA5C2D12DAE5C8A4111A1102085F8CE52ABA6A2C1975404241ABBEA50</ncp:sha-256>
            <ncp:description>SCAP content for checklist entitled SCAP: Guide To The Secure Configuration of Sun Solaris 9.</ncp:description>
            <ncp:type>SCAP Content</ncp:type>
        </ncp:supporting-resource>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/unix_checklist_v5r1-19_20090815.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>CFC60D835D75538A8DC56C62B9DC48A5ADB83DAA</ncp:sha-1>
            <ncp:sha-256>A84319C8F2495F6E8784A7845AC50DF892E8356B7842EC24189A36100997E1E9</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="285" checklist-version="Version 5, Release 1.19" published-datetime="2008-03-31T04:00:00.000Z" entry-datetime="2008-03-31T04:00:00.000Z" checklist-name="UNIX Security Checklist" last-modified-datetime="2009-10-07T16:33:14.827Z">
        <ncp:tier>2</ncp:tier>
        <ncp:review-status>UNDER_REVIEW</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>HP HP-UX 11</ncp:name>
            <ncp:cpe-name>cpe:/o:hp:hp-ux:11</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This guide has been created to assist IT professionals, in effectively securing systems with HP-UX 11.</ncp:summary>
        <ncp:checklist-role>Operating System</ncp:checklist-role>
        <ncp:target-audience>Developed for the DOD.
This document is intended for IAOs, SAs, IAMs, NSOs, and others who are responsible for the configuration, management, or support of information systems. It assumes that the reader has knowledge of the UNIX operating system and is familiar with common computer terminology.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.</ncp:comments-warnings-miscellaneous>
        <ncp:disclaimer>Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment. NIST assumes no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic. NIST would appreciate acknowledgement if the document and template are used</ncp:disclaimer>
        <ncp:product-support>It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.</ncp:product-support>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/stig/unix-stig-v5r1.pdf" />
            <ncp:description />
        </ncp:ncp-reference>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>true</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>true</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/scap/content/scap-hpux11-content.zip" />
            <ncp:author system-id="http://www.irs.gov/" name="IRS" />
            <ncp:sha-1>9F449A6BBE5100416B4487E66038368816B72BE9</ncp:sha-1>
            <ncp:sha-256>2A1AAC44576C0E466D732A06CA8824DEA51E3F941DF1DDA58BD73614DE57A279</ncp:sha-256>
            <ncp:description>The machine-readable configuration guidance for the checklist entitled SCAP: Guide To The Secure Configuration of HP-UX 11.</ncp:description>
            <ncp:type>Standalone XCCDF</ncp:type>
        </ncp:supporting-resource>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/unix_checklist_v5r1-19_20090815.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>CFC60D835D75538A8DC56C62B9DC48A5ADB83DAA</ncp:sha-1>
            <ncp:sha-256>A84319C8F2495F6E8784A7845AC50DF892E8356B7842EC24189A36100997E1E9</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="284" checklist-version="Version 5, Release 1.19" published-datetime="2008-03-31T04:00:00.000Z" entry-datetime="2008-03-31T04:00:00.000Z" checklist-name="UNIX Security Checklist" last-modified-datetime="2009-10-07T16:32:57.767Z">
        <ncp:tier>2</ncp:tier>
        <ncp:review-status>UNDER_REVIEW</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>IBM AIX 5</ncp:name>
            <ncp:cpe-name>cpe:/o:ibm:aix:5</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This guide has been created to assist IT professionals, in effectively securing systems with IBM AIX 5.</ncp:summary>
        <ncp:checklist-role>Operating System</ncp:checklist-role>
        <ncp:target-audience>Developed for the DOD.
This document is intended for IAOs, SAs, IAMs, NSOs, and others who are responsible for the configuration, management, or support of information systems. It assumes that the reader has knowledge of the UNIX operating system and is familiar with common computer terminology.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.</ncp:comments-warnings-miscellaneous>
        <ncp:disclaimer>Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment. NIST assumes no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic. NIST would appreciate acknowledgement if the document and template are used.</ncp:disclaimer>
        <ncp:product-support>It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.</ncp:product-support>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/stig/unix-stig-v5r1.pdf" />
            <ncp:description />
        </ncp:ncp-reference>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>true</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>true</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://nvd.nist.gov/scap/content/scap-aix5-content.zip" />
            <ncp:author system-id="http://www.irs.gov/" name="IRS" />
            <ncp:sha-1>8482B0FF060F1F105E514325310AFA314F4AC625</ncp:sha-1>
            <ncp:sha-256>473716B92B81D54379ADDD358721FDEAA9503FF2AC1BD74112124D69321264C0</ncp:sha-256>
            <ncp:description>This is the machine-readable configuration content for the checklist entitled SCAP: Guide To The Secure Configuration of IBM AIX 5.</ncp:description>
            <ncp:type>Standalone XCCDF</ncp:type>
        </ncp:supporting-resource>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/unix_checklist_v5r1-19_20090815.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>CFC60D835D75538A8DC56C62B9DC48A5ADB83DAA</ncp:sha-1>
            <ncp:sha-256>A84319C8F2495F6E8784A7845AC50DF892E8356B7842EC24189A36100997E1E9</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="94" checklist-version="Version 6, Release 1.11" published-datetime="2009-04-23T04:00:00.000Z" entry-datetime="2007-10-31T04:00:00.000Z" checklist-name="Web Apache Checklist" last-modified-datetime="2009-10-07T15:08:33.823Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>UNDER_REVIEW</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Apache HTTP Server 2.0</ncp:name>
            <ncp:cpe-name>cpe:/a:apache:http_server:2.0</ncp:cpe-name>
            <ncp:product-category>Web Server</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Apache HTTP Server 1.3</ncp:name>
            <ncp:cpe-name>cpe:/a:apache:http_server:1.3</ncp:cpe-name>
            <ncp:product-category>Web Server</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This group of checklists covers valuable security-related information for the Apache web server and web site server products.  It includes procedures to perform a Security Readiness Review (SRR).  Security items covered are based on the Web Server Secure Technology Implementation Guide (STIG) published by DISA.  The reviewer will apply Systems Administration knowledge and have familiarity with web server and web site configurations.  Apache Server, UNIX, Linux, and/or Windows server experience is beneficial. Users of this checklist will need to be able to navigate the file systems of these operating environments.    

This web server checklist targets conditions that undermine the integrity of security, contribute to inefficient security operations and administration, or that may lead to the interruption of production operations.  The documentation provides procedures for assessing Apache web server and Apache web site server products. The document is broken into the following sections:

Section 1: Contains specific product requirements for an Apache web server that were not addressed in the Web Server Secure Technology Implementation Guide (STIG) [http://iase.disa.mil/stigs/stig/index.html]. 

Section 2: Is not applicable to assessing Apache, but is specific to clients of the DISA VMS database.

Section 3: Provides configuration information for Apache 1.3.x web server installations focusing on mitigating denial of dervice attacks, restricting file access, mitigating buffer overflows, account management, OS and DMZ configurations.

Section 4: Provides configuration information for Apache web site 1.3.x in the areas of policy configuration, account privileges, and encryption.

Section 5: Provides configuration information for Apache 2.x web server installations focusing on mitigating Denial of Service attacks, restricting file access, mitigating buffer overflows, account management, OS and DMZ configurations.

Section 6: Provides configuration information for Apache web site 2.x in the areas of policy configuration, account privileges, and encryption.

Note: Specific assessment procedures and information for assessing Apache can be found in all other sections of this checklist bundle, some of which is question-answer oriented.</ncp:summary>
        <ncp:checklist-role>Web Server</ncp:checklist-role>
        <ncp:target-audience>Developed by DISA for the DOD.  This document is intended for those responsible 
for the configuration and management of information systems. It assumes that the 
reader has knowledge of web servers and is familiar with common computer terminology.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.2, DOD Directive 8520.2</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist.</ncp:comments-warnings-miscellaneous>
        <ncp:product-support>Only available to DOD customers.</ncp:product-support>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/web_srr_checklist_apache_v6r1-11.zip" />
            <ncp:sha-1>781955F1F661BD3014D61548008B1742E2393257</ncp:sha-1>
            <ncp:sha-256>E2479B2ECBB09E82F542EB211F74AAC864547389D2B6D9430379F545B47128F7</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="25" checklist-version="Version 4 Release 1.7" published-datetime="2009-06-15T04:00:00.000Z" entry-datetime="2007-10-29T04:00:00.000Z" checklist-name="Domain Name System Security Checklist" last-modified-datetime="2009-10-07T15:13:18.370Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>FINAL</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Server 2003</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_2003_server</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>ISC Bind 9.3.1</ncp:name>
            <ncp:cpe-name>cpe:/a:isc:bind:9.3.1</ncp:cpe-name>
            <ncp:product-category>DNS Servers</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>ISC Bind 9.3.2</ncp:name>
            <ncp:cpe-name>cpe:/a:isc:bind:9.3.2</ncp:cpe-name>
            <ncp:product-category>DNS Servers</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Server 2000</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_2000:::server</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows XP</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_xp</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows 2000</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_2000</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Cisco Content Services Switch</ncp:name>
            <ncp:cpe-name>cpe:/h:cisco:content_services_switch</ncp:cpe-name>
            <ncp:product-category>Network Switch</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This document contains procedures that enable qualified personnel to conduct a Domain Name System (DNS) Security Readiness Review (SRR).  The DNS SRR assesses an organizationÃ?Â¢??s compliance with the Defense Information Systems Agency (DISA) DNS Security Technical Implementation Guidance (STIG).  DISA Field Security Operations (FSO) conducts SRRs to provide DISA, Joint Commands, and other Department of Defense (DOD) organizations with a level of confidence that their DNS is secure and can adequately support their mission. 

This document provides step by step instructions to verify Domain Name Systems are securely configured.  This checklist is arranged by asset posture. The first section is dedicated to the Non-Computing Asset posture of DNS Policy.  These checks/requirements need only be performed once for the site as they apply to all DNS servers and the DNS architecture, regardless of platform or function.  The finding status should be updated if a change takes place on the system, during a yearly accreditation visit if vulnerabilities are identified, or during a self assessment.  The remaining sections focus on the computing asset posture of the type of DNS software running on the platform: All DNS servers, BIND, Windows DNS, or CISCO CSS.  

- Section 2: Non-Computing DNS Policy 
- Section 3: All DNS servers
- Section 4: BIND servers, both UNIX and Windows operating system platforms
- Section 5: Windows DNS Server
- Section 6: CISCO CSS DNS</ncp:summary>
        <ncp:checklist-role>Domain Name Server</ncp:checklist-role>
        <ncp:known-issues>The reviewer must examine the IAVM notices carefully when there are potential issues.  In future releases of the checklist, additional guidance will be provided on how to check for these scenarios.</ncp:known-issues>
        <ncp:target-audience>Developped for the DOD.
This checklist has been created for IT professionals, particularly network system administrators and information security personnel. The document assumes that the reader has experience installing and administering DNS Servers.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.</ncp:comments-warnings-miscellaneous>
        <ncp:product-support>It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.</ncp:product-support>
        <ncp:change-history>Version 1, Release 1, date unknown
Version 1, Release 2.2, date unknown
Version 1, Release 3.1, date unknown
Version 2, Release 1.1, 2004-05-12
Version 2, Release 1.2, 2004-07-15
Version 2, Release 1.3, 2005-08-08
Version 2, Release 2, 2006-06-16
Version 3, Release 1, 2006-12-08
Version 3, Release 1.1, 2007-03-15
Version 4, Release 1.1, 2007-10-17
Version 4, Release 1.5, 2008-12-15</ncp:change-history>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/dns-checklist-vr4r1-7_20090815.pdf" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>72C424EEFF19910FF5B5E45DBB36C9E4DC7B82BD</ncp:sha-1>
            <ncp:sha-256>4BAEBA2A91B857E08C58AC19877CED2DE81A7F6ADABA05C4E28845B92DBDDB21</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="135" checklist-version="Version 8, Release 1.2" published-datetime="2006-10-29T04:00:00.000Z" entry-datetime="2007-11-08T05:00:00.000Z" checklist-name="Generic Database Security Checklist" last-modified-datetime="2009-10-07T17:56:25.277Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>FINAL</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Microsoft SQL Server 2000</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:sql_server:2000</ncp:cpe-name>
            <ncp:product-category>Database Management System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Oracle Database 8i</ncp:name>
            <ncp:cpe-name>cpe:/a:oracle:oracle8i</ncp:cpe-name>
            <ncp:product-category>Database Management System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Oracle Database 10g</ncp:name>
            <ncp:cpe-name>cpe:/a:oracle:oracle10g</ncp:cpe-name>
            <ncp:product-category>Database Management System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Oracle Database 9i</ncp:name>
            <ncp:cpe-name>cpe:/a:oracle:oracle9i</ncp:cpe-name>
            <ncp:product-category>Database Management System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>IBM DB2 8.1</ncp:name>
            <ncp:cpe-name>cpe:/a:ibm:db2:8.1</ncp:cpe-name>
            <ncp:product-category>Database Management System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft SQL Server 7.0</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:sql_server:7.0</ncp:cpe-name>
            <ncp:product-category>Database Management System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>The Database Security Readiness Review (SRR) targets conditions that undermine the integrity of security, contribute to inefficient security operations and administration, or may lead to interruption of production operations. This SRR guide focuses strictly on Oracle versions 8i, 9i and Microsoft SQL Server versions 7.0, 2000. Additionally, this checklist ensures the site has properly installed and implemented the database environment and that it is being managed in a way that is secure, efficient, and effective, through procedures outlined in the checklist. The items reviewed are based on standards and requirements published by DISA in the Security Handbook and the Database Security Technical Implementation Guide. The results of the SRR scripts will coincide with the Database SRR Checklist with the following: F - Finding, N/F - Not A Finding, N/A - Not Applicable, MR - Manual Review, or NR - Not Reviewed, which can be filled in Section 2A (Oracle SRR Result Report) or Section 2B (MS SQL Server SRR Results Report). 

DISA Field Security Operations has assigned a level of urgency to each finding based on Chief Information Officer (CIO) established criteria for certification and accreditation. All findings are based on regulations and guidelines. All findings require correction by the host organization. Category I findings are any vulnerabilities that provide an attacker immediate access into a machine, superuser access, or access that bypasses a firewall. Category II findings are any vulnerabilities that provide information that has a high potential of giving access to an intruder. Category III findings are any vulnerabilities that provide information that potentially could lead to compromise. Category IV vulnerabilities, when resolved, will prevent the possibility of degraded security.</ncp:summary>
        <ncp:checklist-role>Database Server</ncp:checklist-role>
        <ncp:known-issues>The vulnerabilities discussed in Sections 2A and 3A of this document are applicable to Oracle versions 8i, 9i, and 10g, vulnerabilities discussed in Sections 2B and 3B are applicable to MS SQL Server versions 7.0 and 2000, and vulnerabilities discussed in Sections 2C and 3C are applicable to DB2 version 8 on Unix and Windows platforms. The checklist does not address database versions earlier than those referenced above. For earlier versions, the reviewer should mark all checks except the check for a supported version, as NA and treat this as a completed database review. The unsupported version check should be marked as Open. The generic checklist should be used to cover databases other than Oracle, SQL Server, and DB2. To perform a successful Security Readiness Review (SRR), this document provides two methods to assess vulnerabilities on an Oracle and MS SQL Server DBMS Ã????Ã???Ã??Ã?Â¢?? DISA FSO scripts and manual procedures. The manual procedures should be performed if the SRR command-scripts are not available, if they are not permitted, or if there is a discrepancy in the toolsÃ????Ã???Ã??Ã?Â¢?? reporting.</ncp:known-issues>
        <ncp:target-audience>Developped for the DOD.
This checklist has been created for IT professionals, information security and database personnel. The document assumes that the reader has experience administering Oracle, SQL Server, DB2, or other databases.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist or the README.TXT files provided with the scripts for any comments, warnings, or detailed instructions.</ncp:comments-warnings-miscellaneous>
        <ncp:product-support>It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.</ncp:product-support>
        <ncp:change-history>Version 6, Release 1.4, 2004-05
Version 6, Release 1.5, 2004-09
Version 6, Release 1.6, 2004-12-10
Version 7, Release 1.2, 2005-07-29
Version 7, Release 1.3, 2005-12-16
Version 7, Release 1.4, 2006-04-14
Version 7, Release 2.1, 2006-06-30
Version 7, Release 2.2, 2006-10-29</ncp:change-history>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/db_srr_chklst_generic_v8r1-2.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>2AFE1E2A8F95B9A01FD0AA14CEAD0041F4D88E30</ncp:sha-1>
            <ncp:sha-256>B02C178D37086C3771AA7F800103030B6C172DDD3E6452C264FDDFB664FF3B47</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="55" checklist-version="Version 6, Release 1.2" published-datetime="2009-04-23T04:00:00.000Z" entry-datetime="2007-10-29T04:00:00.000Z" checklist-name="zOS RACF STIG Checklist" last-modified-datetime="2009-10-07T16:55:09.030Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>FINAL</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>IBM OS390</ncp:name>
            <ncp:cpe-name>cpe:/o:ibm:os_390</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This SRR Review Procedures, OS/390 Resource Access Control Facility (RACF) document provides the procedures for conducting a Security Readiness Review (SRR) to determine compliance with the requirements in the OS/390 Security Technical Implementation Guides (STIG). This checklist must be used together with the corresponding version of the STIG document. This SRR guide focuses strictly on the IBM OS/390 operating system (OS) and how the RACF security component interacts with the operating system. Additionally, this checklist ensures the site has properly installed and implemented the RACF component for the IBM OS/390 OS and that it is being managed in a way that is secure, efficient, and effective, through procedures outlined in the checklist. The items reviewed are based on standards and requirements published by DISA in the OS/390 Security Technical Implementation Guide.</ncp:summary>
        <ncp:checklist-role>Server</ncp:checklist-role>
        <ncp:target-audience>Developped for the DOD.
This checklist has been created for IT professionals, particularly operating system administrators with a background in the IBM OS/390 OS, as well as information security personnel. The document assumes that the reader has experience installing and administering the IBM OS/390-based systems in domain or standalone configurations.</ncp:target-audience>
        <ncp:target-operational-environment>MANAGED</ncp:target-operational-environment>
        <ncp:target-operational-environment>SSLF</ncp:target-operational-environment>
        <ncp:regulatory-compliance>DOD Directive 8500.</ncp:regulatory-compliance>
        <ncp:comments-warnings-miscellaneous>Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.</ncp:comments-warnings-miscellaneous>
        <ncp:product-support>It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.</ncp:product-support>
        <ncp:change-history>Version 4, Release 1.3, 2004-02
Version 4, Release 1.4, 2004-10
Version 4, Release 1.5, 2005-07
Version 5, Release 1.1, 2006-04
Version 5, Release 2.1, 2006-11
Version 5, Release 2.2, 2007-03-23
Version 5, Release 2.3, 2007-05-30
Version 5, Release 2.6, 2007-11
Version 5, Release 2.10, 2008-12</ncp:change-history>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/zos-racf-stig-ver6-rel12.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>DA3C50C3AD808FD310289153CA5DBF2128F9BC54</ncp:sha-1>
            <ncp:sha-256>72B43F1AEC2F185BF3B63AEE78EAD5AA9F73D48DC5E65644C8781FA57FC7A5E6</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="274" checklist-version="Version 1, Release 1.5" published-datetime="2009-04-14T04:00:00.000Z" entry-datetime="2009-04-23T15:08:21.937Z" checklist-name="Directory Services Security Checklist" last-modified-datetime="2009-10-07T17:29:40.827Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>UNDER_REVIEW</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Server 2003</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_2003_server</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Server 2000</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_2000:::server</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>Directory Services Security Checklist provides the procedures for conducting a Security Readiness Review (SRR) to determine compliance with the requirements in the Directory Services Security Technical Implementation Guide (STIG).  This Checklist document must be used together with the corresponding version of the STIG document.
This Checklist currently addresses three review subjects:
- Generic Directory Service - This subject covers checks for an implementation of a generic directory service.
- Generic Directory Synchronization Application - This subject covers checks for an implementation of an application used to perform synchronization on two or more directory service implementations.
- Active Directory (AD) Implementation - This subject covers checks for AD Domain Controllers, AD Domains, and the AD Forest that make up an implementation of Active Directory.

The procedures in this document are part of the effort to ensure that the security configuration guidelines required by Department of Defense (DoD) Directive 8500.1, Information Assurance, and other relevant guidance are properly implemented.

In order to minimize repetition, certain procedures in this document reference information in the Windows 2000 Security Checklist and the Windows Server 2003 Security Checklist. Therefore, familiarity with those documents is considered a prerequisite to this checklist.</ncp:summary>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/directoryservices_checklist_v1r1-5_20090828.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>5E715F27A4C5935831A3EE1BEA085C5B34842394</ncp:sha-1>
            <ncp:sha-256>641A6D9E86B05CC58F47031E21684C2EE8175B36A3C210AB325038B90F274F57</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="221" checklist-version="Version 6 Release 1.13" published-datetime="2009-06-26T04:00:00.000Z" entry-datetime="2008-06-09T04:00:00.000Z" checklist-name="Windows Server 2003 Security Checklist" last-modified-datetime="2009-10-07T17:33:56.670Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>FINAL</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Microsoft Internet Explorer</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:ie</ncp:cpe-name>
            <ncp:product-category>Web Browser</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Server 2003</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_2003_server</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>NetMeeting</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:netmeeting</ncp:cpe-name>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Media Player</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:windows_media_player</ncp:cpe-name>
        </ncp:target-product>
        <ncp:summary>The Windows Server 2003 Security Checklist is composed of three major sections and several appendices.  The organizational breakdown proceeds as follows:

Section 1- Introduction
This section contains summary information about the sections and appendices that comprise the Windows Server 2003 Security Checklist, and defines its scope.  Supporting documents consulted are listed in this section.

Section 2- Automated System Check Procedures
This section contains summary information for running the Gold Disk.

Section 3- Manual System Check Procedures
This section documents the procedures that instruct the reviewer on how to perform an SRR manually, and to interpret the program output for vulnerabilities.

Appendix A- Object Permissions
This appendix documents the allowed Access Control Lists (ACLs) for file and registry objects.  The tables contained in this section are referenced in Section 3.

Appendix B- Information Assurance Vulnerability Management (IAVM) Compliance
This appendix contains checks for IAVM compliance to be done against a Windows Server 2003 machine.

Appendix C- MS Group Policy Analysis Tools
This appendix provides information for the use of Microsoft tools for analyzing group policy.

Appendix D- Windows VMS Asset Creation and Findings Import Procedures for Reviewers and Self Assessments
This appendix documents the procedures for creating assets and importing findings into VMS 6.0

Appendix E- Joint Task Force - Global Network Operations (JTF-GNO) Communications Tasking Orders (CTO) Compliance
This appendix identifies Windows specific requirements from JTF-GNO CTOs.

Appendix F- SRR Results Report
This section is the matrix that allows the reviewer to document vulnerabilities discovered during the SRR process.  The entries in this table are mapped to the manual procedures in Section 3 and appendix B.</ncp:summary>
        <ncp:checklist-role>Server</ncp:checklist-role>
        <ncp:target-audience>This document is designed to instruct the reviewer on how to assess Windows Server 2003 configurations in Windows 2000, or Windows 2003 domains.  In addition, the security settings recommended can also be used to configure Group Policy in a Windows 2000 or Windows 2003 Active Directory environment  

Field Security Operations- DISA

Sites are required to secure the Microsoft Windows Server 2003 operating system in accordance with  DOD Directive 8500.1, Section 4.18 (and related footnote).  The checks in this document were developed from DOD guidelines specified in the above reference, as well as the Windows Server 2003 security guides and security templates published by the Microsoft Corporation.</ncp:target-audience>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=1b6acf93-147a-4481-9346-f93a4081eea8&amp;DisplayLang=en" />
            <ncp:description>The Threats and Countermeasures Guide</ncp:description>
        </ncp:ncp-reference>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://www.microsoft.com/downloads/details.aspx? FamilyID=8a2643c1-0685-4d89-b655-521ea6c7b4db&amp; DisplayLang=en" />
            <ncp:description>Windows Server 2003 Security Guide</ncp:description>
        </ncp:ncp-reference>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/windows_2003_checklist_v6-1-13_20090828.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>B93DF561AF2A44ACDAC863C78F45B314FF7CFF40</ncp:sha-1>
            <ncp:sha-256>FBE9B767B5A91E32E96919077F5FA22526B436EA719441B56A7E43617A854186</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="228" checklist-version="Version 6, Release 1.6" published-datetime="2009-06-25T04:00:00.000Z" entry-datetime="2008-09-17T04:00:00.000Z" checklist-name="Windows Server 2008 Security Checklist" last-modified-datetime="2009-10-07T17:45:36.980Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>FINAL</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Defender</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:windows_defender</ncp:cpe-name>
            <ncp:product-category>Malware</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Internet Explorer</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:ie</ncp:cpe-name>
            <ncp:product-category>Web Browser</ncp:product-category>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Mail</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:windows_mail</ncp:cpe-name>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Media Player</ncp:name>
            <ncp:cpe-name>cpe:/a:microsoft:windows_media_player</ncp:cpe-name>
        </ncp:target-product>
        <ncp:target-product>
            <ncp:name>Microsoft Windows Server 2008</ncp:name>
            <ncp:cpe-name>cpe:/o:microsoft:windows_server:2008</ncp:cpe-name>
            <ncp:product-category>Operating System</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>The Windows Server 2008 Security Checklist is composed of three major sections and several appendices.  The organizational breakdown proceeds as follows:

Section 1 - Introduction
This section contains summary information about the sections and appendices that comprise the Windows Server 2008 Security Checklist, and defines its scope.  Supporting documents consulted are listed in this section.

Section 2 - Automated System Check Procedures
The Gold Disk does not support Windows 2008 at this time.

Section 3 - Manual System Check Procedures
This section documents the procedures that instruct the reviewer on how to perform an SRR manually, and to interpret the program output for vulnerabilities.

Appendix A - Object Permissions
This appendix documents the any additional Access Control Lists (ACLs) for file and registry objects.  The tables contained in this section are referenced in Section 3.

Appendix B - Joint Task Force Global Network Operations (JTF-GNO) Information Assurance Vulnerability Management (IAVM) Compliance
This appendix contains checks for IAVM compliance to be done against a Windows Server 2008 machine.

Appendix C - MS Group Policy Analysis Tools
This appendix provides information for the use of Microsoft tools for analyzing group policy.

Appendix D - Windows VMS Asset Creation and Findings Import Procedures for Reviewers and Self Assessments
This appendix documents the procedures for creating assets and importing findings into VMS 6.0

Appendix E - Joint Task Force - Global Network Operations (JTF-GNO) Communications Tasking Orders (CTO) Compliance
This appendix identifies Windows specific requirements from JTF-GNO CTOs.

Appendix F - SRR Result Report
This section is the matrix that allows the reviewer to document vulnerabilities discovered during the SRR process.  The entries in this table are mapped to procedures, referenced by Vulnerability and STIG IDs in Sections 3 and Appendix B.</ncp:summary>
        <ncp:checklist-role>Server</ncp:checklist-role>
        <ncp:target-audience>This document is designed to instruct the reviewer on how to assess Windows Server 2008 configurations in Windows domains.  In addition, the security settings recommended can also be used to configure Group Policy in a Windows Active Directory environment.</ncp:target-audience>
        <ncp:change-history>Version 6.1.1 - July 2008 - New Checklist
Version 6.1.2 - 2008-12-26
Version 6.1.3 - 2009-02-27</ncp:change-history>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=fb8b981f-227c-4af6-a44b-b115696a80ac&amp;DisplayLang=en" />
            <ncp:description>Windows Server 2008 Security Guide</ncp:description>
        </ncp:ncp-reference>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://www.microsoft.com/downloads/details.aspx?familyid=a3d1bbed-7f35-4e72-bfb5-b84a526c1565&amp;displaylang=en" />
            <ncp:description>Windows Vista Security Guide</ncp:description>
        </ncp:ncp-reference>
        <ncp:ncp-reference>
            <ncp:reference xml:lang="en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=1b6acf93-147a-4481-9346-f93a4081eea8&amp;DisplayLang=en" />
            <ncp:description>The Threats and Countermeasures Guide</ncp:description>
        </ncp:ncp-reference>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/windows_2008_checklist_v6r1-6_20090828.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>FF48B762BDD5706914B676B4DC2981578257AABF</ncp:sha-1>
            <ncp:sha-256>CF67BA5309D5D24A8561E90752D703927AB89771DDD3CE02BB9528C64C1819F9</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>
    <entry id="252" checklist-version="Version 5, Release 4" published-datetime="2009-04-13T04:00:00.000Z" entry-datetime="2008-10-17T04:00:00.000Z" checklist-name="Wireless STIG Blackberry Security Checklist" last-modified-datetime="2009-10-07T17:51:10.853Z">
        <ncp:tier>1</ncp:tier>
        <ncp:review-status>FINAL</ncp:review-status>
        <ncp:authority>
            <ncp:organization system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:type>GOVERNMENTAL_AUTHORITY</ncp:type>
        </ncp:authority>
        <ncp:target-product>
            <ncp:name>Research In Motion Blackberry</ncp:name>
            <ncp:cpe-name>cpe:/a:rim:blackberry</ncp:cpe-name>
            <ncp:product-category>Wireless Email</ncp:product-category>
        </ncp:target-product>
        <ncp:summary>This Checklist provides security policy and configuration requirements for the use of BlackBerry wireless email in the Department of Defense (DoD). Guidance in this document applies to all BlackBerry systems, including BlackBerry handheld devices and the BlackBerry Enterprise Server (BES).

This checklist serves as both a security review checklist and a configuration guide. Information Assurance Officers (IAOs), Security Managers (SMs), System Administrators (SAs), device users, and security readiness reviewers, each with varying experience levels, should use this document to ensure the security of BlackBerry implementations. Thus, the format of each section is tailored to meet these various needs.</ncp:summary>
        <ncp:scap-expression-data>
            <ncp:scap-expressed>false</ncp:scap-expressed>
            <ncp:xccdf-expressed>false</ncp:xccdf-expressed>
            <ncp:oval-expressed>false</ncp:oval-expressed>
            <ncp:cce-expressed>false</ncp:cce-expressed>
            <ncp:cve-expressed>false</ncp:cve-expressed>
            <ncp:cvss-expressed>false</ncp:cvss-expressed>
            <ncp:cpe-expressed>false</ncp:cpe-expressed>
        </ncp:scap-expression-data>
        <ncp:supporting-resource>
            <ncp:reference xml:lang="en" href="http://iase.disa.mil/stigs/checklist/wireless_stig_blackberry_checklist_v5r4_28aug2009.zip" />
            <ncp:author system-id="http://www.disa.mil/" name="Defense Information Systems Agency " />
            <ncp:sha-1>DA39A3EE5E6B4B0D3255BFEF95601890AFD80709</ncp:sha-1>
            <ncp:sha-256>E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855</ncp:sha-256>
            <ncp:type>Prose</ncp:type>
        </ncp:supporting-resource>
    </entry>

</ncp>