SV-59337r8_rule
V-46473
DTBI014-IE11-TLS setting
DTBI014-IE11
CAT II
10
Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Panel >> Advanced Page >> "Turn off Encryption Support" to "Enabled".
Select only "Use TLS 1.1" and "Use TLS 1.2" from the drop-down box.
The policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Panel >> Advanced Page >> "Turn off Encryption Support" must be "Enabled".
Verify the only options selected are "Use TLS 1.1" and "Use TLS 1.2" from the drop-down box.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings!SecureProtocols.
Criteria: If the value for "SecureProtocols" is not REG_DWORD = "2560", this is a finding.
V-46473
False
DTBI014-IE11
The policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Panel >> Advanced Page >> "Turn off Encryption Support" must be "Enabled".
Verify the only options selected are "Use TLS 1.1" and "Use TLS 1.2" from the drop-down box.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings!SecureProtocols.
Criteria: If the value for "SecureProtocols" is not REG_DWORD = "2560", this is a finding.
M
2589